Post

BigCommerce Alerts Merchants of Data Breach Linked to Ribon Apps

BigCommerce Alerts Merchants of Data Breach Linked to Ribon Apps

BigCommerce Alerts Merchants of Data Breach Linked to Ribon Apps

Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. The cloud-based Software-as-a-Service (SaaS) ecommerce platform confirmed the credential compromise on September 17 and immediately removed the apps to protect its customers.

In a statement for BleepingComputer, BigCommerce said that the attacker compromised credentials for Ribon and Ribon 1.5 applications. The company underlined that its systems or the BigCommerce platform were not breached.

The hacker used the compromised credentials to access shopper data in BigCommerce environments between September 13 and September 17. UK-based online spirits vendor Master of Malt is one of the BigCommerce customers that received the notification. The retailer said the attacker accessed shopper information, including full names, email addresses, phone numbers, and shipping postal addresses. Master of Malt stated, “It looks like hackers were able to compromise a BigCommerce Application key held by Ribon, which they were able to use to gain access to customer data held on their system.” The e-commerce platform says it stores account passwords and payment card information separately and that this type of data was not exposed.

BigCommerce told BleepingComputer that “Acting in the best interest of our customers and their shoppers, we uninstalled the application from affected stores to revoke the attacker’s access, notified those merchants directly, and are providing log data to support the developer’s investigation.” Master of Malt reported the incident to the UK Information Commissioner’s Office (ICO) and noted that it may extend well beyond its own customers, potentially to hundreds of other stores. Law firm Emery Reddy is seeking potential claimants linked to the incident, saying several retailers are currently notifying customers about data exposure linked to the Ribon app key theft, without naming any.

This incident is similar to a 2024 breach affecting electronics accessory maker ZAGG, where attackers compromised the third-party FreshClick BigCommerce app and injected payment-skimming code into its online store. However, unlike the ZAGG incident, where attackers captured payment information entered by customers during checkout, the Ribon attackers used a compromised application key to access existing customer records through BigCommerce.

To read the complete article see: Read full article

🚀 Stay informed and protect your data!

This post is licensed under CC BY 4.0 by the author.