Last Update: 09/25/2026 at 4:33 PM EST

Ribon App Breach Exposes BigCommerce…

Coverage from BleepingComputer, Emery Reddy, and others

Ribon App Breach Exposes BigCommerce Shopper Data image

Attackers compromised credentials for Ribon applications connected to BigCommerce and accessed shopper contact records at affected stores between September 13 and 17, 2026. BigCommerce removed the applications and revoked access; the company and merchants said passwords and payment card data were stored separately and not exposed. The incident’s full reach remains unclear, and the exposed contact details may increase the risk of targeted scams.

First Article: 09/22/26

Latest Article: 09/24/26

Articles3 articles
09-22-2026
Safestate
Attackers used a stolen Ribon access key from September 13 to 17 to access shopper records at multiple BigCommerce stores, including a UK retailer's store.
09-21-2026
BleepingComputer / Bill Toulas
BigCommerce notified merchants in September after attackers used compromised Ribon application credentials to access shopper records at multiple online stores, including Master of Malt in the United Kingdom.
09-18-2026
Emery Reddy
Online retailers using BigCommerce are notifying customers that attackers accessed names and contact information through a compromised Ribon application key.