BigCommerce has confirmed a supply-chain security incident involving the Ribon and Ribon 1.5 third-party applications, which led to the exposure of customer data across several storefronts. The compromise, attributed to a breach at the app developer Fastr, allowed unauthorized actors to use stolen API credentials to scrape personal information over a four-day window in September 2026.
The unauthorized access began at 17:21 BST on September 13 and persisted until BigCommerce intervened at 21:12 BST on September 17, 2026. During this period, attackers utilized compromised application keys to make unauthorized REST API requests. According to technical disclosures from affected merchants, the attackers used these keys to download customer records “page by page,” effectively bypassing standard storefront security measures.

Data Exposure and Technical Scope
The breach exposed specific categories of Personally Identifiable Information (PII). According to SecurityWeek, the compromised data includes customer full names, email addresses, phone numbers, and physical shipping addresses. BigCommerce has clarified that account passwords and payment card information (PCI) were not accessed, as these data sets are maintained in separate, isolated systems that were not reachable via the Ribon app’s API permissions.
In addition to data scraping, attackers used the compromised credentials to inject malicious scripts into some merchant storefronts. While the primary goal appears to have been data harvesting, the presence of unauthorized scripts represents a significant secondary risk to the integrity of the affected e-commerce sites.
Discrepancy in Breach Scale
A notable gap exists between the official vendor assessment and the reports from impacted merchants. BigCommerce has described the impact as affecting a “small number” of storefronts. However, the retailer Master of Malt, which was among those notifying customers of the leak, stated that the Ribon app was installed on “hundreds” of BigCommerce stores at the time of the compromise.
The Ribon applications are owned and operated by “Be A Part Of,” a subsidiary brand of Fastr. BigCommerce has officially attributed the credential leak to a “Fastr system compromise,” though Fastr has not yet provided a public detailed account of how its internal systems were breached.

Mitigation and Legal Response
BigCommerce took proactive measures to halt the data exfiltration on September 17 by forcibly uninstalling both Ribon and Ribon 1.5 from all merchant stores. This action effectively revoked the attackers’ access to the REST API and removed the malicious scripts from storefronts. Merchants using these applications were notified that the apps were removed for security reasons.
Merchants who previously utilized the Ribon or Ribon 1.5 apps are advised to audit their API logs for any unusual activity during the September 13–17 window and ensure no residual unauthorized scripts remain in their custom themes or headers.












