BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injection
BigCommerce Merchant Storefronts Compromised via Stolen (TL-2026-2610) is a medium-severity data breach, first published 2026-09-21. It has no confirmed attribution, affects Be A Part Of (a Fastr company) Ribon / Ribon 1.5 (BigCommerce, maps to 10 MITRE ATT&CK techniques (T1059.007, T1071.001, T1195.002), and is covered by 9 detection rules and 9 indicators of compromise.
Key facts for TL-2026-2610
- Threat ID
- TL-2026-2610
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-09-21
- Last reviewed
- 2026-09-21
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- retail, ecommerce
- Target regions
- united kingdom, Global
- Detection rules
- 9
- Indicators of compromise
- 9
Malware and tooling in BigCommerce Merchant Storefronts Compromised via Stolen
Malware and tooling: Ribon, Ribon 1.5
Attackers stole a BigCommerce application access key belonging to the third-party storefront-optimization apps Ribon and Ribon 1.5 (operated by Be A Part Of, a Fastr company) and used it to access customer data and inject malicious scripts across BigCommerce merchant storefronts between September 13-17, 2026. BigCommerce revoked the key and removed the apps platform-wide; confirmed victim Master of Malt (UK) had customer names, emails, phone numbers, and shipping addresses exposed, with passwords and payment data unaffected.
How BigCommerce Merchant Storefronts Compromised via Stolen works
Between Sunday, September 13, 2026 and Thursday, September 17, 2026, attackers obtained and abused a stolen BigCommerce application access key belonging to Ribon and Ribon 1.5, third-party storefront-optimization apps operated by Be A Part Of, a Fastr company, and distributed through the BigCommerce App Marketplace. Because the apps run with elevated, trusted API scopes granted by every merchant who installs them, the stolen token gave the attackers a single credential that fanned out across the customer data of every BigCommerce storefront running Ribon or Ribon 1.5 -- a textbook trusted-relationship / software-supply-chain compromise rather than a vulnerability in BigCommerce's own platform.
Reporting on the incident describes two related effects of the compromise: attackers used the stolen key to pull customer records directly from data stored on Ribon's backend systems, and separately, malicious scripts were injected into affected online stores. BigCommerce has stated its own platform and systems were not breached; the compromise originated entirely within the third-party vendor's application and credential handling.
On September 17, 2026, BigCommerce's security team identified the abuse, revoked the compromised access key, and uninstalled Ribon and Ribon 1.5 from every affected merchant storefront. BigCommerce notified impacted merchants directly and supplied log data to support their own investigations. Individual retailers then began notifying their own customers; UK online spirits retailer Master of Malt is the first confirmed victim, disclosing that unauthorized parties accessed customers' full names, email addresses, phone numbers, and postal addresses. Master of Malt and BigCommerce both state that account passwords and payment card data were held in separate systems and were not exposed, and Master of Malt has stated the breach is contained with no ongoing unauthorized access. Notably, Emery | Reddy's own breach-litigation intake page states that it has not independently verified retailers' claim that passwords and payment data sat in a separate, unaffected system -- that segregation claim currently rests solely on statements from BigCommerce and the retailers themselves. Master of Malt reported the incident to the UK Information Commissioner's Office (ICO). Because Ribon and Ribon 1.5 were installed on every BigCommerce storefront that used them -- not just Master of Malt's -- multiple retailers beyond Master of Malt are expected to disclose the same underlying incident to their own customers; Emery | Reddy is soliciting affected customers across retailers for potential breach litigation. The malicious storefront scripts persisted in place, embedded via the apps' legitimate extensibility/integration mechanism into each merchant's live storefront pages, for the duration of the September 13-17, 2026 window until BigCommerce forcibly uninstalled Ribon and Ribon 1.5 platform-wide -- the removal, not detection by the merchants themselves, is what ended their execution. No technical indicators -- attacker infrastructure IPs/domains, malware hashes, the content of the injected scripts, or the mechanism by which the Ribon access key itself was originally obtained -- have been publicly disclosed by BigCommerce, Be A Part Of/Fastr, or affected merchants as of this writing; every source reviewed (BleepingComputer, Born's IT- und Windows-Blog, Emery | Reddy) independently confirms this absence of technical detail rather than merely omitting it.
MITRE ATT&CK techniques used in TL-2026-2610
Execution
Command and Control
Initial Access
T1195.002 Compromise Software Supply Chain; T1199 Trusted Relationship
Collection
T1213 Data from Information Repositories; T1530 Data from Cloud Storage
Persistence
T1505 Server Software Component
Credential Access
T1528 Steal Application Access Token
Lateral Movement
T1550.001 Application Access Token
Exfiltration
Affected products and versions in BigCommerce Merchant Storefronts Compromised via Stolen
- Be A Part Of (a Fastr company) — Ribon / Ribon 1.5 (BigCommerce storefront app)
Vulnerable versions: Ribon; Ribon 1.5
Fixed in: N/A - apps uninstalled platform-wide by BigCommerce on 2026-09-17 - BigCommerce — BigCommerce merchant storefronts with the Ribon or Ribon 1.5 app installed
Vulnerable versions: Any storefront with Ribon or Ribon 1.5 installed as of 2026-09-13
Fixed in: N/A - BigCommerce revoked the compromised application access key and removed the apps
Remediation for BigCommerce Merchant Storefronts Compromised via Stolen
Immediate actions
- Confirm the Ribon and Ribon 1.5 apps have been fully uninstalled from all BigCommerce storefronts and any residual API scopes revoked
- Rotate all BigCommerce store-level API accounts and application access tokens exposed to any third-party app, not only Ribon
- Review BigCommerce store audit/access logs for the September 13-17, 2026 window for anomalous data pulls or script injections
- Notify affected customers of exposed name/email/phone/address data and advise vigilance against follow-on phishing and vishing
Workarounds
- Merchants who installed Ribon or Ribon 1.5 should treat all customer PII exported through the app as potentially exposed regardless of individual breach notification timing
- Monitor for phishing, smishing, and vishing campaigns leveraging exposed customer names, emails, phone numbers, and addresses
Longer-term hardening
- Apply least-privilege API scoping to every installed third-party BigCommerce app rather than accepting default broad scopes
- Implement continuous monitoring and anomaly detection on third-party app API key usage across the App Marketplace ecosystem
- Require periodic security assessments and credential-handling attestations from SaaS app vendors before/after installation
- Maintain an inventory of installed third-party storefront apps and their data-access scopes for rapid incident response
Timeline of BigCommerce Merchant Storefronts Compromised via Stolen
- Attackers begin using a stolen BigCommerce application access key belonging to the Ribon/Ribon 1.5 apps to access customer data across affected merchant storefronts.
- BigCommerce notifies affected merchants directly and provides log data to support their own investigations.
- BigCommerce revokes the stolen access key and uninstalls the Ribon and Ribon 1.5 apps from every affected merchant storefront, ending unauthorized access.
- BigCommerce's security team identifies unauthorized use of the Ribon application access key.
- Master of Malt begins emailing affected customers, disclosing exposure of names, email addresses, phone numbers, and postal addresses via the Ribon app compromise.
- Independent outlets (BleepingComputer, Born's IT- und Windows-Blog) publish reporting on the BigCommerce/Ribon compromise, confirming BigCommerce's alert to merchants.
- Master of Malt reports the breach to the UK Information Commissioner's Office (ICO).
- US law firm Emery | Reddy publishes a breach-lawsuit intake page soliciting affected BigCommerce/Ribon customers.
Sources cited for BigCommerce Merchant Storefronts Compromised via Stolen
- BigCommerce alerts merchants of data breach linked to Ribon apps
- eCommerce-Plattform BigCommerce wohl über Drittanbieter Ribon gehackt
- BigCommerce Ribon App Data Breach Lawsuit
- Master of Malt data breach: customer names, addresses and phone numbers exposed
- Master of Malt investigates data hack (2019, prior unrelated incident cited for organizational security history)
More in data breach
- Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromised
- ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak
- ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour Extortion
- Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image Upload Server Exploit
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)
Detection coverage for TL-2026-2610
As of 2026-09-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2610 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.