Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    How AI Chatbots Are ‘Deskilling’ Human Empathy

    September 21, 2026

    BigCommerce alerts merchants of data breach linked to Ribon apps

    September 21, 2026

    CISA alerts of active exploitation of three Linux kernel flaws

    September 21, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»BigCommerce alerts merchants of data breach linked to Ribon apps
    News

    BigCommerce alerts merchants of data breach linked to Ribon apps

    adminBy adminSeptember 21, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    BigCommerce alerts merchants of data breach linked to Ribon apps

    Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores.

    The cloud-based Software-as-a-Service (SaaS) ecommerce platform confirmed the credential compromise on September 17 and immediately removed the apps to protect its customers.

    UK-based online spirits vendor Master of Malt is one of the BigCommerce customers that received the notification. The retailer said the attacker accessed shopper information.

    The hacker used the compromised credentials to access shopper data in BigCommerce environments between September 13 and September 17, the company said.

    In updates on the incident, Master of Malt says impacted shopper details include full names, email addresses, phone numbers, and shipping postal addresses.

    “It looks like hackers were able to compromise a BigCommerce Application key held by Ribon, which they were able to use to gain access to customer data held on their system,” Master of Malt stated.

    BigCommerce supports over 1,200 third-party applications and integrations, including Ribon, an application operated by Be A Part Of, a brand operated by Fastr, specialized in shopping experience optimization.

    The e-commerce platform says it stores account passwords and payment card information separately and that this type of data was not exposed.

    In a statement for BleepingComputer, BigCommerce said that the attacker compromised credentials for Ribon and Ribon 1.5 applications.

    “On September 17, 2026, Commerce confirmed that credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by ‘Be A Part Of,’ a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts.”

    The company underlined that its systems or the BigCommerce platform were not breached.

    “Acting in the best interest of our customers and their shoppers, we uninstalled the application from affected stores to revoke the attacker’s access, notified those merchants directly, and are providing log data to support the developer’s investigation,” the company told BleepingComputer.

    Master of Malt reported the incident to the UK Information Commissioner’s Office (ICO) and noted that it may extend well beyond its own customers, potentially to hundreds of other stores.

    Law firm Emery Reddy is seeking potential claimants linked to the incident, saying several retailers are currently notifying customers about data exposure linked to the Ribon app key theft, without naming any.

    BleepingComputer has contacted Be A Part Of and Fastr for more information about the incident but we have not received a response by publication time.

    The incident is similar to a 2024 breach affecting electronics accessory maker ZAGG, where attackers compromised the third-party FreshClick BigCommerce app and injected payment-skimming code into its online store.

    At the time, BigCommerce told BleepingComputer that its platform was not breached and removed the compromised app from customers’ stores.

    However, unlike the ZAGG incident, where attackers captured payment information entered by customers during checkout, the Ribon attackers used a compromised application key to access existing customer records through BigCommerce.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCISA alerts of active exploitation of three Linux kernel flaws
    Next Article How AI Chatbots Are ‘Deskilling’ Human Empathy
    admin
    • Website

    Related Posts

    News

    How AI Chatbots Are ‘Deskilling’ Human Empathy

    September 21, 2026
    News

    CISA alerts of active exploitation of three Linux kernel flaws

    September 21, 2026
    News

    CIS Community Defense Model v3.0: Turning Threat Intelligence Into Action

    September 21, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Our Picks

    How AI Chatbots Are ‘Deskilling’ Human Empathy

    September 21, 2026

    BigCommerce alerts merchants of data breach linked to Ribon apps

    September 21, 2026

    CISA alerts of active exploitation of three Linux kernel flaws

    September 21, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.