BigCommerce supply chain attack via Ribon app steals customer data
Hackers used stolen API credentials for a third-party app to access customer records from hundreds of BigCommerce stores.
What to know
- Attackers stole API credentials for Ribon, a third-party app used by hundreds of BigCommerce merchants, and accessed customer names, emails, phone numbers, and addresses between Sept. 13–17.
- The breach stemmed from a Fastr system compromise that affected Ribon's parent company; BigCommerce's core platform and payment systems were not compromised.
- BigCommerce uninstalled the affected apps and notified merchants after revoking the key; Be A Part Of and Fastr have not publicly acknowledged the incident.
- The supply chain attack underscores how third-party app integrations can create security risks even when the primary platform remains secure.
“The hackers downloaded customer data working 'page by page' until the compromised key was revoked on September 17, one day after the Ribon developers became aware of its misuse.”
SecurityWeek, Reporting outlet · SecurityWeek ↗
BigCommerce eCommerce SaaS platformBe A Part Of (Fastr subsidiary) Developer of Ribon appMaster of Malt UK spirits retailer affected by breachFastr Parent company of app developer
How it unfolded 1 development · click the chart to see its coverage articlesposts
-
1
SecurityWeek confirms scope and details of supply chain attack
SecurityWeek reports that the attack targeted hundreds of BigCommerce stores using the Ribon app. Customer data stolen included names, email addresses, phone numbers, and addresses. Neither Be A Part Of nor Fastr have publicly acknowledged the incident.
“The attack was against Ribon, which was installed on hundreds of BigCommerce stores. Once the attackers compromised an access key from Ribon, they used it to access data held inside BigCommerce.”
— Master of Malt -
first by SecurityWeek, 1d ago
-
B
BigCommerce Merchants Suffer Data Breach via Compromised Ribon App API Credentials BigCommerce merchants suffered a data breach after attackers stole API credentials for the third-party Ribon application to steal customer records and inject malicious scripts. The incident affected multiple retailers, including Master of Malt, but did not…
-
-
background
Master of Malt publishes technical details of the attack — A UK spirits retailer affected by the breach released a technical write-up documenting how attackers exploited the compromised Ribon credentials to download customer data page by page until the key was revoked.
-
background
BigCommerce uninstalls Ribon apps and notifies affected merchants — After disabling the compromised credentials, BigCommerce uninstalled the Ribon applications from affected stores and began directly notifying merchants of the incident. Master of Malt and other affected retailers reported the breach to regulators and customers.
-
background
BigCommerce revokes compromised Ribon API credentials — The compromised API key was disabled, stopping the attackers' access. BigCommerce confirmed that API credentials belonging to Ribon and Ribon 1.5 had been compromised due to a Fastr system compromise and that the credentials were used to inject malicious scripts into merchant storefronts.
-
background
Ribon developers discover unauthorized API key usage — One day before the compromised key was revoked, Ribon developers became aware that their API credentials were being misused by attackers.
-
background
Attackers begin exploiting compromised Ribon API credentials — Hackers used a stolen API key belonging to Ribon, a storefront optimization app developed by Fastr-owned Be A Part Of, to access customer data from BigCommerce merchant stores. The attackers downloaded customer records page by page over a four-day period.