started · updated
BigCommerce merchants targeted in Ribon app supply chain attack
BigCommerce has confirmed a supply chain attack involving compromised API credentials from a third-party application, Ribon. The breach originated from a system compromise at Fastr, the owner of Be A Part Of, which develops the Ribon storefront optimization app.
Between September 13 and September 17, 2026, threat actors used the compromised Ribon application keys to access customer data within BigCommerce merchant stores. The attackers reportedly downloaded data ‘page by page’ until the credentials were revoked. Affected information includes personally identifiable information (PII) such as names, email addresses, phone numbers, and physical addresses.
While the breach involved data held within the BigCommerce ecosystem, the company stated that the attack was against Ribon and did not constitute a breach of the core BigCommerce platform or its internal systems. One affected retailer, Master of Malt, has already notified its customers of the exposure.
Entities
Be A Part Of · BigCommerce · Fastr · Master of Malt · Ribon