A man in Leeds ordered a bottle of whisky online for his father’s birthday. He typed his name, his email address, his phone number and his dad’s home address into the checkout page of a shop he trusts. Last week, a company whose name he does not know lost all four. So the next email about “a problem with your Master of Malt order” may be real. Or the people who took the list may have written it. The BigCommerce data breach is that kind of leak: nothing about your own accounts, and everything about the mail that is about to arrive.
Confirmation: confirmed by the company. BigCommerce issued a statement on 17 September 2026 naming the compromised apps, and Master of Malt has written to its customers.
What happened in the BigCommerce data breach
Between 13 and 17 September 2026, attackers used stolen credentials for two third-party apps, Ribon and Ribon 1.5, to inject malicious scripts into BigCommerce storefronts and read shopper data. BigCommerce is the platform behind tens of thousands of online shops. Ribon is an add-on those shops can install to tune their checkout. Be A Part Of, a Fastr company, makes it.
BigCommerce’s statement, as reported by BleepingComputer on 21 September: “On September 17, 2026, BigCommerce confirmed that credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by ‘Be A Part Of,’ a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts.” The company says it uninstalled the app from affected stores, notified those merchants and is handing log data to the developer.
So this is a supply-chain breach. BigCommerce says nobody broke into its own platform. Instead, the attackers came in through an app that merchants had granted access to. Master of Malt, the UK drinks retailer, told customers: “It looks like hackers were able to compromise a BigCommerce Application key held by Ribon, which they were able to use to gain access to customer data held on their system.”
How many people is unknown. BigCommerce says “a small number” of storefronts. Master of Malt believes the incident “may extend well beyond its own customers, potentially to hundreds of other stores”, and a US law firm says several retailers are now writing to customers. Until BigCommerce or Fastr publishes a count, treat the size of the BigCommerce data breach as unconfirmed.
What the BigCommerce data breach exposed
The stolen records hold shoppers’ full names, email addresses, phone numbers and shipping postal addresses. The app could not reach payment card numbers or account passwords, because BigCommerce stores those separately. That is genuinely good news.
But here is what each of the four items is worth to whoever has them:
- Email address plus the shop you bought from. This is the ingredient for a convincing phish. A message that says “your Master of Malt order needs attention” to someone who really did order from Master of Malt gets opened.
- Full name and home address. Enough to make that message name you correctly and quote the right delivery address, so it reads like a real courier notice.
- Phone number. The same trick by text: a fake “delivery fee” or “redelivery” link, dressed as the courier or the shop.
- All four together. A complete profile for identity fraud, and a mailing list that can be sold to anyone who wants to impersonate an online shop.
The attackers injected the scripts into live storefronts. So some shoppers lost their details while placing an order during those five days, not from a database at rest. If you bought from a BigCommerce store between 13 and 17 September, assume the BigCommerce data breach covers you until your shop says otherwise.
What to do now
Most of this is about the next email, not the last purchase.
1. Treat any “problem with your order” message as a phish until proven otherwise. Do not click. Open the shop’s site by typing the address yourself, log in, and check the order there. 2. Do the same for texts about a delivery. A courier does not need a fee paid through a link in a text. If in doubt, use the tracking number from your original confirmation. 3. Watch your card statements anyway. Card numbers were not in this leak, but a phish that follows it will ask for them. If you enter a card on a page you reached from an email, tell your bank. 4. Use a password manager and the strongest sign-in each shop offers. The attackers took no passwords here. Even so, a fake login page dressed as the shop is the standard follow-up. A password manager will refuse to fill it, because the address is wrong. 5. If the shop emails you a notice, read it. It will say which fields it holds on you and whether it has cut off the app. Master of Malt has already written, and other stores are following. 6. Consider a separate email address for shopping. Then a leaked list from one shop does not lead straight to the inbox where your bank and your accounts live.
How OptMsg changes this exposure
Honestly, and at its real size: OptMsg would not have prevented the BigCommerce data breach. The attackers hit the app on the shop’s side, and no choice you make about your own inbox reaches into a retailer’s checkout. What an OptMsg account changes is what the stolen list can do once it is out.
Mail from a sender you have not approved goes to Trash, not your Inbox, and auto-deletes after 30 days. With OptMsg’s patent-pending opt-in technology, only people you approve can reach your inbox. Everyone else goes to Trash. So the fake “your order needs attention” email from a domain you have not seen before lands in Trash, with your real name and address in it. A month later it auto-deletes, and you have not read it. The real shop, which you approved when you ordered, still reaches you.
The second mechanism matters less here, but it is true. Your OptMsg account has no password, so a password stolen from another site can’t open your inbox. No passwords left this breach. But the fake login page that follows one exists to collect them, and there is no OptMsg password for it to collect.
What that does not cover: a message from the real shop’s address if someone takes over its mail account; a text to your phone, which is not email; a phishing page you open yourself; a compromised device; or someone with your unlocked phone. Those are the six steps above.
If you want an inbox that a leaked shopping list cannot fill, see how Simple by Design works, or read how to stop spam emails for good.
Ready for an inbox that only holds the mail you asked for? Create Your Account.
Your Inbox. Your Rules.
Frequently asked questions
What happened in the BigCommerce data breach? Between 13 and 17 September 2026, attackers used compromised credentials for the third-party Ribon and Ribon 1.5 apps to inject malicious scripts into BigCommerce merchant storefronts and access shopper data. BigCommerce confirmed it on 17 September, uninstalled the app from affected stores and notified the merchants.
Was BigCommerce itself hacked? BigCommerce says its platform was not breached. The way in was a third-party app, Ribon, made by Be A Part Of (a Fastr company), whose application credentials were stolen and used against the stores that had installed it.
What information was exposed in the BigCommerce breach? Shoppers’ full names, email addresses, phone numbers and shipping postal addresses. According to BigCommerce, the app could not reach payment card data or account passwords, because it stores them separately.
Which stores were affected by the BigCommerce breach? BigCommerce says “a small number” of storefronts and has not named them. Master of Malt, the UK drinks retailer, has confirmed it was one and has written to customers. A US law firm says several other retailers are notifying customers. No total count has been published.
Would OptMsg have stopped the BigCommerce breach? No. It happened inside a retailer’s checkout, through an app the retailer installed. What OptMsg changes is the aftermath: mail from a sender you have not approved goes to Trash, not your Inbox, so the fake order email built from the stolen list has a shorter path.
Sources
- BleepingComputer: BigCommerce alerts merchants of data breach linked to Ribon apps — 21 September 2026, carrying BigCommerce’s and Master of Malt’s statements
Previous in Breach Breakdown: Gyazo Data Breach: 23 Million Accounts, and Your Screenshots Were the Payload
Next in Breach Breakdown: LimeLeads Data Breach: 17.8 Million People Who Were Never Customers
