Executive Summary
In mid-September 2026, attackers abused stolen API / application access credentials for the BigCommerce App Marketplace apps Ribon and Ribon 1.5, owned and operated by Be A Part Of, a Fastr company. Those credentials were used to access shopper/customer records for merchants who had installed the apps and, for a small number of storefronts, to inject malicious scripts.
BigCommerce states this was not a breach of Commerce systems or the BigCommerce platform. Impact required a merchant to have independently installed a Fastr-developed application. There is no CVE for this incident — it is a third-party marketplace app credential / trusted-relationship fan-out, not a disclosed vulnerability in BigCommerce core software. As of 1 October 2026, CISA KEV contains no BigCommerce / Ribon / Fastr entries related to this event.
Technical Information
What was compromised
According to BigCommerce’s Trust Center notice (“Security Notice Regarding Third-Party Fastr Applications”) and statements to BleepingComputer (21 September 2026), SecurityWeek (22 September 2026), and The Register (23 September 2026):
- Credentials: API credentials belonging to third-party application developer Be A Part Of (a Fastr company) for marketplace apps Ribon and Ribon 1.5.
- Cause (vendor wording): Compromised “as a result of a Fastr system compromise.” The initial mechanism of credential theft has not been publicly detailed.
- Abuse: Unauthorized use of the stolen application access key to (a) access customer/shopper data associated with installs and (b) inject malicious scripts into a small number of merchant storefronts.
- Platform scope: BigCommerce reiterates platform-not-breached; merchants were affected only if they had installed a Fastr-developed app.
Trust Center: https://security.bigcommerce.com/
Confirmed abuse window
Master of Malt (a publicly disclosing UK merchant) reported unauthorized use of the stolen key from approximately 13 September 2026 17:21 BST through 17 September 2026 21:12 BST, when the key was revoked and Ribon access was removed from their storefront. Broader reporting aligns with a 13–17 September 2026 abuse window; merchant notification and media coverage concentrated 18–23 September 2026.
Confirmed merchant impact example (Master of Malt)
Master of Malt’s public customer notice and technical write-up state that attackers accessed name, email, phone number, and address. Passwords and payment card data were stated as stored separately and not accessed. The retailer notified customers on 18 September 2026, published https://www.masterofmalt.com/sorry, reported to the UK ICO (case ref IC-569770-Y1R9), and received a private email from Fastr’s CEO (~18 September 2026 ~18:55 BST) confirming the Fastr/Ribon compromise. Master of Malt also stated Ribon was installed on “hundreds” of BigCommerce stores — a merchant-sourced figure, not a BigCommerce-published global count.
Platform response (as reported)
- BigCommerce confirmed the credential compromise on 17 September 2026.
- Affected Ribon apps were uninstalled from stores to revoke attacker access.
- Affected merchants were notified directly.
- Log data was provided to support the developer’s investigation.
- Merchants are directed to support@getfastr.com via the Trust Center notice.
App-vendor public statement
As of OSINT research date (1 October 2026), no standalone public blog or press release from Be A Part Of / Fastr was located. Primary journalism (BleepingComputer, SecurityWeek) similarly reported no public vendor response at publication time. Private confirmation to Master of Malt is the clearest direct vendor acknowledgment sourced for this advisory.
Attribution and ATT&CK
Primary sources describe unidentified attackers. No named threat actor is confirmed. Public IoCs and vendor ATT&CK mappings are not published by BigCommerce, Fastr/Be A Part Of, or Master of Malt. Do not invent attribution or technique IDs.
Affected Product Versions
This incident is not a versioned product CVE. Scope is install- and credential-based:
| Entity | Role | What was in scope |
|---|---|---|
| Be A Part Of (Fastr company) | App developer/operator | API credentials for its BigCommerce apps compromised via Fastr system compromise (BigCommerce wording) |
| Ribon and Ribon 1.5 | BigCommerce App Marketplace third-party apps (storefront / shopping-experience optimization) | Compromised application/API credentials used for data access and, on some stores, script injection; apps uninstalled ~17 September 2026 |
| BigCommerce / Commerce.com | Ecommerce SaaS platform | Platform stated not breached; hosted merchant data reachable via third-party app API scopes; keys revoked, apps removed, merchants notified |
| Merchants who installed Ribon / Ribon 1.5 | Downstream victims | Shopper PII access risk; script injection for a “small number” of storefronts |
| Master of Malt | Confirmed public disclosing merchant | Name, email, phone, address accessed; passwords/payment not accessed per MoM |
Open scale gaps (do not invent numbers): BigCommerce has not publicly quantified total merchants or shoppers affected. Script injection is described as a “small number” of storefronts; MoM’s “hundreds” of Ribon installs is not reconciled to a platform-wide figure. Whether other Fastr-developed BigCommerce apps shared the same compromised credential plane is not fully detailed beyond Trust Center language about Fastr-developed applications.
Workaround and Mitigation
Sourced merchant and platform guidance across Master of Malt hardening notes, BigCommerce actions, and secondary coverage:
- Confirm removal: Ensure Ribon and Ribon 1.5 (and any related Fastr / Be A Part Of apps) are fully uninstalled from the storefront; revoke residual OAuth/API scopes.
- Rotate credentials: Rotate BigCommerce store/API tokens and accounts that third-party apps could have seen — not only Ribon-specific credentials.
- Audit the abuse window: Review store audit/access logs for 13–17 September 2026 (and adjacent days) for anomalous bulk customer data pulls and Script Manager / theme / content changes.
- Storefront hygiene: Scan and remove any residual injected scripts after app removal.
- Customer risk: Where PII may have been accessed, notify affected shoppers as required; warn on phishing, smishing, and vishing that misuse exposed contact and address data.
- Inventory and least privilege: Inventory all marketplace apps with customer PII read scopes or script-injection capability; reduce scopes and remove unused apps.
- Vendor contact: For Fastr/Ribon-specific questions, Trust Center points to support@getfastr.com.
Indicators of Compromise
None published in open sources reviewed for this advisory: no attacker IPs, domains, malware hashes, or injected-script samples from BigCommerce, Fastr/Be A Part Of, Master of Malt, BleepingComputer, SecurityWeek, or The Register.
Do not invent hashes, IPs, domains, or ATT&CK IDs for this advisory.
Why this matters for third-party / vendor risk
A single marketplace-app API key held by a third-party vendor can reach shopper PII and storefront extensibility across every merchant that installed the app — classic third-party / software-supply-chain fan-out without a platform CVE. For ecommerce suppliers and internal store owners on BigCommerce (and peer platforms), treat Ribon / Ribon 1.5 / Be A Part Of / Fastr as a concrete reminder to inventory apps with PII and script scopes, demand credential-storage and notification SLAs from app vendors, and verify uninstall, token rotation, and log review for the September 2026 window.
Forwardable blurb for your TPRM / vendor-risk owner:
"Please confirm whether any of our BigCommerce (or peer) storefronts currently or previously used Ribon, Ribon 1.5, or other Fastr / Be A Part Of marketplace apps; whether those apps are fully uninstalled with residual API scopes revoked; whether store API tokens were rotated after 17 September 2026; and whether audit logs for 13–17 September 2026 were reviewed for bulk customer exports or Script Manager / injected-script changes. Provide evidence of app inventory (least privilege) and merchant notification status if customer PII may have been exposed."
Sources (selected)
- BigCommerce Trust Center — Security Notice Regarding Third-Party Fastr Applications: https://security.bigcommerce.com/
- BleepingComputer, 21 September 2026: https://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/
- SecurityWeek, 22 September 2026: https://www.securityweek.com/bigcommerce-data-stolen-via-ribon-apps-hack/
- Master of Malt customer notice: https://www.masterofmalt.com/sorry
- Master of Malt technical write-up: https://www.masterofmalt.com/sorry/technical/
- The Register, 23 September 2026: https://www.theregister.com/cyber-crime/2026/09/23/bigcommerce-app-breach-spills-master-of-malt-customer-data/5298377
- TechRadar, 22 September 2026 (secondary synthesis)
- CISA KEV feed catalogVersion 2026.09.30 — 0 BigCommerce/Ribon/Fastr matches (checked 2026-10-01)



