BigCommerce told merchants on 17 and 18 September 2026 that an application key belonging to the third-party apps Ribon and Ribon 1.5 had been compromised and used between 13 and 17 September to access shopper data through the platform’s API and to inject malicious scripts into a small number of storefronts. The apps, storefront-optimisation tools, are operated by Be A Part Of, a company owned by Fastr. BigCommerce uninstalled them from affected stores, revoked the key and said the incident was not a breach of its own platform.
The exposed fields were names, email addresses, phone numbers and shipping addresses. Passwords and payment cards are stored separately and were not involved, the platform said. Master of Malt, the British spirits retailer, emailed customers the following week and suggested the incident could reach hundreds of other stores. Neither the app’s operator nor its parent had publicly acknowledged the compromise when SecurityWeek reported it.
The Key Was The App’s, And The Data Was The Merchant’s
A platform app is granted an API key with scopes to do its job. When the key is stolen from the app’s developer, every store that installed the app is reachable with whatever those scopes allow, and the store learns about it from the platform. The corpus filed the structure at 25-1207, where an OAuth grant persisted until somebody removed it, and at 26-0611, where one vendor’s compromise reached Salesforce environments. BigCommerce lists more than 1,200 third-party apps. The question the file cannot answer is whether Ribon’s scopes included reading customer records because it needed to, or because the default was broad.
Scripts In The Storefront
The second use of the key, injecting scripts into storefronts, was described without detail. A script placed in a checkout page is the mechanism of card skimming, and the platform’s statement that card data was not exposed refers to its own storage, not to what a script in a shopper’s browser could capture. No source established what the scripts did, and the file records the gap.
Three Parties, One Letter
The platform notified merchants. Merchants notified shoppers, or did not. The app operator whose credential was taken said nothing in public. The shopper who received Master of Malt’s email had never heard of Ribon or Fastr, and the merchant who sent it had learned the name from BigCommerce. That distribution of knowledge is the ordinary condition of a SaaS ecosystem, and the file is graded medium because the party that knows how the key was stolen has not spoken.
Compiled from BigCommerce’s merchant notice as reported, Master of Malt’s customer email as reported and contemporaneous coverage, listed below. No affected count exists from any party. The purpose of the injected scripts was not described. The app operator had not commented. Graded medium. Corrections: corrections@forensicpost.com.