Top Buzz Trends
No Result
View All Result
  • Entertainment
  • Gaming
  • Tech
  • More
    • Netflix
    • Prime Video
    • Max
    • Celebrity News
    • Movies
    • TV Shows
    • Paramount+
    • Disney+
    • Hulu
    • Apple TV
    • Google TV
  • Entertainment
  • Gaming
  • Tech
  • More
    • Netflix
    • Prime Video
    • Max
    • Celebrity News
    • Movies
    • TV Shows
    • Paramount+
    • Disney+
    • Hulu
    • Apple TV
    • Google TV
No Result
View All Result
Top Buzz Trends
  • Entertainment
  • Gaming
  • Tech
  • More
Home Tech

BigCommerce and Merchants Dispute Scale of Ribon Supply-Chain Security Incident

by Scarlet Luka
September 23, 2026
in Tech
Reading Time: 2 mins read
0
Conceptual illustration of a digital data leak with red binary streams flowing from a broken lock icon.

The incident involved compromised API credentials from a third-party developer.

BigCommerce has confirmed a supply-chain security incident involving the Ribon and Ribon 1.5 third-party applications, which led to the exposure of customer data across several storefronts. The compromise, attributed to a breach at the app developer Fastr, allowed unauthorized actors to use stolen API credentials to scrape personal information over a four-day window in September 2026.

RELATED POSTS

iOS Settings Banners Promote Apple Services Under CEO John Ternus

Meta Issues Hot-Fix for Muse AI Assistant Following Zero-Day Disclosure

iPhone AutoLock: How Apple’s New Voting System Detects Snatch-and-Grab Theft

The unauthorized access began at 17:21 BST on September 13 and persisted until BigCommerce intervened at 21:12 BST on September 17, 2026. During this period, attackers utilized compromised application keys to make unauthorized REST API requests. According to technical disclosures from affected merchants, the attackers used these keys to download customer records “page by page,” effectively bypassing standard storefront security measures.

Abstract representation of a digital supply chain showing interconnected server nodes.
Attackers utilized stolen API keys to scrape PII directly from connected storefronts.

Data Exposure and Technical Scope

The breach exposed specific categories of Personally Identifiable Information (PII). According to SecurityWeek, the compromised data includes customer full names, email addresses, phone numbers, and physical shipping addresses. BigCommerce has clarified that account passwords and payment card information (PCI) were not accessed, as these data sets are maintained in separate, isolated systems that were not reachable via the Ribon app’s API permissions.

In addition to data scraping, attackers used the compromised credentials to inject malicious scripts into some merchant storefronts. While the primary goal appears to have been data harvesting, the presence of unauthorized scripts represents a significant secondary risk to the integrity of the affected e-commerce sites.

ADVERTISEMENT

Discrepancy in Breach Scale

A notable gap exists between the official vendor assessment and the reports from impacted merchants. BigCommerce has described the impact as affecting a “small number” of storefronts. However, the retailer Master of Malt, which was among those notifying customers of the leak, stated that the Ribon app was installed on “hundreds” of BigCommerce stores at the time of the compromise.

The Ribon applications are owned and operated by “Be A Part Of,” a subsidiary brand of Fastr. BigCommerce has officially attributed the credential leak to a “Fastr system compromise,” though Fastr has not yet provided a public detailed account of how its internal systems were breached.

Conceptual digital audit and forensic analysis of computer code.
Merchants are advised to audit API logs for unauthorized activity occurring between September 13 and 17.

Mitigation and Legal Response

BigCommerce took proactive measures to halt the data exfiltration on September 17 by forcibly uninstalling both Ribon and Ribon 1.5 from all merchant stores. This action effectively revoked the attackers’ access to the REST API and removed the malicious scripts from storefronts. Merchants using these applications were notified that the apps were removed for security reasons.

Merchants who previously utilized the Ribon or Ribon 1.5 apps are advised to audit their API logs for any unusual activity during the September 13–17 window and ensure no residual unauthorized scripts remain in their custom themes or headers.

ShareTweetShareSend
Scarlet Luka

Scarlet Luka

Related Posts

A conceptual rendering of smartphone notification layers representing digital services.
Tech

iOS Settings Banners Promote Apple Services Under CEO John Ternus

September 23, 2026
A conceptual digital visualization of AI security and data protection.
Tech

Meta Issues Hot-Fix for Muse AI Assistant Following Zero-Day Disclosure

September 23, 2026
Conceptual illustration of smartphone security and motion detection
Tech

iPhone AutoLock: How Apple’s New Voting System Detects Snatch-and-Grab Theft

September 22, 2026
Jeremy Levine Changes Name on Zoom to Avoid Recordings
Tech

Jeremy Levine Changes Name on Zoom to Avoid Recordings

July 18, 2026
Tech

Generative AI and Fair Compensation for Artists: The Call for Proper Authorization and Compensation

October 1, 2023
Tech

Building Equitable Products: Strategies for Inclusive Product Innovation

September 30, 2023

Popular - Posts

  • A moody, dimly lit London office desk with files and an old telephone.

    Slow Horses Maintains 630-Day Global Top 10 Streak on Apple TV+

    0 shares
    Share 0 Tweet 0
  • The Latest Update for No Man’s Sky Game Introduces Randomly Created Spacecraft Using Procedural Generation

    0 shares
    Share 0 Tweet 0
  • Peacemaker Season 2: Cast, Plot, and Release Date Revealed – All You Need to Know!

    1 shares
    Share 0 Tweet 0
  • Trending
  • Comments
  • Latest
Netflix anime series "Super Crooks": everything we need to know

Netflix anime series “Super Crooks”: everything we need to know

October 23, 2021
Prince Harry wants to request an apology from the royal family

Prince Harry wants to request an apology from the royal family

June 15, 2022

Introducing Artifact’s AI-Powered Text-to-Speech Feature for Personalized News Listening

July 28, 2023

New York Comic Con Schedule: Marvel Booth, Signings, and Exciting Events

October 2, 2023
Conceptual illustration of a digital data leak with red binary streams flowing from a broken lock icon.

BigCommerce and Merchants Dispute Scale of Ribon Supply-Chain Security Incident

September 23, 2026
Silhouetted figures of two detectives standing against a New York City night skyline.

Mariska Hargitay to Direct Christopher Meloni’s Return in SVU Milestone

September 23, 2026
A collection of sports equipment from different disciplines representing various comedy series.

5 Sports Comedies to Stream During Ted Lasso Season 4

September 23, 2026
A conceptual image of a chess piece in a high-tech surveillance center.

Special Ops: Lioness: Stephanie Nur on Aaliyah Amrohi’s Season 3 Return

September 23, 2026
  • About Us
  • Contact Us
  • Privacy Policy
  • Disclaimer
  • Editorial Policy
  • Terms and Conditions
  • Use Of Cookies

Top Buzz Trends
Top Buzz Trends is not endorsed, moderated, owned by, or affiliated with TopBuzz or any of its partners in any capacity. Top Buzz Trends is an independent news website for Entertainment, Movies, TV Shows, Netflix, Games, and Gadgets, Software, Computers, Smartphones, and more. All promotional material including but not limited to trailers, images, and videos, are all copyrighted to their respective owners. TopBuzz is a registered trademark of ByteDance Ltd.
© Top Buzz Trends - All Rights Reserved.

No Result
View All Result
  • Entertainment
  • Gaming
  • Tech
  • More
    • Netflix
    • Prime Video
    • Max
    • Celebrity News
    • Movies
    • TV Shows
    • Paramount+
    • Disney+
    • Hulu
    • Apple TV
    • Google TV

Top Buzz Trends
Top Buzz Trends is not endorsed, moderated, owned by, or affiliated with TopBuzz or any of its partners in any capacity. Top Buzz Trends is an independent news website for Entertainment, Movies, TV Shows, Netflix, Games, and Gadgets, Software, Computers, Smartphones, and more. All promotional material including but not limited to trailers, images, and videos, are all copyrighted to their respective owners. TopBuzz is a registered trademark of ByteDance Ltd.
© Top Buzz Trends - All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Go to mobile version