BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injection

BigCommerce Merchant Storefronts Compromised via Stolen (TL-2026-2610) is a medium-severity data breach, first published 2026-09-21. It has no confirmed attribution, affects Be A Part Of (a Fastr company) Ribon / Ribon 1.5 (BigCommerce, maps to 10 MITRE ATT&CK techniques (T1059.007, T1071.001, T1195.002), and is covered by 9 detection rules and 9 indicators of compromise.

Key facts for TL-2026-2610

Threat ID
TL-2026-2610
Severity
MEDIUM
Status
ACTIVE
Category
DATA_BREACH
First published
2026-09-21
Last reviewed
2026-09-21
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
retail, ecommerce
Target regions
united kingdom, Global
Detection rules
9
Indicators of compromise
9

Malware and tooling in BigCommerce Merchant Storefronts Compromised via Stolen

Malware and tooling: Ribon, Ribon 1.5

Attackers stole a BigCommerce application access key belonging to the third-party storefront-optimization apps Ribon and Ribon 1.5 (operated by Be A Part Of, a Fastr company) and used it to access customer data and inject malicious scripts across BigCommerce merchant storefronts between September 13-17, 2026. BigCommerce revoked the key and removed the apps platform-wide; confirmed victim Master of Malt (UK) had customer names, emails, phone numbers, and shipping addresses exposed, with passwords and payment data unaffected.

How BigCommerce Merchant Storefronts Compromised via Stolen works

Between Sunday, September 13, 2026 and Thursday, September 17, 2026, attackers obtained and abused a stolen BigCommerce application access key belonging to Ribon and Ribon 1.5, third-party storefront-optimization apps operated by Be A Part Of, a Fastr company, and distributed through the BigCommerce App Marketplace. Because the apps run with elevated, trusted API scopes granted by every merchant who installs them, the stolen token gave the attackers a single credential that fanned out across the customer data of every BigCommerce storefront running Ribon or Ribon 1.5 -- a textbook trusted-relationship / software-supply-chain compromise rather than a vulnerability in BigCommerce's own platform.

Reporting on the incident describes two related effects of the compromise: attackers used the stolen key to pull customer records directly from data stored on Ribon's backend systems, and separately, malicious scripts were injected into affected online stores. BigCommerce has stated its own platform and systems were not breached; the compromise originated entirely within the third-party vendor's application and credential handling.

On September 17, 2026, BigCommerce's security team identified the abuse, revoked the compromised access key, and uninstalled Ribon and Ribon 1.5 from every affected merchant storefront. BigCommerce notified impacted merchants directly and supplied log data to support their own investigations. Individual retailers then began notifying their own customers; UK online spirits retailer Master of Malt is the first confirmed victim, disclosing that unauthorized parties accessed customers' full names, email addresses, phone numbers, and postal addresses. Master of Malt and BigCommerce both state that account passwords and payment card data were held in separate systems and were not exposed, and Master of Malt has stated the breach is contained with no ongoing unauthorized access. Notably, Emery | Reddy's own breach-litigation intake page states that it has not independently verified retailers' claim that passwords and payment data sat in a separate, unaffected system -- that segregation claim currently rests solely on statements from BigCommerce and the retailers themselves. Master of Malt reported the incident to the UK Information Commissioner's Office (ICO). Because Ribon and Ribon 1.5 were installed on every BigCommerce storefront that used them -- not just Master of Malt's -- multiple retailers beyond Master of Malt are expected to disclose the same underlying incident to their own customers; Emery | Reddy is soliciting affected customers across retailers for potential breach litigation. The malicious storefront scripts persisted in place, embedded via the apps' legitimate extensibility/integration mechanism into each merchant's live storefront pages, for the duration of the September 13-17, 2026 window until BigCommerce forcibly uninstalled Ribon and Ribon 1.5 platform-wide -- the removal, not detection by the merchants themselves, is what ended their execution. No technical indicators -- attacker infrastructure IPs/domains, malware hashes, the content of the injected scripts, or the mechanism by which the Ribon access key itself was originally obtained -- have been publicly disclosed by BigCommerce, Be A Part Of/Fastr, or affected merchants as of this writing; every source reviewed (BleepingComputer, Born's IT- und Windows-Blog, Emery | Reddy) independently confirms this absence of technical detail rather than merely omitting it.

MITRE ATT&CK techniques used in TL-2026-2610

Execution

T1059.007 JavaScript

Command and Control

T1071.001 Web Protocols

Initial Access

T1195.002 Compromise Software Supply Chain; T1199 Trusted Relationship

Collection

T1213 Data from Information Repositories; T1530 Data from Cloud Storage

Persistence

T1505 Server Software Component

Credential Access

T1528 Steal Application Access Token

Lateral Movement

T1550.001 Application Access Token

Exfiltration

T1567 Exfiltration Over Web Service

Affected products and versions in BigCommerce Merchant Storefronts Compromised via Stolen

  • Be A Part Of (a Fastr company) — Ribon / Ribon 1.5 (BigCommerce storefront app)
    Vulnerable versions: Ribon; Ribon 1.5
    Fixed in: N/A - apps uninstalled platform-wide by BigCommerce on 2026-09-17
  • BigCommerce — BigCommerce merchant storefronts with the Ribon or Ribon 1.5 app installed
    Vulnerable versions: Any storefront with Ribon or Ribon 1.5 installed as of 2026-09-13
    Fixed in: N/A - BigCommerce revoked the compromised application access key and removed the apps

Remediation for BigCommerce Merchant Storefronts Compromised via Stolen

Immediate actions

  • Confirm the Ribon and Ribon 1.5 apps have been fully uninstalled from all BigCommerce storefronts and any residual API scopes revoked
  • Rotate all BigCommerce store-level API accounts and application access tokens exposed to any third-party app, not only Ribon
  • Review BigCommerce store audit/access logs for the September 13-17, 2026 window for anomalous data pulls or script injections
  • Notify affected customers of exposed name/email/phone/address data and advise vigilance against follow-on phishing and vishing

Workarounds

  • Merchants who installed Ribon or Ribon 1.5 should treat all customer PII exported through the app as potentially exposed regardless of individual breach notification timing
  • Monitor for phishing, smishing, and vishing campaigns leveraging exposed customer names, emails, phone numbers, and addresses

Longer-term hardening

  • Apply least-privilege API scoping to every installed third-party BigCommerce app rather than accepting default broad scopes
  • Implement continuous monitoring and anomaly detection on third-party app API key usage across the App Marketplace ecosystem
  • Require periodic security assessments and credential-handling attestations from SaaS app vendors before/after installation
  • Maintain an inventory of installed third-party storefront apps and their data-access scopes for rapid incident response

Timeline of BigCommerce Merchant Storefronts Compromised via Stolen

  • Attackers begin using a stolen BigCommerce application access key belonging to the Ribon/Ribon 1.5 apps to access customer data across affected merchant storefronts.
  • BigCommerce notifies affected merchants directly and provides log data to support their own investigations.
  • BigCommerce revokes the stolen access key and uninstalls the Ribon and Ribon 1.5 apps from every affected merchant storefront, ending unauthorized access.
  • BigCommerce's security team identifies unauthorized use of the Ribon application access key.
  • Master of Malt begins emailing affected customers, disclosing exposure of names, email addresses, phone numbers, and postal addresses via the Ribon app compromise.
  • Independent outlets (BleepingComputer, Born's IT- und Windows-Blog) publish reporting on the BigCommerce/Ribon compromise, confirming BigCommerce's alert to merchants.
  • Master of Malt reports the breach to the UK Information Commissioner's Office (ICO).
  • US law firm Emery | Reddy publishes a breach-lawsuit intake page soliciting affected BigCommerce/Ribon customers.

Sources cited for BigCommerce Merchant Storefronts Compromised via Stolen

More in data breach

Detection coverage for TL-2026-2610

As of 2026-09-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2610 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats