BigCommerce alerts merchants of data breach linked to Ribon apps

BigCommerce has issued a warning to its merchants after a data breach was linked to third-party Ribon applications. The compromise allowed hackers to inject malicious scripts into online stores, putting customer data at risk.

The breach is believed to have occurred between September 13 and 17, with attackers using compromised credentials for Ribon and Ribon 1.5 applications to gain access to shopper information stored on BigCommerce environments. UK-based retailer Master of Malt was one of the affected merchants, with hackers accessing full names, email addresses, phone numbers, and shipping postal addresses.

The breach is thought to have been facilitated by a compromised application key held by Ribon, which allowed attackers to inject malicious scripts into customer records through BigCommerce. This type of attack differs from previous breaches, where payment information was stolen during checkout. Instead, the hackers used existing customer records stored on BigCommerce to extract sensitive data.

BigCommerce has confirmed that its own systems and platform were not breached, but rather, the compromise occurred through a third-party application. The company has removed the affected Ribon apps from merchant stores and is working with developers to investigate the incident. Merchants who have been impacted are being notified directly by BigCommerce, with some having already reported the breach to regulatory bodies.

The incident highlights the risks associated with using third-party applications on ecommerce platforms like BigCommerce. While these integrations can enhance online shopping experiences, they also introduce new vulnerabilities that can be exploited by hackers. Merchants should take a closer look at their app usage and ensure that any third-party integrations are thoroughly vetted for security.

BigCommerce stores account passwords and payment card information separately from customer data, so this type of sensitive information was not exposed in the breach. However, the incident serves as a reminder to merchants to regularly review their app usage and take proactive measures to protect against data breaches.

The full extent of the breach is still unclear, with some reports suggesting that hundreds of other stores may be affected. Law firm Emery Reddy is seeking potential claimants linked to the incident, indicating that multiple retailers are notifying customers about data exposure related to the Ribon app key theft.

In light of this breach and others like it, merchants should prioritize their cybersecurity efforts by regularly reviewing their app usage, implementing robust security measures, and staying informed about emerging threats. By taking proactive steps to protect against data breaches, businesses can minimize the risk of customer data being compromised in future incidents.


Source: Bleeping Computer — 2026-09-21