This is a dedicated page related to the Ribon application security incident. Our goal is to be fully transparent of the incident. Fastr’s investigation and forensics are ongoing including the engagement of third-party security consultants. We plan to continue to share information and facts through communications such as this, so our customers have the information they need to support their processes. We are very sorry for the disruption this is causing our clients and encourage you to reach out with any questions to support@getfastr.com.
Beginning on or around September 12, 2026, Ribon, an application for BigCommerce custom site development from Be A Part Of, the custom design and development arm of Fastr, was subject to an attack by a malicious threat actor. All storefronts using Ribon were affected. No other products or services in the Fastr portfolio were involved. MiniBC, Publicator, Creator, Fastr Frontend, Fastr Optimize, and Fastr Workspace run on separate infrastructure and were not affected by this incident.
All client stores using the Ribon app were affected, including sandboxes and development/staging stores. Customer data was accessed and exfiltrated from all affected stores.
So far, our investigation shows the malicious threat actor gained access to customer data that included individual customer names, email addresses, phone numbers, billing and shipping addresses and transactional information associated with order history, including products purchased, quantities, order dates, order status, and order values. All customer data and all order history that clients had in their BigCommerce store was available to the actor and should be assumed to have been taken or copied by the actor.
So far, we have not found any evidence that payment card numbers or verification codes (CVVs) were taken. We have not found any evidence that passwords were taken. At this time, we do not believe that the attack vector would allow the malicious threat actor to access payment information or passwords, but we are still investigating to ensure this is the case.
Some client stores were subject to additional unauthorized activities involving the creation of unauthorized coupon codes. We have not yet found that any of these were successfully used. The actor also attempted to utilize impersonation tokens on some client stores. Again, at this time our investigation indicates none of these attempts were successful.
Fastr has worked to investigate and remediate the security incident as quickly as possible, collaborating closely with BigCommerce. So far Fastr has:
Fastr continues working with BigCommerce and the 3rd party security consultant to fully investigate the extent of the security incident as quickly as possible. We do not yet have an estimated timeframe for completing the investigation and analysis. We will immediately update clients with this and all other pertinent information as it becomes available.
We believe that the root cause identified above has been remediated for client stores and they are now safe to operate. We have removed unauthorized JavaScript and webhooks, rotated API keys to render the ones the attacker obtained ineffective, closed the path the attackers used to obtain keys, and begun further securing the system.
Affected clients should check their stores for the unauthorized “Order Status” page and the unauthorized coupon code, and remove both if present. Instructions were included in our email notices and we can assist with any questions.
Clients who have specific questions about how the incident affected their store can contact us at support@getfastr.com, or through the channels we provided in our September 19 notice.
Updated Friday, September 25