BigCommerce Data Breach Compromised Shopper Information

Attackers exploited third-party application keys to access customer data across multiple storefronts.

Updated on Sept. 21, 2026 in Cybersecurity

Modern, structural architectural detail of intersecting steel beams and reflective glass panels, symbolizing complex digital infrastructure.
BigCommerce confirmed that attackers accessed customer information after compromising third-party application keys to inject malicious scripts into merchant storefronts last week. AI Illustration. Upload story photo >

Live Poll

Do you trust online retailers to protect your personal information from third-party app security breaches?

BigCommerce has confirmed that attackers gained access to shopper information through compromised third-party applications between September 13 and September 17, 2026. The incident affected customers at multiple merchants, including Master of Malt, by leveraging stolen application keys to inject malicious scripts.

Why it matters

This incident highlights the security risks inherent in platform ecosystems where third-party developers share privileged access to merchant environments. The compromise specifically affected shopper data rather than platform-wide payment credentials or account passwords.

Attackers accessed customer names, email addresses, phone numbers, and shipping addresses by leveraging compromised keys from Ribon and Ribon 1.5 applications. While these applications were removed from the BigCommerce environment, the extent of the storefront exposure beyond the identified merchants is still being determined.

The players

BigCommerce

An open-SaaS e-commerce platform that provides infrastructure and third-party application support for online merchants.

Master of Malt

An online retailer of spirits and whiskies that reported the data breach to the UK Information Commissioner's Office.

Be A Part Of

A Fastr brand responsible for the development and operation of the Ribon applications involved in the security incident.

The details

The breach occurred when attackers compromised third-party application keys, digital credentials used to authenticate software integrations, to inject malicious scripts into merchant storefronts. These scripts allowed unauthorized access to sensitive customer data processed through BigCommerce environments. The affected software was operated by Be A Part Of, a brand under Fastr, and the platform has since revoked access by removing these applications.

Timeline

  1. September 13-17, 2026: Attackers utilized compromised application keys to access customer data.

  2. September 17, 2026: BigCommerce identified the compromise and removed the affected Ribon applications.

The Tech Race

This breach underscores the vulnerability inherent in modern SaaS platforms that rely on expansive third-party application ecosystems. As these platforms race to integrate thousands of plugins to increase merchant functionality, securing the credential exchange between the platform and third-party developers remains the primary security challenge.

Customers who purchased from affected merchants may face an increased risk of phishing or spam due to the exposure of their contact and shipping information. Retailers using the platform should monitor their integration logs and audit all third-party application permissions to prevent similar script injections.

The takeaway

Merchants should immediately review third-party application access rights and monitor storefronts for unauthorized script modifications. Future developments will depend on the findings of the investigation by the UK Information Commissioner's Office into the scale of the customer data exposure.

Further reading

For broader trends in platform security, visit Cybersecurity.

Live Poll

Do you trust online retailers to protect your personal information from third-party app security breaches?