Breach

BigCommerce merchants impacted by third-party app data breach

(Adobe Stock)

E-commerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. The cloud-based Software-as-a-Service (SaaS) e-commerce platform confirmed the credential compromise on September 17 and immediately removed the apps to protect its customers, based on information published by Bleeping Computer.

The breach occurred between September 13 and September 17, 2026, when attackers gained access to shopper data via compromised credentials for the Ribon and Ribon 1.5 applications. This allowed them to inject malicious scripts into a small number of BigCommerce merchant storefronts. Affected customer information includes full names, email addresses, phone numbers, and shipping postal addresses. BigCommerce stated that its own systems and platform were not breached, and that account passwords and payment card information were not exposed.

The incident is similar to a 2024 breach affecting ZAGG, though in that case, attackers injected payment-skimming code. Master of Malt, a UK-based online spirits vendor, is one of the affected merchants and has reported the incident to the UK Information Commissioner’s Office. The breach potentially impacts hundreds of other stores, with law firms already seeking potential claimants.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Attack Vector

You can skip this ad in 5 seconds