BigCommerce has alerted multiple merchants to a data breach after attackers compromised credentials for third-party applications and used them to inject malicious scripts into online stores, potentially exposing customer information.
The cloud-based e-commerce platform confirmed the credential compromise on September 17 and immediately removed the affected applications to protect customers. UK-based online spirits vendor Master of Malt was among the merchants that received a notification about the incident.
How Did Attackers Access BigCommerce Stores?
The attackers used compromised credentials to gain access to shopper data in BigCommerce environments between September 13 and September 17.
Master of Malt said potentially affected shopper information included full names, email addresses, phone numbers and shipping postal addresses.
The incident involved third-party applications operating within the BigCommerce ecosystem rather than a breach of the BigCommerce platform itself.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Which Third-Party Apps Were Involved?
Master of Malt said it appeared hackers had compromised a BigCommerce application key held by Ribon, allowing access to customer data stored on its system.
BigCommerce supports more than 1,200 third-party applications and integrations, including Ribon, an application operated by Be A Part Of, which specialises in shopping experience optimisation.
The e-commerce platform said it stores account passwords and payment card information separately and that this type of data was not exposed.
What Did BigCommerce Say About the Breach?
In a statement concerning SleepingComputer, BigCommerce said an attacker had compromised credentials for Ribon and Ribon 1.5 applications.
The company said it identified unauthorised access on September 17 and immediately removed the applications from its platform.
BigCommerce also underlined that its own systems and the BigCommerce platform were not breached.
How Were Customer Records Accessed?
According to the information provided to customers, attackers captured payment information entered by shoppers during checkout.
The Ribon attackers allegedly used a compromised application key to access existing customer records through BigCommerce.
Master of Malt reported the incident to the UK Information Commissioner’s Office and said it may extend its review into its own customers and potentially hundreds of other stores.
What Other Retailers May Be Affected?
Several retailers were examining whether their customers could have been exposed in connection with the incident.
Law firm Emery Reddy was seeking potential claimants linked to the breach, saying several retailers were notifying customers about data exposure connected to the Ribon application key theft.
SleepingComputer contacted Be A Part Of and Fast for more information about the incident but had not received a response by publication time.
Is the Incident Similar to Earlier Supply-Chain Attacks?
The breach was described as similar to a 2024 incident affecting electronics accessory maker ZAGG, where attackers compromised the third-party FreshClick BigCommerce application and injected payment-skimming code into its online store.
In the latest case, the attackers again appear to have exploited access associated with a third-party application rather than directly breaching the BigCommerce platform.
What Does the Incident Mean for Merchants?
The incident highlights the exposure that can arise when third-party applications are connected to online stores and receive access to customer information. Even when the underlying commerce platform is not breached, compromised application credentials can provide attackers with a route to merchant environments and customer records.
BigCommerce said it had removed the compromised applications from customers’ stores after detecting the unauthorised access.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics