BigCommerce has notified several merchants about data exposure linked to compromised third-party application credentials. Attackers used the stolen Ribon credentials to access customer records and inject malicious scripts into online stores.

Attackers Compromise Ribon Application Credentials

BigCommerce confirmed the credential compromise on September 17. The incident affected the Ribon and Ribon 1.5 applications.

Both apps belong to Be A Part Of, a Fastr company that develops tools for improving online shopping experiences.

Attackers used the compromised credentials between September 13 and September 17. During that period, they accessed shopper data within affected BigCommerce environments.

Furthermore, the intruders injected malicious scripts into a small number of merchant storefronts.

BigCommerce supports more than 1,200 third-party applications and integrations. However, the company stressed that attackers did not breach its platform or internal systems.

Master of Malt Confirms Customer Data Exposure

UK online spirits retailer Master of Malt received a breach notification from BigCommerce.

The company said attackers accessed customers’ full names and email addresses. Exposed records also included phone numbers and shipping addresses.

Master of Malt believes the attackers compromised an application key held by Ribon. They then used that key to reach customer data stored within the ecommerce environment.

However, the incident did not expose account passwords or payment card details. BigCommerce stores that information separately from the affected data.

BigCommerce Removes Apps From Stores

After confirming the Ribon app breach, BigCommerce removed the affected applications from impacted stores.

This action revoked the attacker’s access to merchant environments. The company also contacted affected merchants directly.

In addition, BigCommerce provided log information to support the application developer’s investigation.

The company has not disclosed the exact number of affected stores. However, Master of Malt warned that the incident could involve hundreds of other merchants.

Several retailers have reportedly started notifying customers about exposure linked to the stolen application key.

Retailer Reports Breach to UK Regulator

Master of Malt reported the incident to the UK Information Commissioner’s Office.

Meanwhile, a law firm has started seeking potential claimants connected to the breach. It says several retailers are sending notifications about Ribon-related data exposure.

Be A Part Of and Fastr had not publicly responded to requests for further information when the incident became public.

Incident Resembles Previous App Compromise

The breach resembles a 2024 incident involving electronics accessory maker ZAGG.

In that case, attackers compromised a third-party BigCommerce application called FreshClick. They then injected payment-skimming code into the retailer’s online store.

However, the two incidents differ in an important way. The ZAGG attackers captured payment information that customers entered during checkout.

By contrast, the Ribon attackers used a stolen application key to access existing customer records. Therefore, the Ribon app breach exposed personal details but not payment card information.

The incident highlights the risks that third-party applications can introduce into ecommerce environments. Merchants should review installed integrations and monitor application access for unusual activity.


0 responses to “BigCommerce Warns Merchants of Ribon App Breach”