BigCommerce has notified an undisclosed number of merchants that attackers used stolen credentials for the third-party Ribon and Ribon 1.5 applications to break into online stores and plant malicious scripts. The ecommerce platform confirmed the credential compromise on September 17 and pulled the apps to shield its customers. The attackers used the compromised credentials to reach shopper data inside BigCommerce environments between September 13 and September 17. BigCommerce said its own systems and platform were not breached.
Master of Malt, a UK-based online spirits vendor, is among the customers that received the alert. The retailer said the attacker reached shopper information. According to Master of Malt, the exposed details include full names, email addresses, phone numbers, and shipping postal addresses. Master of Malt said the breach appeared to stem from a BigCommerce application key held by Ribon that hackers used to reach customer data stored on BigCommerce systems. The retailer reported the incident to the UK Information Commissioner's Office and suggested it could reach hundreds of other stores beyond its own customers.
BigCommerce said an attacker compromised credentials belonging to the Ribon and Ribon 1.5 applications, which are owned and operated by Be A Part Of, a Fastr company. The company said the credentials were used to inject malicious scripts into a small number of merchant storefronts. It added that it uninstalled the application from affected stores to revoke the attacker's access, notified those merchants directly, and is supplying log data to support the developer's investigation. BigCommerce supports more than 1,200 third-party applications and integrations, including Ribon, which focuses on shopping experience optimization.
BigCommerce said account passwords and payment card information are stored separately and that this type of data was not exposed. The Ribon attackers used a compromised application key to reach existing customer records through BigCommerce, a different method than a 2024 breach involving the electronics accessory maker ZAGG. In that earlier case, attackers compromised the third-party FreshClick BigCommerce app and injected payment-skimming code into its online store. BigCommerce said at the time that its platform was not breached and removed the compromised app from customers' stores.
Law firm Emery Reddy is looking for potential claimants tied to the incident, saying several retailers are notifying customers about data exposure linked to the theft of the Ribon app key, without naming any. BleepingComputer said it contacted Be A Part Of and Fastr for more information and had not received a response by publication time. For US merchants and shoppers, the incident highlights the exposure that can flow from third-party applications connected to hosted storefronts, even when the platform's own systems are not compromised.
More cybersecurity news from TechManNews.





