Find notable cyber news and cases, enriched with sources, timelines, and signals.

BigCommerce merchant shopper data exposure via compromised Ribon app credentials

Data Leak
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

A BigCommerce data leak exposed shopper records after attackers used compromised Ribon app credentials to reach merchant environments, affecting Master of Malt and other stores. The exposed data included full names, email addresses, phone numbers, and shipping postal addresses. BigCommerce said the exposure ran from September 13 to September 17, 2026, and that payment cards and account passwords were not exposed. The platform removed the apps and notified merchants after confirming the credential compromise on September 17.

Related Happenings

23AndMe hit by network compromise

Incident
H score55 First: 16.07.2026 16:47 Last: 16.07.2026 16:47 Sources 1

About this happening: 23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from A...

Latest development: 17.07.2026 17:30

23andMe reached an $18m settlement with a coalition of 42 US attorneys general over the 2023 credential stuffing breach, and the agreement adds new data protection requirements for 23andMe customer data and TTAM Research.

Timeline

  1. 22.09.2026 00:18 1 articles · 3h ago

    BigCommerce confirms Ribon credentials were used to inject malicious scripts

    Initial Disclosure

    BigCommerce confirmed that credentials for the third-party Ribon and Ribon 1.5 applications, owned and operated by Be A Part Of, a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts. The company said it uninstalled the applications from affected stores to revoke the attacker’s access, notified those merchants directly, and stated that its systems and the BigCommerce platform were not breached.

    Show sources
  2. 22.09.2026 00:18 2 articles · 3h ago

    Master of Malt says shopper records were accessed through the Ribon app key theft

    Victim Impact Update

    UK-based online spirits vendor Master of Malt said it received the notification and that the attacker accessed shopper information. The impacted shopper details included full names, email addresses, phone numbers, and shipping postal addresses, and the retailer reported the incident to the UK Information Commissioner’s Office while warning the exposure could extend beyond its own customers.

    Show sources