Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
BigCommerce Faces Data Breach Through Ribon Apps

BigCommerce Faces Data Breach Through Ribon Apps

Posted on September 22, 2026 By CWS

An alarming breach has impacted BigCommerce, a notable eCommerce platform, as a supply chain attack led to the theft of sensitive customer data. This incident underscores vulnerabilities within third-party applications.

Details of the BigCommerce Breach

BigCommerce, a SaaS provider that supports merchants in establishing and managing online shops, became the target of a cyberattack. The breach involved the compromise of an application key associated with Ribon, a storefront optimization tool created by Fastr’s subsidiary, Be A Part Of.

The attack occurred between September 13 and September 17, when hackers exploited the compromised key to access customer details such as names, emails, phone numbers, and addresses. This was reported by UK spirits retailer Master of Malt, which provided a technical account of the breach.

Timeline and Response to the Incident

Master of Malt revealed that the attackers systematically downloaded customer information until the compromised key was deactivated on September 17, following its misuse detection by Ribon developers. BigCommerce subsequently began informing affected merchants on September 18, after the deactivation of the key and removal of the compromised Ribon applications.

The attack’s focus was on Ribon, a third-party application installed on numerous BigCommerce stores. Once the attackers breached Ribon’s access key, they managed to infiltrate data within the BigCommerce environment, according to Master of Malt.

BigCommerce’s Actions and Future Considerations

Despite the breach not directly involving BigCommerce’s core systems, the platform took decisive measures to mitigate the impact. By uninstalling the affected application from merchants’ stores, it aimed to prevent further unauthorized access and limit potential damage.

BigCommerce confirmed the breach of Ribon and Ribon 1.5 application credentials, which were used by hackers to inject harmful scripts into a few merchant sites. These applications were independent from BigCommerce, with the relationship existing solely between merchants and the third-party app.

The incident highlights the ongoing challenges of securing third-party applications and underscores the need for comprehensive security protocols. The incident’s full scope remains uncertain as Fastr and Be A Part Of have yet to publicly address the breach. SecurityWeek has reached out for comments and will provide updates when available.

This breach serves as a critical reminder of the complexities involved in securing digital commerce platforms, especially those relying heavily on third-party applications.

Security Week News Tags:API credentials, Be A Part Of, BigCommerce, customer data, Cybersecurity, data breach, digital commerce, eCommerce security, Fastr, hacker attack, malicious scripts, merchant security, online store security, Ribon apps, supply chain attack

Post navigation

Previous Post: Microsoft Dismantles AI-Powered Phishing Network EvilTokens
Next Post: Critical Flaw in Check Point Servers Actively Exploited

Related Posts

CoChat Introduces Platform to Manage Shadow AI Risks CoChat Introduces Platform to Manage Shadow AI Risks Security Week News
Chrome 145 Fixes Critical Browser Vulnerabilities Chrome 145 Fixes Critical Browser Vulnerabilities Security Week News
MokN Raises  Million for Phish-Back Solution MokN Raises $3 Million for Phish-Back Solution Security Week News
FBI Probes Cyber Incident on Sensitive Surveillance System FBI Probes Cyber Incident on Sensitive Surveillance System Security Week News
Iran-Linked Cyber Attacks Threaten Critical Infrastructure Iran-Linked Cyber Attacks Threaten Critical Infrastructure Security Week News
Citrix Patches Exploited NetScaler Zero-Day Citrix Patches Exploited NetScaler Zero-Day Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Aembit Integrates Okta’s Cross App Access for AI Control
  • Check Point Addresses Management Server Zero-Day Exploit
  • Critical Flaw in Check Point Servers Actively Exploited
  • BigCommerce Faces Data Breach Through Ribon Apps
  • Microsoft Dismantles AI-Powered Phishing Network EvilTokens

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Aembit Integrates Okta’s Cross App Access for AI Control
  • Check Point Addresses Management Server Zero-Day Exploit
  • Critical Flaw in Check Point Servers Actively Exploited
  • BigCommerce Faces Data Breach Through Ribon Apps
  • Microsoft Dismantles AI-Powered Phishing Network EvilTokens

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark