BigCommerce warns customers of potential data leaks following cyber incident
Date:
Tue, 22 Sep 2026 12:00:00 +0000
Description:
Hackers broke into a third-party app and stole customer data, including personally identifiable information.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter BigCommerce confirms
supplychain breach via compromised Ribon app credentials affecting merchant storefronts Master of Malt notified customers: names, emails, phone numbers, and addresses were exposed Attack ran Sept 1317 2026; ICO notified, law firm warns of phishing risks for affected retailers Ecommerce platform BigCommerce was recently hit with a cyberattack in which it lost sensitive data belonging to some of its users.
One of the users - online spirits retailer Master of Malt - confirmed the hit and notified its customers that their personally identifiable information (PII) was accessed in the attack. BigCommerce is an ecommerce platform relatively similar to Shopify. Businesses use it to build and operate online stores without needing to develop the entire commerce infrastructure themselves. It offers features like storefronts, shopping carts, integrations with different payment providers, product inventories, SEO and marketing tools, and more. Latest Videos From TechRadar Watch full video here:
The platform has been around since 2009 and according to a late 2024 SEC filing , serves 5,884 accounts with at least one unique enterprise plan subscription. A 2025 press release says BigCommerce is used by tens of thousands of B2C and B2B companies across 150 countries. Software supply
chain attack BigCommerce allows its users to install, among others, a third-party app called Ribon, an ecommerce app providing tools that improve the online shopping experience. Some merchants integrate Ribon into their stores to add different functionality to the customer-facing storefront, and to optimize how visitors interact with different elements of their website.
We dont know exactly how many stores use Ribon. You may like Lidl customers across Europe hit in suspected data breach - here's what we know Carhartt
data breach exposed information from 12.9 million user accounts Levi's
reveals security tear may have let hackers steal important corporate data
According to Master of Malt, unidentified threat actors managed to compromise a BigCommerce Application key held by Ribon, and used it to access customer data that was held on their system. The attack took place on Sunday,
September 13 2026, until the access was finally revoked four days later, on September 17.
Speaking to BleepingComputer , BigCommerce said credentials for Ribon and Ribon 1.5 were compromised: Are you a pro? Subscribe to our newsletter Sign
up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
"On September 17, 2026, Commerce confirmed that credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by 'Be A
Part Of,' a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts, the statement reads. "Acting in the best interest of our customers and their shoppers, we uninstalled the application from affected stores to revoke the attacker's access, notified those merchants directly, and are providing log data to support the developer's investigation," the company told the publication.
The keyword in this statement is small number of merchant storefronts. BigCommerce hints that the attack was relatively small in scope and, consequently, in damage. However, in its report Master of Malt says
otherwise:
Its now clear that we werent the target of the attack. The attack was against Ribon, which was installed on hundreds of BigCommerce stores. Once the attackers compromised an access key from Ribon, they used it to access data held inside BigCommerce. What to read next Massive supply-chain attack sees terabytes of data leaked online Pokmon Center data breach exposes customer info, cancels some orders Manchester Airports hack: Experts weigh in on 8.7M data leak Names and emails Whether or not this transforms into a new
Snowflake fiasco remains to be seen.
In the meantime, Master of Malt also said BigCommerce notified it that the attack had been stopped and that there was no further risk of compromise. All companies affected by the breach were contacted. As for the spirits retailer, here is what it said about the data exposed in the hit:
Im sorry to say that the attackers had access to your name, email address, phone number, and address. However, they were not able to access your password, credit card or other payment information as they are held in a separate system which was never compromised.
Master of Malt reported the attack to the UK Information Commissioners Office (ICO). Law firm Emery Reddy is calling for potential claimants to the incidents, saying that several retailers are currently notifying customers about data exposure related to the incident, BleepingComputer reported.
A number of online retailers that use the BigCommerce e-commerce platform
have begun notifying customers of a data breach that originated not with the retailers themselves, but with a third-party application called Ribon, the
law firm says. Emery Reddy also warned of potential phishing and scam
attacks. The best antivirus for all budgets Our top picks, based on
real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/bigcommerce-warns-customers-of-potentia l-data-leaks-following-cyber-incident
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)