Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-22 · updated: 2026-09-22 · tags: [incident, retail, phishing] · confidence: high · severity: high · affected_sectors: [retail] · au_impact: false

Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. The company confirmed the credential compromise on 17 September and removed the applications immediately, and says the attacker used the compromised access to reach shopper data between 13 and 17 September. UK spirits retailer Master of Malt, one of the customers notified, told shoppers that the attacker compromised a BigCommerce application key held by Ribon and used it to reach customer data held on the platform's systems; the impacted details include full names, email addresses, phone numbers and shipping postal addresses. The case is the standard shape of app-marketplace risk: a merchant extends its storefront with a third-party integration, the integration's API key carries the merchant's scope, and a compromise at the vendor propagates straight into the merchant's customer records. Removing the apps stops the injection but does not undo the collection window, so affected merchants are in the same position as any breach victim — notification, and the expectation of follow-on phishing against the addresses and phone numbers that were taken. BigCommerce has not published a total figure for affected shoppers, and the number of merchants involved has not been disclosed.

Attribute Detail
Sector Retail & Entertainment & Sport
Date 2026-09-22
Source BleepingComputer
Reliability Tier 2