# BigCommerce Faces Data Breach Through Ribon App Exploit

*Published September 23, 2026*
*Source: [https://www.securityweek.com/bigcommerce-data-stolen-via-ribon-apps-hack/](https://www.securityweek.com/bigcommerce-data-stolen-via-ribon-apps-hack/)*

## Executive Summary

BigCommerce suffered a data breach after hackers exploited a compromised key from the Ribon app, leading to unauthorized access to customer information. The breach underscores the risks associated with third-party apps and the importance of swift response measures.

## Article

BigCommerce, a prominent eCommerce platform provider, has been hit by a supply chain attack resulting in the theft of customer data. The breach occurred when hackers exploited a compromised application key from Ribon, an app developed by Be A Part Of, a company owned by Fastr. This key, active from September 13 to September 17, allowed unauthorized access to sensitive customer information such as names, email addresses, phone numbers, and addresses across various merchant stores.

The breach was first discovered when the UK spirits vendor Master of Malt reported the misuse of the compromised key. The hackers systematically downloaded customer data until the key was disabled on September 17, a day after the Ribon developers became aware of the issue. Following this, BigCommerce promptly informed affected merchants on September 18, after revoking access and uninstalling the compromised Ribon applications.

BigCommerce clarified that the breach stemmed from a third-party app and not its own systems. The company took swift action to mitigate the impact by removing the Ribon apps from affected storefronts and providing necessary data logs to assist in the ongoing investigation. Despite the quick response, the exact method of compromise for Ribon remains uncertain, and further details from Be A Part Of and Fastr are awaited.

The incident highlights the vulnerabilities that can arise from third-party applications, emphasizing the need for robust security measures and prompt incident response to protect customer data.
