MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-21 · via BleepingComputer

E-commerce platform warns sellers after third-party app credentials stolen

Image via BleepingComputer
Image via BleepingComputer

BigCommerce notified several merchants that attackers used compromised credentials for the Ribon and Ribon 1.5 apps to inject malicious scripts into storefronts. The breach exposed shopper names, emails, phone numbers, and postal addresses between September 13 and 17, but not passwords or payment card data. BigCommerce removed the apps and is assisting the developer's investigation, while one affected retailer, Master of Malt, reported the incident to the UK's data protection authority.

Expanded Detail

The breach affected a small number of merchant storefronts, with BigCommerce uninstalling the apps to revoke attacker access. The company emphasized its own platform was not compromised and is providing log data to support the developer's investigation. Master of Malt reported the incident to the UK's Information Commissioner's Office, and law firm Emery Reddy is seeking potential claimants.

This incident echoes a 2024 breach at electronics accessory maker ZAGG, where attackers compromised the FreshClick BigCommerce app to inject payment-skimming code. However, the Ribon attack differed: hackers used a compromised application key to access existing customer records rather than capturing payment information during checkout. BigCommerce supports over 1,200 third-party applications, underscoring the potential attack surface.

Context

This breach could affect thousands of shoppers who made purchases from BigCommerce-powered stores using Ribon apps, exposing personal details that may enable targeted phishing or social engineering schemes. While payment data was not compromised, the combination of names, emails, phones, and addresses creates meaningful identity-fraud risk. Small merchants relying on third-party integrations may face reputational damage and regulatory scrutiny, particularly in jurisdictions with strict data protection laws like the UK's GDPR framework.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Brevo breach: Stolen Cloudflare key used to push ClickFix malware to client websites · Cybersecurity
Image-sharing platform Gyazo hit by breach affecting 23.6 million accounts · Cybersecurity
ShinyHunters leak Florida driver records after ransom demand unmet · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “BigCommerce alerts merchants of data breach linked to Ribon apps.” Browse more stories.