INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

BigCommerce Data Breach Linked to Ribon Apps Malware Attack

| 2026-09-22 17:58 HIGH LOW DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
A series of high-profile data breaches has been reported in recent weeks, with multiple companies falling victim to sophisticated cyber attacks. In a particularly egregious incident, UK spirits vendor Master of Malt revealed that hackers had accessed customer data between September 13 and September 17 using a compromised key. The attackers downloaded sensitive information page by page until the key was revoked on September 17. This breach is part of a larger trend, with other notable incidents including the compromise of 23 million user records at Gyazo, 680 high-profile accounts stolen from Revolut in a ransom demand for $3M, and an AI data breach reported to Spanish regulators. The attacks highlight the growing threat of supply chain attacks, which can have far-reaching consequences for companies and their customers.
Technical Mitigations AI-generated
• Implement robust access controls and monitoring for third-party applications to prevent unauthorized access. • Regularly review and update API credentials, especially those related to sensitive data storage and manipulation. • Utilize secure communication protocols (e.g., HTTPS) when integrating with external services or APIs.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
FIVE_EYES FIVE_EYES retailretail technologytechnology
Incident Timeline
‎2026/09/15
Threat actors compromised a BigCommerce application key held by Ribon, a storefront and shopping experience optimization app developed by Fastr-owned Be A Part Of.
organisation Ribon
organisation Fastr
‎September 17, 2026
Threat actors used compromised Fastr system credentials to steal API keys belonging to third-party applications Ribon and Ribon 1.5, owned by 'Be A Part Of,' a Fastr company.
organisation Commerce
organisation API
general_metric 1.5 Ribon
organisation Gyazo Data Breach
data_breach 23 Records Compromised
data_breach 680 Profile Accounts
financial $3 Ransom
organisation SecurityWeek
‎September 17, one day
Threat actors downloaded customer data from BigCommerce working 'page by page' until the compromised key was revoked on September 17.
‎September 17
Threat actors used a Ribon Apps plugin to target BigCommerce, compromising its credentials and prompting the platform's immediate removal of the malicious software.
tactic T1592.002 - Software
‎September 18
BigCommerce notified merchants of a data theft incident on September 18, after Ribon applications had been disabled and uninstalled.
‎between September 13 and September 17
Threat actors used a key between September 13 and September 17 to access customer data of BigCommerce stores managed by Ribon Apps.
target_region United Kingdom
‎September 13 and September 17
Threat actors used compromised credentials to access shopper data in BigCommerce environments between September 13 and September 17.
‎2026/09/22
Threat actors compromised the Ribon application credentials, allowing them to access existing customer records through BigCommerce.
organisation BigCommerce
organisation Ribon
organisation Fastr
organisation BigCommerce Data Stolen
organisation BleepingComputer
organisation FreshClick BigCommerce
organisation BigCommerce Application
organisation ZAGG
organisation NFL
organisation CHANEL
Tactical Metrics
Metrics
data_breach
23,000,000
Records Compromised
Metrics
data_breach
680
Profile Accounts
Metrics
financial
3,000,000
Ransom
Intelligence Sources
SecurityWeek 2026-09-22
BleepingComputer 2026-09-21