BigCommerce Data Breach: Third-Party App Compromise Exposes Customer Data

BigCommerce merchants were affected by a third-party app compromise.

BigCommerce merchants were affected by a third-party app compromise. Image: Generated via Google’s Nano Banana

BigCommerce merchants were affected after compromised Ribon app credentials exposed customer data, including names, emails, phone numbers, and addresses.

Written By
Matt Gonzales
Matt Gonzales
Sep 28, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A stolen third-party credential opened the door to customer data stored by BigCommerce merchants.

Attackers compromised credentials for the Ribon and Ribon 1.5 applications and used them to attack BigCommerce merchant stores. The incident exposed customer information at affected merchants, but BigCommerce says its own systems and core platform were not breached.

The incident highlights a familiar supply-chain security problem: Even when an organization's own infrastructure remains secure, trusted applications with access to sensitive data can create another route in.

Attackers compromised Ribon app credentials

According to a statement from BigCommerce, reported by SecurityWeek, credentials for Ribon and Ribon 1.5 were compromised following a security incident involving Fastr, whose Be A Part Of business operates the applications.

The compromised credentials were then used to inject malicious scripts into a small number of merchant storefronts, BigCommerce said. The company confirmed the credential compromise on Sept. 17 and removed the affected applications from impacted stores to revoke the attackers' access.

BigCommerce emphasized that the incident did not involve a breach of its own systems or platform.

Ribon is a third-party application available to BigCommerce merchants for optimizing storefront and shopping experiences. BigCommerce supports more than 1,200 third-party applications and integrations, making these connections an important part of the platform's broader ecosystem.

The incident resembles other attacks in which compromising a trusted vendor or integration creates access to downstream organizations. Earlier this year, a third-party breach affecting ManoMano exposed data belonging to nearly 38 million customers, highlighting the scale of vendor access when something goes wrong.

Customer names, emails, phone numbers, and addresses exposed

UK retailer Master of Malt was among the BigCommerce merchants affected by the incident and published details about what happened.

According to Master of Malt's findings reported by BleepingComputer, attackers used the compromised Ribon application key to access the retailer's shopper information between Sept. 13 and Sept. 17.

Advertisement

The exposed information included:

  • Full names
  • Email addresses
  • Phone numbers
  • Shipping postal addresses

BigCommerce said account passwords and payment card information are stored separately and were not included in the customer records exposed through the compromised Ribon application key.

Master of Malt said the attacker appeared to download customer information page by page until the compromised key was revoked. BigCommerce began notifying affected merchants after the credentials were disabled and the applications removed.

The incident echoes another supply-chain compromise covered by eSecurityPlanet in June, when a Klue breach exposed Salesforce data across multiple cybersecurity companies. That attack also demonstrated how credentials associated with a trusted integration can become a route into data belonging to multiple downstream organizations.


Why third-party application access deserves scrutiny

For organizations using SaaS platforms, the BigCommerce incident is another reminder that securing the primary platform is only part of the job.

Applications connected through APIs can hold credentials and permissions that allow them to interact with sensitive systems or customer information. If those credentials are compromised, an attacker may be able to abuse the application's legitimate access without directly compromising the underlying SaaS provider.

That makes third-party access an important part of an organization's attack surface.

Security teams should maintain an inventory of applications connected to business-critical SaaS environments and understand what information each integration can access. Organizations should also periodically review whether applications still require their existing permissions and remove integrations that are no longer necessary.

API and application activity should be monitored for unusual behavior, particularly unexpected data exports or access patterns. The BigCommerce incident also demonstrates why organizations need a way to quickly revoke a third party's access when a vendor reports a security issue.

Advertisement

Similar concerns arise when third-party applications handle sensitive customer information. An eSecurityPlanet analysis of third-party breach risk explains how vendors and service providers can expand an organization's exposure beyond systems it directly controls.

What BigCommerce merchants should do now

BigCommerce has already removed the affected Ribon applications from impacted stores and revoked the compromised access, but merchants notified about the incident still have work to do.

Affected organizations should review the information provided by BigCommerce and determine exactly what customer data was accessible through their Ribon integration. They should also examine available logs for suspicious activity during the relevant exposure period identified for their store and follow applicable breach-notification requirements based on the information exposed and the jurisdictions involved.

Because names, email addresses, phone numbers, and postal addresses can be used to carry out convincing social-engineering attacks, affected merchants should also consider the possibility of follow-on phishing, smishing, or impersonation attempts targeting their customers.

For security teams beyond BigCommerce, the larger lesson is to treat third-party application credentials as part of the organization's own security perimeter. A SaaS platform can remain intact while a trusted integration provides attackers another path to valuable data. Knowing which applications have access, limiting those permissions, monitoring their activity, and being able to revoke access quickly can make the difference between a vendor incident and a much larger breach.

More cybersecurity news: For another look at third-party security risks, read how a GitHub account breach fueled a supply chain attack that spread credential-stealing malware across hundreds of packages.


Matt Gonzales

Matt Gonzales is the Managing Editor of Cybersecurity for eSecurity Planet. An award-winning journalist and editor, Matt brings over a decade of expertise across diverse fields, including technology, cybersecurity, and military acquisition. He combines his editorial experience with a keen eye for industry trends, ensuring readers stay informed about the latest developments in cybersecurity.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.