BigCommerce alerts merchants to data breach via Ribon apps
BigCommerce warned merchants that attackers compromised credentials for third-party Ribon and Ribon 1.5 apps and used them to inject malicious scripts into storefronts. Shopper data was accessed between September 13 and 17, exposing names, emails, phone numbers, and shipping addresses.
- Ribon credential compromise confirmed on September 17, 2026
- Shopper data was accessible from September 13 to 17
- Exposed data includes names, emails, phones, and shipping addresses
- Account passwords and payment card data were not exposed
Read next
Security