BigCommerce merchant shopper data exposure via compromised Ribon app credentials
Data Leak
Summary
Hide ▲
Show ▼
A BigCommerce data leak exposed shopper records after attackers used compromised Ribon app credentials to reach merchant environments, affecting Master of Malt and other stores. The exposed data included full names, email addresses, phone numbers, and shipping postal addresses. BigCommerce said the exposure ran from September 13 to September 17, 2026, and that payment cards and account passwords were not exposed. The platform removed the apps and notified merchants after confirming the credential compromise on September 17.
Related Happenings
23AndMe hit by network compromise
Incident
H score55
First: 16.07.2026 16:47
Last: 16.07.2026 16:47
Sources 1
About this happening:
23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from A...
23AndMe hit by network compromise
IncidentAbout this happening: 23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from A...
Latest development: 17.07.2026 17:30
23andMe reached an $18m settlement with a coalition of 42 US attorneys general over the 2023 credential stuffing breach, and the agreement adds new data protection requirements for 23andMe customer data and TTAM Research.
Timeline
-
22.09.2026 00:18 1 articles · 3h ago
BigCommerce confirms Ribon credentials were used to inject malicious scripts
Initial DisclosureBigCommerce confirmed that credentials for the third-party Ribon and Ribon 1.5 applications, owned and operated by Be A Part Of, a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts. The company said it uninstalled the applications from affected stores to revoke the attacker’s access, notified those merchants directly, and stated that its systems and the BigCommerce platform were not breached.
Show sources
- BigCommerce alerts merchants of data breach linked to Ribon apps — www.bleepingcomputer.com — 22.09.2026 00:18
-
22.09.2026 00:18 2 articles · 3h ago
Master of Malt says shopper records were accessed through the Ribon app key theft
Victim Impact UpdateUK-based online spirits vendor Master of Malt said it received the notification and that the attacker accessed shopper information. The impacted shopper details included full names, email addresses, phone numbers, and shipping postal addresses, and the retailer reported the incident to the UK Information Commissioner’s Office while warning the exposure could extend beyond its own customers.
Show sources
- BigCommerce alerts merchants of data breach linked to Ribon apps — www.bleepingcomputer.com — 22.09.2026 00:18
- BigCommerce alerts merchants of data breach linked to Ribon apps — www.bleepingcomputer.com — 22.09.2026 00:18