**BigCommerce Customers Hit by Data Breach Linked to Compromised Ribon Apps**
A disturbing data breach has affected multiple merchants using the popular e-commerce platform BigCommerce, after hackers compromised credentials for third-party Ribon applications and injected malicious scripts into online stores. The breach is a stark reminder of the importance of secure integrations and the need for vigilance in protecting customer data.
The incident began on September 13, when attackers exploited a vulnerability in the Ribon apps, which are used by over 1,200 third-party applications and integrations on the BigCommerce platform. Between September 13 and September 17, the hackers accessed shopper data stored on BigCommerce environments, using the compromised credentials to inject malicious scripts into online stores.
UK-based online spirits vendor Master of Malt is one of the merchants affected by the breach, with the attackers accessing customer information including full names, email addresses, phone numbers, and shipping postal addresses. “It looks like hackers were able to compromise a BigCommerce Application key held by Ribon, which they were able to use to gain access to customer data held on their system,” Master of Malt stated in an update on the incident.
BigCommerce has confirmed that its systems or platform were not breached, but rather the attackers exploited a vulnerability in the third-party applications. The company removed the compromised apps from affected stores and notified merchants directly, while also providing log data to support the developer’s investigation.
The breach is similar to a 2024 incident affecting electronics accessory maker ZAGG, where attackers compromised a third-party BigCommerce app and injected payment-skimming code into its online store. However, in this case, the hackers used a compromised application key to access existing customer records through BigCommerce, rather than capturing payment information entered by customers during checkout.
The incident highlights the importance of secure integrations and the need for e-commerce platforms to prioritize data protection. With over 1,200 third-party applications and integrations on its platform, BigCommerce must ensure that these apps are thoroughly vetted and secured to prevent similar breaches in the future.
**What Can Merchants Do?**
The breach serves as a stark reminder of the importance of secure integrations and regular security audits. Merchants using BigCommerce or any other e-commerce platform should take immediate action to:
* Review their integrations and ensure that they are secure and up-to-date
* Conduct regular security audits to identify potential vulnerabilities
* Educate customers on data protection practices, such as using strong passwords and enabling two-factor authentication
By taking proactive steps to protect customer data, merchants can minimize the risk of similar breaches in the future.
Source: Bleeping Computer — 2026-09-21