Attackers compromised API credentials for the third-party Ribon and Ribon 1.5 applications, operated by Be A Part Of, a Fastr company, and used them to access customer records in BigCommerce merchant environments. Between September 13 and 17, they also injected malicious scripts into a small number of storefronts; reported exposed data included customer names, email addresses, phone numbers, and shipping or physical addresses.
BigCommerce said its core platform and systems were not breached and that passwords and payment-card data were not exposed. The company disabled the compromised credentials, removed the affected apps from impacted stores, revoked attacker access, notified merchants, and provided logs to support the application developer's investigation.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
BigCommerce began directly notifying affected merchants and supplied log data to support the Ribon developer's investigation. It stated that its own platform and systems were not breached and that passwords and payment-card information were not exposed.
BigCommerce confirmed the Ribon credential compromise and revoked the compromised application key, ending the documented period of unauthorized access. The company also removed the affected applications from impacted stores to revoke attacker access.
Ribon developers became aware that the application's compromised credentials were being misused.
Attackers used compromised Ribon and Ribon 1.5 credentials to access customer records held in BigCommerce environments and inject malicious scripts into a small number of merchant storefronts. The accessed data included customer names, email addresses, telephone numbers, and physical or shipping addresses.
Master of Malt, a BigCommerce customer, reported the incident to the UK Information Commissioner's Office and warned that customers of hundreds of other stores could potentially be affected.
Fastr, the operator of Be A Part Of and the Ribon applications, experienced a system compromise that exposed API credentials for Ribon and Ribon 1.5. The initial compromise method was not disclosed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.