Desk live·
ForensicPost
Cloud/Third party/File 26-0917

BigCommerce Merchants Lost Shopper Data Through a Stolen App Key at a Third-Party Vendor

Credentials held by the Ribon storefront apps were used from 13 to 17 September to read customer records through the platform API and inject scripts into storefronts. Master of Malt told its customers; the app’s owner had said nothing by the time reporters asked.

Constructed geometry · not a chart of case data
JurisdictionUSAAustinthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetBigCommerce merchants via Ribon
ActorUnattributed
S. Rosler9 min readConfidence: medium3 sources reviewed

BigCommerce told merchants on 17 and 18 September 2026 that an application key belonging to the third-party apps Ribon and Ribon 1.5 had been compromised and used between 13 and 17 September to access shopper data through the platform’s API and to inject malicious scripts into a small number of storefronts. The apps, storefront-optimisation tools, are operated by Be A Part Of, a company owned by Fastr. BigCommerce uninstalled them from affected stores, revoked the key and said the incident was not a breach of its own platform.

The exposed fields were names, email addresses, phone numbers and shipping addresses. Passwords and payment cards are stored separately and were not involved, the platform said. Master of Malt, the British spirits retailer, emailed customers the following week and suggested the incident could reach hundreds of other stores. Neither the app’s operator nor its parent had publicly acknowledged the compromise when SecurityWeek reported it.

The Key Was The App’s, And The Data Was The Merchant’s

A platform app is granted an API key with scopes to do its job. When the key is stolen from the app’s developer, every store that installed the app is reachable with whatever those scopes allow, and the store learns about it from the platform. The corpus filed the structure at 25-1207, where an OAuth grant persisted until somebody removed it, and at 26-0611, where one vendor’s compromise reached Salesforce environments. BigCommerce lists more than 1,200 third-party apps. The question the file cannot answer is whether Ribon’s scopes included reading customer records because it needed to, or because the default was broad.

Scripts In The Storefront

The second use of the key, injecting scripts into storefronts, was described without detail. A script placed in a checkout page is the mechanism of card skimming, and the platform’s statement that card data was not exposed refers to its own storage, not to what a script in a shopper’s browser could capture. No source established what the scripts did, and the file records the gap.

Three Parties, One Letter

The platform notified merchants. Merchants notified shoppers, or did not. The app operator whose credential was taken said nothing in public. The shopper who received Master of Malt’s email had never heard of Ribon or Fastr, and the merchant who sent it had learned the name from BigCommerce. That distribution of knowledge is the ordinary condition of a SaaS ecosystem, and the file is graded medium because the party that knows how the key was stolen has not spoken.

How we reported this

Compiled from BigCommerce’s merchant notice as reported, Master of Malt’s customer email as reported and contemporaneous coverage, listed below. No affected count exists from any party. The purpose of the injected scripts was not described. The app operator had not commented. Graded medium. Corrections: corrections@forensicpost.com.

Sources
  1. BigCommerce alerts merchants of data breach linked to Ribon appsBleepingComputer
  2. BigCommerce Data Stolen via Ribon Apps HackSecurityWeek
  3. Whisky merchant Master of Malt confirms customer data spiltThe Register
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary