BigCommerce Ribon App Breach: What It Is and How to Protect Yourself

Customer names, email addresses, phone numbers, and shipping addresses were exposed across multiple e-commerce storefronts when attackers breached two third-party shopping applications. The cyberattack was confirmed when UK online spirits retailer Master of Malt notified its customers on September 18, 2026 of the risk to their personally identifiable information (PII). The following day, they informed customers that Master of Malt was not the target of the attack and that “The attack was against Ribon, which was installed on hundreds of BigCommerce stores.”

In a September 2026 statement reported by BleepingComputer, e-commerce platform BigCommerce alerted merchants that unauthorized actors accessed shopper records between September 13 and September 17, 2026. BigCommerce confirmed its core platform remained uncompromised and uninstalled the affected software on September 17, 2026, to block cybercriminals from further access.

No compromise. Promise.

Your credit, finances, and info, all kept Safer Than Safe.

How the BigCommerce Ribon App Breach Worked

According to BigCommerce’s comments to BleepingComputer, the data breach originated from a system compromise at Fastr, the parent company of third-party app developer “Be A Part Of.” Attackers obtained API application keys for the Ribon and Ribon 1.5 e-commerce apps, which merchants integrate into BigCommerce storefronts to manage customer features.

Because e-commerce integrations grant application keys permission to read store data, holding valid credentials allowed attackers to generate legitimate platform API requests. From September 13 to September 17, 2026, the unauthorized actor extracted customer records across affected stores and injected malicious scripts into a small number of storefronts. BigCommerce uninstalled the applications on September 17, 2026, and notified impacted merchants directly.

Warning Signs That Your Personal Data May Have Been Exposed

Exposed contact details often serve as the foundation for follow-up phishing attempts and impersonation scams. Watch for these specific indicators:

  • Unsolicited credential or payment requests: Watch for unexpected emails, texts, or phone calls claiming to be from affected retailers that ask for account passwords, PINs, or financial details.
  • Urgent payment or store verification messages: Be skeptical of communications demanding payment confirmation or immediate money transfers due to an alleged processing error or security update.
  • Suspicious login and verification links: Avoid clicking links in text messages or emails that direct you to non-official login portals or request personal information.
  • Requests for non-standard payment methods: Treat any demand for wire transfers, prepaid gift cards, or cryptocurrency as a major scam indicator.

 How to Protect Yourself After a Data Breach

Protecting your personal accounts after news of a data breach requires proactive credential management and exercising caution with calls and emails. Take these actions to help protect yourself:

  • Verify sender identity before responding. Legitimate retailers will not contact you unexpectedly to ask for sensitive credentials or payment information over phone or email.
  • Inspect email header details and website URLs. Ensure links lead directly to official domain names rather than lookalike URLs.
  • Use unique passwords across online accounts. Ensure passwords used on e-commerce sites are not reused on email or banking portals.
  • Enable multi-factor authentication (MFA). Turn on MFA across primary email and shopping accounts to add a verification layer beyond passwords.

What to Do If You Have Already Been Targeted

If your data was exposed or you received a breach notification from an affected BigCommerce merchant, take these immediate steps to secure your identity and finances:

  • Stop contact and do not send money. Discontinue communication with any sender requesting credentials or payments related to recent purchases.
  • Contact your bank, card issuer, or payment app immediately. Report potential fraud or stop suspicious transactions if payment details were compromised.
  • Update exposed passwords. Change login credentials and turn on multi-factor authentication for affected merchant accounts and any accounts where you reused passwords.
  • Freeze your credit reports. Consider a credit freeze with Equifax, Experian, and TransUnion if you suspect broader personal identity data exposure.
  • Document all suspicious interactions. Keep records of suspicious activity, including phone numbers, message transcripts, email headers, and receipts.

Next Steps After the BigCommerce Data Breach News

If you encounter phishing attempts or fraudulent activity linked to this breach, report the incident directly to official regulatory and law enforcement channels. You can submit details to the FBI Internet Crime Complaint Center, report deceptive or suspicious messages through the Federal Trade Commission, or notify the impacted retailer directly through the customer support portal on its primary website.

The BigCommerce Ribon app incident demonstrates how compromised third-party application permissions can expose customer records even when core e-commerce platform infrastructure remains secure. Verifying sender credentials and maintaining separate passwords across online accounts helps mitigate personal risk when supply-chain breaches occur.

FacebookLinkedInTwitterEmailCopy Link

Stay Updated

Follow us to stay updated on all things McAfee and on top of the latest consumer and mobile security threats.

FacebookTwitterInstagramLinkedINYouTubeRSS

More from Security News

Back to top