Skip to content

BigCommerce

Disclosed Sep 21, 20264 days agoUnverified

BigCommerce merchants' customer data stolen via compromised Ribon apps

BigCommerce alerted merchants that attackers used compromised credentials for third-party Ribon apps to inject scripts into stores and pull customer records through its APIs between September 13 and 17. Passwords and card data were not taken; Master of Malt was among affected stores.

What is known

People affectedNot stated in the sources we have
DisclosedSep 21, 2026
DiscoveredSep 17, 2026
AttackSupply chain
Data exposedNames, Emails, Phone numbers, Addresses
SectorTech · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalSep 21
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about BigCommerce

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.