Skip to main content
Jump to a category page

A stolen access key gave hackers days of access to customer data through Ribon, a third-party app used by online stores built on the BigCommerce platform. If you shop at a retailer that uses BigCommerce, you may have received, or may still receive, a breach notice tracing back to this incident.

A number of online retailers that use the BigCommerce e-commerce platform have begun notifying customers of a data breach that originated not with the retailers themselves, but with a third-party application called Ribon. Ribon is owned and operated by Be A Part Of, which describes itself as a brand of Fastr, a digital commerce technology company. According to breach notification emails retailers have started sending to their customers, attackers compromised a BigCommerce application key held by Ribon and used it to access customer data stored on Ribon’s system — data belonging to the customers of every retailer that had the Ribon app installed.

The Timeline

According to the notification retailers are sending, the key facts are:

  • Unauthorized access began Sunday, September 13, 2026, and continued until Thursday, September 17, 2026, when the stolen access key was revoked
  • BigCommerce’s security team uninstalled the affected Ribon app from retailer stores on September 17, 2026
  • Retailers began notifying their own customers shortly after

What Information Was Exposed?

Retailers’ notification emails describe the exposed information as names, email addresses, phone numbers, and physical addresses. Retailers are telling customers that passwords, credit card numbers, and other payment information were not exposed, because that information is reportedly held in a separate system that was not compromised. Emery | Reddy has not independently verified this claim and is reporting it as the retailers’ own representation.

One Vendor, Many Retailers

This is a supply-chain breach: the vulnerability sat with Ribon, not with any individual retailer, which means every store that had the Ribon app connected to its BigCommerce site is potentially affected — not just one company’s customers. If you’ve received a breach notice from a retailer that explains the incident traces back to a BigCommerce app, Ribon, Be A Part Of, or Fastr, you’re likely dealing with this same underlying event, even if the retailer that emailed you isn’t named in this post. This kind of app-level compromise isn’t unheard of on the BigCommerce platform — a separate incident in late 2024 saw hackers compromise a different third-party BigCommerce app to steal payment card data from a national retailer’s customers, and BigCommerce again had to uninstall the compromised app across affected stores.

Watch for Phishing

Even without passwords or payment data, the combination of your name, email, phone number, and address is exactly what scammers use to run convincing phishing and vishing (phone-based phishing) attacks. Be cautious of anyone contacting you by phone, text, or email claiming to be from a retailer you shop with and asking you to click a link, confirm payment details, or provide a password. Legitimate retailers generally will not ask for that information over email or phone.

Do You Have Legal Options?

Companies that build customer-facing technology on shared platforms like BigCommerce, and the retailers that install their apps, have a legal duty to secure the personal information they handle and to notify affected customers without unreasonable delay.

If you were notified about this breach — by BigCommerce, Ribon, Be A Part Of, Fastr, or by a retailer you shop with — contact Emery | Reddy today for a Free Case Review.

FAQ

I got a breach notice from a retailer I shop with. Is this the same breach?

If the notice mentions BigCommerce, an app called Ribon, Be A Part Of, or Fastr, yes — you’re likely affected by this same incident, even if the specific retailer isn’t named in this post. Many retailers using BigCommerce may have had the Ribon app installed.

What information was exposed?

According to retailers’ own notification emails, the exposed information includes names, email addresses, phone numbers, and physical addresses. Retailers state that passwords and payment card information were not exposed because they’re held in a separate system.

Was my password or credit card stolen?

Retailers are telling customers no — that passwords and payment information are held in a separate system that wasn’t compromised. We haven’t independently verified this and are reporting it as the retailers’ own representation. It’s still worth watching your accounts and changing your password as a precaution.

Why is a third-party app responsible for my retailer’s data breach?

Many online stores built on platforms like BigCommerce connect third-party apps to add features like loyalty programs, personalization, or customer engagement tools. Those apps often get access to customer data as part of how they work. When the app itself is compromised — in this case, by a stolen access key — customer data can be exposed even though the retailer’s own systems were never breached.

Has this happened with BigCommerce apps before?

Yes. A different BigCommerce third-party app was compromised in a separate incident in late 2024, exposing payment card data for a national retailer’s customers. This new incident involves a different app (Ribon) and different data, but reflects the same kind of supply-chain risk.

Do I have a legal claim?

Companies that build customer-facing technology on shared commerce platforms, and the retailers that use their apps, have a legal duty to secure the personal information they handle and to notify affected customers without unreasonable delay. If you were notified about this breach, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now