BigCommerce Hit by Supply Chain Attack via Third-Party App Compromise
Hackers stole customer data from BigCommerce merchants by exploiting a compromised application key belonging to the Ribon app developer.

Enterprise eCommerce platform BigCommerce has become the latest victim of a supply chain attack, resulting in the theft of customer data from its hosted merchant stores. The incident underscores the significant risks associated with third-party application integrations within cloud-based platforms.
BigCommerce, a Software-as-a-Service (SaaS) provider, offers merchants tools to build and manage their online stores, handling hosting, backend operations, and server security. The breach occurred when attackers gained unauthorized access to a BigCommerce application key that belonged to Ribon, a developer of storefront and shopping experience optimization apps, owned by Fastr's Be A Part Of.
Between September 13 and September 17, the compromised application key was used by threat actors to access sensitive customer information. This data included names, email addresses, phone numbers, and physical addresses. Master of Malt, a UK spirits vendor that utilizes the Ribon app, detailed in a technical write-up how the attackers systematically downloaded customer data page by page until the compromised key was revoked on September 17.
BigCommerce initiated notifications to affected merchants on September 18, shortly after the Ribon application key was disabled and the associated applications were uninstalled from potentially compromised stores. The company stated that the attack targeted Ribon, which was installed on hundreds of BigCommerce stores, and that the attackers leveraged the compromised key to access data within the BigCommerce platform, rather than breaching BigCommerce's core systems directly.
In response to the incident, BigCommerce confirmed that the API credentials for Ribon and Ribon 1.5, both operated by Be A Part Of, were compromised due to a Fastr system compromise. The attackers used these credentials to inject malicious scripts into a limited number of merchant storefronts. BigCommerce emphasized that this was not a breach of their own systems or the core BigCommerce platform.
While the Ribon applications are third-party tools that merchants independently install, BigCommerce took action to protect its customers. The company uninstalled the Ribon application from affected stores to revoke the attackers' access, notified merchants directly, and provided log data to assist the developer's investigation. This proactive stance aimed to limit further harm to merchants and their shoppers.
Details regarding the initial compromise of Ribon or Fastr's systems remain unclear, as neither Be A Part Of nor Fastr have issued public statements regarding the incident. SecurityWeek has reached out to both companies for comment and will update its reporting if further information becomes available. The incident serves as a stark reminder for businesses to rigorously vet third-party applications and monitor their access permissions.