Stolen Ribon app keys expose shopper data across BigCommerce stores

Stolen Ribon app keys expose shopper data across BigCommerce stores. Shoppers had personal information exposed after attackers compromised credentials belonging to the third-party Ribon and Ribon 1.5 applications.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Tuesday, September 22nd, 2026.

Shoppers had personal information exposed after attackers compromised credentials belonging to the third-party Ribon and Ribon 1.5 applications. Between September 13th and September 17th, those credentials were used to access customer records and inject malicious scripts into a small number of BigCommerce storefronts. Reported exposed information included names, email addresses, phone numbers, and shipping addresses. BigCommerce said passwords and payment card information were stored separately and weren’t exposed.

The company also said its own platform wasn’t breached. It removed the affected applications, revoked their access, notified merchants, and provided logs to support the developer’s investigation. Even so, merchants and shoppers still carried the consequences of a compromised integration.

For leaders, the key point is that third-party application keys can function as privileged access to customer environments. Defenders should maintain an inventory of installed commerce apps, review what each one can access, and preserve logs showing customer-data access and storefront changes. Review all ecommerce integrations now, and revoke any key whose owner, permissions, or current business need can’t be verified. The broader lesson is that platform security depends on every connected application and credential holder.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Stolen Ribon app keys expose shopper data across BigCommerce stores
Broadcast by