BigCommerce has confirmed a supply chain breach after compromised credentials from a third-party application called Ribon were used to access customer data from multiple merchant storefronts. The attack, which ran from September 13 to September 17, 2026, exposed personally identifiable information including names, email addresses, phone numbers and physical addresses, according to affected merchant Master of Malt.

What You Need to Know

The breach originated from compromised credentials for Ribon, a third-party app used by BigCommerce merchants. The attack targeted a small number of storefronts but exposed sensitive customer data. Master of Malt notified its customers and reported the incident to the ICO. Law firm Emery Reddy is investigating potential claims and warning of phishing risks.

How the Breach Unfolded

The BigCommerce Application key held by Ribon was compromised, allowing attackers to inject malicious scripts into merchant storefronts. BigCommerce said credentials for Ribon and Ribon 1.5, operated by a Fastr company called Be A Part Of, were used in the attack. The company uninstalled the app from affected stores and revoked the attacker's access. However, Master of Malt reported that the attack affected hundreds of stores, contradicting BigCommerce's characterization of a small number of storefronts. BleepingComputer first reported on the incident, noting that BigCommerce provided log data to support the developer's investigation.

Data Exposed and Impact

Master of Malt confirmed that the attackers accessed customer names, email addresses, phone numbers and physical addresses. Payment information and passwords were not compromised as they were stored in a separate system. The spirits retailer notified the UK Information Commissioner's Office (ICO) about the breach. Emery Reddy, a law firm, is calling for potential claimants and warned that affected customers may face phishing and scam attacks. The firm highlighted that several retailers are notifying customers about data exposure related to the incident.

  • Names: Customer full names were accessed in the breach
  • Email addresses: Direct contact information was exposed
  • Phone numbers: Telephone numbers were compromised
  • Physical addresses: Home and business addresses were accessed

Why This Matters

This incident underscores the systemic risk of third-party app integrations in ecommerce platforms. Even when the core platform remains secure, vulnerabilities in partner applications can cascade to merchants and their customers. For BigCommerce, trust and security are critical to retaining merchants; this breach may pressure the company to implement stricter app vetting and monitoring processes. The attack also exposes affected customers to phishing campaigns, as cybercriminals now possess detailed personal data. Regulatory bodies like the ICO may impose fines, and class-action lawsuits from law firms such as Emery Reddy could follow. The event serves as a reminder that supply chain security extends beyond direct vendors to every third-party integration.