BigCommerce

Sep 2026 · Graded Attested · Retail and Consumer · Beyond the filings
BigCommerceSep 2026
Not yet quantified
AAttested
BigCommerce confirmed on September 17, 2026, that compromised credentials from Ribon and Ribon 1.5, third-party apps built by 'Be A Part Of,' a Fastr company, let attackers inject malicious scripts into merchant storefronts. One access key belonging to a single app vendor unlocked data across every store that had installed it, hundreds by Master of Malt's count, not the 'small number' BigCommerce named. The app marketplace was the real perimeter, and nobody was guarding it like one. What BigCommerce calls scope is really just how far one vendor's key happened to reach.
Retail and Consumer
BigCommerce warns customers of potential data leaks following cyber incident
Initial attack type third-party or supply chain confirmed · Impact data theft inferred
About this record
This incident is beyond the filings: attributed to a company statement, a regulator or court record, or a news report, and graded Attested or Inferred. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.
← The complete Beyond the Filings ledger ← Back to the index