INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
BigCommerce Data Breach Linked to Ribon Apps Malware Attack
| 2026-09-22 17:58 HIGH LOW DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
A series of high-profile data breaches has been reported in recent weeks, with multiple companies falling victim to sophisticated cyber attacks. In a particularly egregious incident, UK spirits vendor Master of Malt revealed that hackers had accessed customer data between September 13 and September 17 using a compromised key. The attackers downloaded sensitive information page by page until the key was revoked on September 17. This breach is part of a larger trend, with other notable incidents including the compromise of 23 million user records at Gyazo, 680 high-profile accounts stolen from Revolut in a ransom demand for $3M, and an AI data breach reported to Spanish regulators. The attacks highlight the growing threat of supply chain attacks, which can have far-reaching consequences for companies and their customers.
Technical Mitigations AI-generated
• Implement robust access controls and monitoring for third-party applications to prevent unauthorized access.
• Regularly review and update API credentials, especially those related to sensitive data storage and manipulation.
• Utilize secure communication protocols (e.g., HTTPS) when integrating with external services or APIs.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
FIVE_EYES
FIVE_EYES
retailretail
technologytechnology
Incident Timeline
2026/09/15
Threat actors compromised a BigCommerce application key held by Ribon, a storefront and shopping experience optimization app developed by Fastr-owned Be A Part Of.
Click on any entity below to view its context and source!
organisation
Ribon
Late last week, the company started notifying merchants that customer data was stolen after hackers compromised a BigCommerce application key held by Ribon, a storefront and shopping experience optimization app developed by Fastr-owned Be A Part Of.
organisation
Fastr
Late last week, the company started notifying merchants that customer data was stolen after hackers compromised a BigCommerce application key held by Ribon, a storefront and shopping experience optimization app developed by Fastr-owned Be A Part Of.
September 17, 2026
Threat actors used compromised Fastr system credentials to steal API keys belonging to third-party applications Ribon and Ribon 1.5, owned by 'Be A Part Of,' a Fastr company.
Click on any entity below to view its context and source!
organisation
Commerce
“On September 17, 2026, Commerce confirmed that API credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by “Be A Part Of,” a Fastr company, had been compromised due to a Fastr system compromise.
"On September 17, 2026, Commerce confirmed that credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by 'Be A Part Of,' a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts.
organisation
API
“On September 17, 2026, Commerce confirmed that API credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by “Be A Part Of,” a Fastr company, had been compromised due to a Fastr system compromise.
general_metric
1.5 Ribon
“On September 17, 2026, Commerce confirmed that API credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by “Be A Part Of,” a Fastr company, had been compromised due to a Fastr system compromise.
"On September 17, 2026, Commerce confirmed that credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by 'Be A Part Of,' a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts.
organisation
Gyazo Data Breach
Confirms Source Code Stolen in Supply Chain Attack
Related:
23 Million User Records Compromised in Gyazo Data Breach
Related:
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related:
data_breach
23 Records Compromised
Confirms Source Code Stolen in Supply Chain Attack
Related:
23 Million User Records Compromised in Gyazo Data Breach
Related:
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related:
data_breach
680 Profile Accounts
Confirms Source Code Stolen in Supply Chain Attack
Related:
23 Million User Records Compromised in Gyazo Data Breach
Related:
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related:
financial
$3 Ransom
Confirms Source Code Stolen in Supply Chain Attack
Related:
23 Million User Records Compromised in Gyazo Data Breach
Related:
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related:
organisation
SecurityWeek
This was not a breach of Commerce systems or the BigCommerce platform,” BigCommerce told SecurityWeek.
September 17, one day
Threat actors downloaded customer data from BigCommerce working 'page by page' until the compromised key was revoked on September 17.
September 17
Threat actors used a Ribon Apps plugin to target BigCommerce, compromising its credentials and prompting the platform's immediate removal of the malicious software.
Click on any entity below to view its context and source!
tactic
T1592.002 - Software
The cloud-based Software-as-a-Service (SaaS) ecommerce platform confirmed the credential compromise on September 17 and immediately removed the apps to protect its customers.
September 18
BigCommerce notified merchants of a data theft incident on September 18, after Ribon applications had been disabled and uninstalled.
between September 13 and September 17
Threat actors used a key between September 13 and September 17 to access customer data of BigCommerce stores managed by Ribon Apps.
Click on any entity below to view its context and source!
target_region
United Kingdom
The hackers used the key between September 13 and September 17 to access customer data, including names, email addresses, phone numbers, and addresses, UK spirits vendor Master of Malt notes in a
technical write-up
.
September 13 and September 17
Threat actors used compromised credentials to access shopper data in BigCommerce environments between September 13 and September 17.
2026/09/22
Threat actors compromised the Ribon application credentials, allowing them to access existing customer records through BigCommerce.
Click on any entity below to view its context and source!
organisation
BigCommerce
BigCommerce alerts merchants of data breach linked to Ribon apps.
Enterprise eCommerce platform BigCommerce fell victim to a supply chain attack that led to customer data theft.
organisation
Ribon
BigCommerce supports over 1,200 third-party applications and integrations, including Ribon, an application operated by Be A Part Of, a brand operated by Fastr, specialized in shopping experience optimization.
organisation
Fastr
BigCommerce supports over 1,200 third-party applications and integrations, including Ribon, an application operated by Be A Part Of, a brand operated by Fastr, specialized in shopping experience optimization.
organisation
BigCommerce Data Stolen
BigCommerce Data Stolen via Ribon Apps Hack.
organisation
BleepingComputer
In a statement for BleepingComputer, BigCommerce said that the attacker compromised credentials for Ribon and Ribon 1.5 applications.
organisation
FreshClick BigCommerce
The incident is similar to a 2024 breach affecting
electronics accessory maker ZAGG
, where attackers compromised the third-party FreshClick BigCommerce app and injected payment-skimming code into its online store.
organisation
BigCommerce Application
“It looks like hackers were able to compromise a BigCommerce Application key held by Ribon, which they were able to use to gain access to customer data held on their system,”
Master of Malt stated
.
organisation
ZAGG
However, unlike the ZAGG incident, where attackers captured payment information entered by customers during checkout, the Ribon attackers used a compromised application key to access existing customer records through BigCommerce.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tactical Metrics
Metrics
data_breach
23,000,000
Records Compromised
Click for context!
Confirms Source Code Stolen in Supply Chain Attack
Related:
23 Million User Records Compromised in Gyazo Data Breach
Related:
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related:
Metrics
data_breach
680
Profile Accounts
Confirms Source Code Stolen in Supply Chain Attack
Related:
23 Million User Records Compromised in Gyazo Data Breach
Related:
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related:
Metrics
financial
3,000,000
Ransom
Confirms Source Code Stolen in Supply Chain Attack
Related:
23 Million User Records Compromised in Gyazo Data Breach
Related:
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related:
Intelligence Sources
SecurityWeek
2026-09-22
BigCommerce Data Stolen via Ribon Apps Hack
SecurityWeek
BleepingComputer
2026-09-21
BigCommerce alerts merchants of data breach linked to Ribon apps
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T06:38
Comprehensive Tactical Telemetry
Highly Correlated Entities
14x
organisation
Identified Entity
Gyazo Data Breach
entity
9x
timeline
Temporal Reference
between September 13 and September 17
date
2x
target region
Target Country
United Kingdom
country
2x
tactic
Cyber Operation Type
Data Breach
tactic
Contextual Telemetry
Context Block
6 METRICS
data breach
Records Compromised
23,000,000
records compromised
data breach
Profile Accounts
680
profile accounts
financial
Ransom
3,000,000
ransom
general metric
Ribon
2
ribon
general metric
Party Applications
1,200
party applications
tactic
MITRE ATT&CK Technique
T1592.002 - Software
technique
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.