Executive Summary
In September 2026, attackers compromised credentials for Ribon third-party applications on the BigCommerce platform, operated by Be A Part Of (a Fastr company). Between September 13-17, the threat actors used stolen API keys to inject malicious scripts into merchant storefronts and access customer data including names, email addresses, phone numbers, and shipping addresses. BigCommerce immediately removed the compromised applications and notified affected merchants, with companies like Master of Malt confirming exposure of shopper information. While BigCommerce's core platform remained secure, the incident demonstrates the expanding attack surface created by third-party integrations in e-commerce ecosystems. This supply chain compromise highlights the growing trend of attackers targeting less-secured vendor applications to reach high-value customer databases, particularly as organizations increasingly rely on SaaS integrations for enhanced functionality.
Why This Matters Now
Third-party app compromises are accelerating as attackers exploit the expanded attack surface of integrated SaaS platforms, making vendor security assessments and API key management critical priorities for preventing supply chain breaches.
Attack Path Analysis
Attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into BigCommerce merchant storefronts, accessing customer data between September 13-17, 2026. The attack leveraged supply chain compromise of the Ribon app's API keys to gain unauthorized access to merchant environments and extract customer personal information including names, emails, phone numbers, and addresses.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers compromised credentials for Ribon and Ribon 1.5 applications operated by Be A Part Of/Fastr, gaining access to BigCommerce API keys
MITRE ATT&CK® Techniques
Valid Accounts
Supply Chain Compromise: Compromise Software Dependencies and Development Tools
Trusted Relationship
Data from Information Repositories: Code Repositories
Command and Scripting Interpreter: JavaScript
Browser Session Hijacking
Data from Cloud Storage Object
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Third-Party Service Provider Risk Management
Control ID: 12.8.4
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.11
GDPR – Processor Security Obligations
Control ID: Article 28
DORA – ICT Third-Party Risk Management
Control ID: Article 28
CISA ZTMM 2.0 – Application Identity and Access Management
Control ID: Application Security
NIS2 Directive – Supply Chain Security Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Retail Industry
Supply-chain attacks targeting e-commerce platforms expose customer data through compromised third-party apps, requiring enhanced egress security and zero trust segmentation controls.
Food/Beverages
Online beverage retailers like Master of Malt face customer data exposure through BigCommerce third-party app compromises, necessitating multicloud visibility and threat detection capabilities.
Computer Software/Engineering
Third-party application developers face credential compromise risks enabling malicious script injection into merchant platforms, requiring kubernetes security and cloud firewall protections.
Wine/Spirits
Spirits vendors suffer customer data breaches through compromised e-commerce platform integrations, highlighting need for encrypted traffic controls and anomaly response systems.
Sources
- BigCommerce alerts merchants of data breach linked to Ribon appshttps://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/Verified
- Master of Malt Data Security Incident Noticehttps://www.masterofmalt.com/sorry/Verified
- BigCommerce App Data Breach - Legal Informationhttps://www.emeryreddy.com/blog/data-breach/bigcommerce-app-breachVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have reduced the blast radius of this BigCommerce supply chain attack by constraining lateral movement between merchant environments and limiting data access scope through segmented API interactions.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust network segmentation would likely have limited the scope of compromised application access by restricting API key reach to specific merchant environments rather than broad platform access
Control: Zero Trust Segmentation
Mitigation: Workload-level segmentation would likely have constrained privilege escalation by isolating API access permissions and limiting cross-tenant resource visibility within the BigCommerce platform
Control: East-West Traffic Security
Mitigation: Microsegmentation controls would likely have reduced lateral reach between merchant environments by enforcing strict inter-tenant traffic policies and limiting cross-store access patterns
Control: Multicloud Visibility & Control
Mitigation: Network visibility controls would likely have detected anomalous script injection patterns and constrained persistent access by monitoring east-west traffic flows between compromised applications and merchant resources
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely have constrained data exfiltration volume by enforcing strict outbound traffic controls and limiting external communication paths from compromised merchant environments
While regulatory notifications would still be required, the constrained blast radius from Zero Trust segmentation would likely have reduced the total number of affected merchants and customers requiring notification
Impact at a Glance
Affected Business Functions
- E-commerce Operations
- Customer Data Management
- Online Payment Processing
- Third-party App Integration
Estimated downtime: 1 days
Estimated loss: N/A
Customer personal information including full names, email addresses, phone numbers, and shipping postal addresses of multiple BigCommerce merchants using Ribon applications. Master of Malt and potentially hundreds of other online retailers affected. Payment card information and account passwords were not compromised as they are stored separately.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate third-party application access and limit scope of credential compromise through identity-based policies and least privilege enforcement
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts and malicious script communications to external destinations
- • Enable Multicloud Visibility & Control to monitor anomalous interactions between third-party applications and detect suspicious automation patterns across merchant environments
- • Establish Threat Detection & Anomaly Response capabilities to baseline normal third-party application behavior and alert on credential misuse or unauthorized access patterns
- • Implement Encrypted Traffic controls to protect customer data in transit and prevent interception during exfiltration attempts through line rate encryption and secure private circuits



