BigCommerce confirmed that stolen credentials for Ribon, a third-party storefront app, let attackers plant malicious scripts on some merchants’ stores and pull shoppers’ names, email addresses, phone numbers, and shipping addresses between September 13 and 17. BigCommerce told BleepingComputer that only a small number of storefronts were hit and that it uninstalled Ribon and Ribon 1.5, both made by Fastr’s Be A Part Of, from those stores to cut off the attackers. UK spirits seller Master of Malt, which warned its own customers, said Ribon ran on hundreds of BigCommerce stores, though passwords and payment details sat in a separate system that wasn’t breached. Law firm Emery Reddy says several retailers are now notifying shoppers, and it’s recruiting people for potential claims.






