Skip to content
Data Breach Linked to BigCommerce and Ribon Apps Exposes Customer Data

Data Breach Linked to BigCommerce and Ribon Apps Exposes Customer Data

First seen 22 Sep 2026, 02:08 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 02:10 UTC
  • Compromised Ribon app credentials led to unauthorized access to customer data.
  • Affected data includes names, emails, phone numbers, and addresses; payment info was not exposed.
  • BigCommerce acted swiftly by uninstalling the Ribon app from affected stores.

A data breach affecting retailers using the BigCommerce platform has been linked to compromised credentials for the Ribon app, a third-party application. Unauthorized access began on September 13, 2026, and continued until September 17, when the access key was revoked. The breach exposed customer data including names, email addresses, phone numbers, and physical addresses, but not payment information. BigCommerce confirmed that the breach originated from Ribon and not its own systems. Multiple retailers, including Master of Malt, have begun notifying affected customers. The incident is classified as a supply-chain breach, impacting numerous retailers using the Ribon app. Emery Reddy law firm is seeking potential claimants related to the incident. The breach is reminiscent of a previous incident in 2024 involving another third-party app on the BigCommerce platform.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-13
Unauthorized access begins
Hackers gained access to customer data through compromised Ribon app credentials.
Bleepingcomputer
2026-09-17
Access key revoked
BigCommerce's security team revoked the compromised access key and uninstalled the Ribon app.
Emery Reddy
2026-09-17
Breach confirmed
BigCommerce confirmed the credential compromise and notified affected merchants.
Bleepingcomputer
2026-09-22
Retailers notify customers
Retailers began sending breach notification emails to affected customers shortly after the incident.
Emery Reddy

More articles in this cluster (2)

Following this threat?

Track Be A Part Of in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed