BigCommerce
Incident posture
Linked entities
- Victim
- BigCommerce
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
BigCommerce experienced a supply chain attack when attackers compromised API credentials of the third‑party Ribon application, allowing them to access customer data stored on the platform. The compromised credentials were used to retrieve names, email addresses, phone numbers, and addresses from affected stores, and the attackers downloaded the information page by page until the key was revoked and the application was removed. The platform notified merchants, disabled the compromised key, uninstalled the Ribon apps from impacted stores, and provided log data to assist the developer’s investigation.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
BigCommerce, a software‑as‑a‑service platform that hosts online stores and provides backend tools for merchants, began informing its customers on September 18 2026 that consumer data had been exfiltrated through a compromised third‑party application key. The affected application, Ribon, is a storefront and shopping experience optimization tool created by Be A Part Of, a subsidiary of Fastr, and it was installed on hundreds of BigCommerce‑powered stores. According to a technical write‑up from the UK spirits retailer Master of Malt, attackers possessed the Ribon API key between September 13 and September 17 and used it to retrieve customer information—including names, email addresses, phone numbers and postal addresses—by downloading data page by page. The key was revoked on September 17, one day after the Ribon developers became aware of its misuse, and BigCommerce disabled the credential and uninstalled the Ribon integration from the impacted storefronts.
BigCommerce confirmed on September 17 that the API credentials for both Ribon and Ribon 1.5 had been compromised due to a security incident affecting Fastr’s systems, and that the stolen credentials were leveraged to inject malicious scripts into a limited number of merchant storefronts. The company emphasized that the intrusion did not constitute a breach of its own infrastructure or the BigCommerce platform itself, characterizing the event as a supply‑chain attack targeting a third‑party partner. In response, BigCommerce uninstalled the Ribon applications from the affected stores to terminate the attackers’ access, directly notified the merchants whose data had been accessed, and supplied log files to assist Be A Part Of in its own investigation. Despite these actions, neither Be A Part Of nor Fastr have issued a public statement acknowledging the compromise, and the precise method by which the Ribon key was obtained remains unknown. The incident highlights the risk posed by the more than 1,200 third‑party applications that BigCommerce supports for its merchants.
SecurityWeek attempted to obtain further clarification from Be A Part Of and Fastr by emailing both companies, noting that any additional details would be incorporated into its reporting if received. The article references related supply‑chain incidents, such as the CrowdSec source‑code theft and the Gyazo data breach, to contextualize the BigCommerce event within a broader trend of attacks on third‑party service providers. No further technical specifics about the volume of records stolen or the exact number of stores affected were disclosed in the source material. The narrative concludes with the confirmation that the attackers’ access was terminated after the key was revoked and the Ribon applications removed from the compromised storefronts.
Sources
Sources available to members: 1 source.