What happened
Compromised credentials for the third‑party Ribon and Ribon 1.5 applications let attackers inject malicious scripts into a handful of merchant storefronts between 13 September and 17 September 2026.
Why it matters
Shopper details – full name, email address, phone number and shipping postal address – were accessed for at least one merchant, the UK‑based spirits retailer Master of Malt. Payment‑card data and account passwords remained protected because they are stored separately.
Technical specifics
BigCommerce confirmed that the breach stemmed from credential compromise, not a flaw in its own platform. The stolen credentials were used to push malicious JavaScript into the affected storefronts, a classic supply‑chain style injection that runs in visitors' browsers.
After discovery, BigCommerce removed the Ribon and Ribon 1.5 apps from its marketplace on 17 September 2026 and alerted all merchants using the apps.
Who is affected
- Merchants that installed the Ribon or Ribon 1.5 apps on BigCommerce during the window.
- Shopper data from those merchants – confirmed for Master of Malt, potentially for others.
- BigCommerce platform itself – not breached, but its ecosystem was abused.
Regulatory response
Master of Malt reported the incident to the UK Information Commissioner’s Office (ICO). Law firm Emery Reddy is already seeking potential claimants linked to the breach.
What to do now
- Rotate any API keys or credentials associated with third‑party apps immediately.
- Audit your storefront code for unexpected scripts; remove any that were not authored by your team.
- Enable a strict Content‑Security‑Policy (CSP) to limit where scripts can be loaded from.
- Review the list of installed third‑party extensions and remove those you no longer need.
- Monitor logs for unusual activity and set up alerts for credential‑use anomalies.
Context
The incident mirrors a 2024 breach involving the FreshClick BigCommerce app, showing that compromised third‑party extensions remain a recurring risk for e‑commerce platforms.