Ecommerce platform BigCommerce has informed its merchants about data breaches resulting from attackers compromising credentials for Ribon applications. These compromised credentials allowed attackers to inject malicious scripts into various online stores hosted on the BigCommerce platform. The incident was confirmed on September 17, after which BigCommerce removed the affected applications to prevent further unauthorized access.
The breach led to the exposure of shopper information, including full names, email addresses, phone numbers, and shipping postal addresses. Master of Malt, a UK-based online spirits vendor and a BigCommerce customer, confirmed receiving a notification about the incident and stated that its shopper data was accessed. The unauthorized access to shopper data occurred between September 13 and September 17.
The compromise specifically targeted credentials for Ribon and Ribon 1.5 applications, which are operated by 'Be A Part Of,' a Fastr company specializing in shopping experience optimization. BigCommerce clarified that its own systems and platform were not breached directly; rather, the vulnerability originated from the third-party application credentials. The company emphasized that account passwords and payment card information are stored separately and were not exposed in this incident.
Upon discovering the compromise, BigCommerce uninstalled the Ribon applications from affected stores to revoke attacker access and directly notified the impacted merchants. The company is also providing log data to support the developer's investigation into the incident. Master of Malt has reported the breach to the UK Information Commissioner’s Office (ICO), indicating that the scope of the incident could extend to hundreds of other stores beyond its own customer base.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
BigCommerce customer data, including names and addresses, was stolen after hackers compromised an application key belonging to Ribon, a third-party app. The attackers used the key to access data between September 13 and September 17, impacting merchants using the Ribon app.
BigCommerce has notified merchants of data breaches stemming from compromised credentials for third-party Ribon applications, which attackers used to inject malicious scripts into online stores. The breach exposed shopper information such as names, email addresses, phone numbers, and shipping addresses, affecting multiple BigCommerce customers.