BigCommerce
Disclosed Sep 21, 20264 days agoUnverified
BigCommerce merchants' customer data stolen via compromised Ribon apps
BigCommerce alerted merchants that attackers used compromised credentials for third-party Ribon apps to inject scripts into stores and pull customer records through its APIs between September 13 and 17. Passwords and card data were not taken; Master of Malt was among affected stores.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Sep 21, 2026 |
| Discovered | Sep 17, 2026 |
| Attack | Supply chain |
| Data exposed | Names, Emails, Phone numbers, Addresses |
| Sector | Tech · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| BigCommerce alerts merchants of data breach linked to Ribon appsbleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Sep 21 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.