By Interestana AI Editorial — AI-drafted, human-overseen. How we report
BigCommerce Reports Data Breach Via Third-Party Ribon Apps
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches that occurred after attackers compromised credentials for third-party Ribon applications. These compromised credentials were then used to inject malicious scripts into the online stores hosted on the BigCommerce platform. The breach was identified when BigCommerce's security team detected suspicious activity and initiated an investigation. The company has stated that the attackers gained access to customer data through these compromised third-party applications, rather than directly breaching BigCommerce's core infrastructure.
Ribon is a company that provides various applications and integrations for e-commerce businesses, often used to enhance store functionality, marketing, and customer engagement. By compromising the credentials for these Ribon applications, the attackers were able to bypass standard security measures and inject code that could potentially exfiltrate sensitive customer information or disrupt store operations. BigCommerce has not disclosed the exact number of merchants affected by this incident, nor the specific types of data that may have been accessed. However, the nature of e-commerce data breaches typically involves customer names, email addresses, shipping addresses, and potentially payment information, depending on the scope of the compromise and the scripts injected.
In response to the incident, BigCommerce has taken immediate steps to mitigate the impact. This includes working with affected merchants to remove the malicious scripts from their stores and assisting them in securing their accounts. The company has also advised merchants to review their connected applications, change passwords for their Ribon accounts and any other third-party services, and monitor their store activity for any further anomalies. BigCommerce is also conducting a thorough review of its security protocols and its vetting process for third-party applications to prevent similar incidents in the future. The company has committed to providing ongoing support and information to its merchants as the investigation progresses. The incident highlights the growing risks associated with supply chain attacks, where vulnerabilities in third-party services can have significant downstream effects on businesses and their customers.
This breach underscores the critical importance of robust security practices for all components of an e-commerce ecosystem. Merchants relying on third-party applications must remain vigilant, regularly auditing the permissions granted to these services and ensuring that their credentials are strong and unique. BigCommerce's proactive notification to its merchants is a crucial step in enabling them to take timely protective measures. The company's ongoing investigation aims to fully understand the extent of the compromise and to implement necessary safeguards to enhance the security posture of its platform and the businesses operating on it. Further details regarding the specific vulnerabilities exploited and the full scope of data impacted are expected to be released as the investigation concludes.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.