BigCommerce has disclosed a cyber incident involving the compromise of credentials for a third-party app used by multiple stores, resulting in unauthorized access to customer information across hundreds of merchant accounts.

  • Third-party app Ribon credentials compromised, enabling data theft
  • Customer names, emails, phone numbers, and addresses accessed
  • Affected merchants notified and breach under investigation

What happened

On September 13, 2026, unauthorized parties compromised the credentials of the third-party app Ribon and its updated version Ribon 1.5, which are integrated into multiple BigCommerce online stores. This breach gave attackers access to customer data stored within these merchant websites. The security issue persisted until September 17, when BigCommerce revoked access by uninstalling the affected applications from impacted storefronts.

BigCommerce explained that the breach allowed malicious scripts to be injected into a limited number of merchant sites, thereby exposing personally identifiable information such as names, emails, phone numbers, and physical addresses. Payment information, including passwords and credit card details, remained secure as they are held separately by BigCommerce. Some affected merchants, such as the online spirits retailer Master of Malt, publicly confirmed the data exposure and informed their customers.

Why it matters

This incident illustrates the vulnerabilities introduced by third-party app integrations in ecommerce platforms and the risks they pose to customer data security. Because BigCommerce serves tens of thousands of merchants worldwide, any attack on commonly used third-party components can lead to widespread exposure and reputational damage for the platform.

The breach is significant as it affects not only the merchants but also the end customers, risking identity theft, phishing attacks, and other fraudulent activities. The involvement of UK’s Information Commissioner’s Office demonstrates regulatory focus on how ecommerce providers and their partners manage data protection. Legal ramifications and potential claims against BigCommerce or the app developer are also emerging as multiple retailers notify customers.

What to watch next

Ongoing investigations by BigCommerce, the third-party app operator Be A Part Of, and regulators will clarify the full scope and security failures that enabled this breach. Evidence from access logs and forensic analysis may reveal if additional data or stores were compromised beyond early estimates from merchants.

Merchants utilizing BigCommerce and similar platforms should monitor updates on security enhancements, consider audits of apps they integrate, and be prepared to communicate transparently with their customers about potential risks related to third-party components. The incident may also trigger broader industry discussions on app vetting processes and the implementation of stronger data protection protocols.

Source assisted: This briefing began from a discovered source item from TechRadar. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings