Enterprise eCommerce platform BigCommerce fell victim to a supply chain attack that led to customer data theft.
BigCommerce is a SaaS provider that enables merchants to build and manage online stores. It hosts the stores, provides backend tools, and handles server security.
Late last week, the company started notifying merchants that customer data was stolen after hackers compromised a BigCommerce application key held by Ribon, a storefront and shopping experience optimization app developed by Fastr-owned Be A Part Of.
The hackers used the key between September 13 and September 17 to access customer data, including names, email addresses, phone numbers, and addresses, UK spirits vendor Master of Malt notes in a technical write-up.
According to Master of Malt, the hackers downloaded customer data working ‘page by page’ until the compromised key was revoked on September 17, one day after the Ribon developers became aware of its misuse.
BigCommerce started notifying merchants of the incident on September 18, after the key had been disabled and the targeted Ribon applications uninstalled.
“The attack was against Ribon, which was installed on hundreds of BigCommerce stores. Once the attackers compromised an access key from Ribon, they used it to access data held inside BigCommerce,” Master of Malt said.
BigCommerce, which provides support for over 1,200 third-party applications, has confirmed that the hackers compromised the Ribon application credentials.
“On September 17, 2026, Commerce confirmed that API credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by “Be A Part Of,” a Fastr company, had been compromised due to a Fastr system compromise. The credentials were used to inject malicious scripts into a small number of merchant storefronts. This was not a breach of Commerce systems or the BigCommerce platform,” BigCommerce told SecurityWeek.
“While the Ribon applications are third-party apps independently installed by the merchant where the relationship occurs between the merchant and the third-party application, Commerce acted in the best interest of our customers and their shoppers by uninstalling the application from affected stores to revoke the attacker’s access and limit harm, notifying affected merchants directly, and providing log data to support the developer’s own investigation,” the company added.
It is unclear how Ribon was compromised and whether other entities were also affected, as neither Be A Part Of nor Fastr have publicly acknowledged the incident.
SecurityWeek has emailed both companies for additional information and will update this article if they respond.
Related: CrowdSec Confirms Source Code Stolen in Supply Chain Attack
Related: 23 Million User Records Compromised in Gyazo Data Breach
Related: Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related: First Agentic AI Data Breach Reported to Spanish Regulator


