BigCommerce Breach Exposes Data via Third-Party App

Attackers used stolen Ribon app keys to access customer records, affecting retailers like Master of Malt.
Key points
- Attackers stole Ribon app keys to access customer records at multiple BigCommerce merchants.
- Master of Malt confirmed exposure of names, emails, and addresses between September 13 and 17.
- BigCommerce removed the compromised apps to cut off access, stating its core platform was safe.
BigCommerce has warned multiple online retailers that customer data was exposed after attackers stole credentials for a third-party application. The security platform confirmed on September 17 that malicious actors compromised the keys for the Ribon and Ribon 1.5 apps, which are operated by Fastr. This allowed the attackers to inject harmful scripts into specific merchant storefronts and access stored shopper information.
The incident highlights a significant trade-off in e-commerce architecture: while third-party apps add functionality, they also create potential entry points for attackers. BigCommerce stated that its core systems were not breached, but the compromised application keys provided a direct route to customer records. The platform immediately removed the apps from affected stores to cut off the attacker's access and notified the impacted merchants directly.
Retailers face direct data exposure
Master of Malt, a UK-based spirits retailer, is one of the businesses affected by the breach. The company stated that between September 13 and 17, the hacker accessed shopper details including full names, email addresses, phone numbers, and shipping addresses. Master of Malt has reported the incident to the UK Information Commissioner’s Office and warned that the impact may extend to hundreds of other stores using the same application.
This breach differs from a similar 2024 incident involving the ZAGG electronics brand. In that case, attackers used a compromised app to capture payment information during checkout. Here, the Ribon attackers used the stolen keys to retrieve existing customer records already stored in the system. BigCommerce noted that payment card data and passwords are stored separately and were not part of this specific exposure.
Third-party apps create security risks
BigCommerce supports over 1,200 third-party integrations, creating a complex supply chain of security dependencies. The company emphasized that the platform itself remained secure, but the compromised credentials for the Ribon apps allowed attackers to bypass standard perimeter defenses. By acting as a trusted component within the store, the app provided the necessary permissions to access sensitive data without triggering a full platform breach alert.
BleepingComputer contacted Be A Part Of and Fastr for comment but did not receive a response before publication. Law firm Emery Reddy is currently seeking potential claimants, noting that several retailers are notifying customers about the data exposure. The situation underscores the challenge for merchants who rely on external tools to enhance user experience while managing the inherent risk of shared credentials.
Merchants must manage app access
The incident serves as a reminder that securing an e-commerce platform requires more than protecting the core infrastructure. Merchants must actively monitor the permissions granted to third-party applications and ensure that developers follow strict security protocols for credential management. As BigCommerce removed the problematic apps to revoke access, merchants are left to assess the extent of the data leakage and notify their customers accordingly.






