The platform wasn't breached. Your shoppers' data still left.
Between 13 and 17 September 2026, attackers used compromised credentials belonging to the third-party applications Ribon and Ribon 1.5 to inject malicious scripts into a number of BigCommerce merchant storefronts, harvesting shopper details as they were entered. BigCommerce says its core platform was not compromised, and there is no reason to doubt that. For the merchants involved, it makes very little difference.
What happened
According to BleepingComputer and SC Media, credentials for the Ribon and Ribon 1.5 apps — owned and operated by 'Be A Part Of', a Fastr company — were compromised and used to inject malicious scripts into a small number of merchant storefronts. The shopper data exposed included full names, email addresses, phone numbers and shipping postal addresses.
BigCommerce uninstalled the application from affected stores to revoke the attacker's access, notified those merchants directly and provided log data to support the developer's investigation. Its own infrastructure was not breached; this was a compromise of a third-party app's credentials.
- Window
- 13 to 17 September 2026.
- Mechanism
- Compromised app credentials used to inject scripts into live storefronts.
- Accountable party
- The merchant, who is the controller of their shoppers' personal data.
Why "the platform wasn't breached" is cold comfort
Every modern commerce platform runs an app marketplace, and installing from it feels like a low-risk act — a few clicks, an OAuth screen, a checkbox. What actually happens is that third-party code gains the ability to run on your storefront, in your customers' browsers, with the authority of your domain. A script in that position can read anything typed into a form, including at checkout.
That has three consequences worth being blunt about:
- You remain the controller. Your shoppers gave their details to you. Under the UK GDPR and the GDPR, the notification duty and the accountability sit with the merchant, whatever the contract with the app developer says.
- Your fourth parties are invisible. Ribon was a supplier to the merchants. Whoever compromised its credentials was operating a layer beyond that. Very few merchants could name the app developers on their storefront today, let alone those developers' security practices.
- Card data rules apply to the page, not just the payment form. PCI DSS 4.0 tightened expectations around scripts on payment pages precisely because of this attack pattern. If your storefront takes card details, the inventory and integrity of every script on that page is now an explicit requirement rather than good practice.
What to do this week
- Inventory the apps. List every app installed on every storefront, what permissions it holds and whether anyone still uses it. Uninstalled-but-still-authorised apps are a common finding.
- Remove what you do not use. The cheapest risk reduction available is deleting the app installed for a campaign in 2024.
- Monitor what runs on your pages. Content Security Policy and script integrity monitoring will tell you when something changes. Without them, the first signal is a customer complaint or a bank.
- Know your notification path. If shopper data left through your storefront, you have a clock to meet and a decision to make about telling customers. Working that out during an incident is the expensive way.
The broader point
Supply chain risk in e-commerce is not mainly about your hosting provider. It is about the accumulated pile of small conveniences — reviews widgets, loyalty apps, analytics snippets, chat tools — each of which was installed by someone reasonable for a good reason, and none of which is on anyone's risk register. The work is not glamorous: list them, justify them, monitor them, and remove the ones that no longer earn their place.
Bring your app and supplier estate into one place, and keep watching it.
Explore TPRMCommon questions
No. BigCommerce says its core platform was not compromised. The incident involved compromised credentials for the third-party Ribon and Ribon 1.5 applications, which were used to inject malicious scripts into a small number of merchant storefronts between 13 and 17 September 2026.
The merchant. Shoppers provide their personal data to the store, so the merchant is the controller and carries the notification duty and the accountability, regardless of which supplier's failure caused the exposure.
PCI DSS 4.0 introduced explicit requirements around managing and monitoring scripts on payment pages, including maintaining an inventory of them with a justification for each and detecting unauthorised changes. This incident is the attack pattern those requirements exist to address.
Sources
- BigCommerce alerts merchants of data breach linked to Ribon apps — BleepingComputer, 23 September 2026
- BigCommerce merchants impacted by third-party app data breach — SC Media, 23 September 2026
- BigCommerce warns customers of potential data leaks following cyber incident — TechRadar Pro, 23 September 2026