News Date: 2026-09-21
A credential compromise involving third-party BigCommerce applications has exposed customer information and demonstrated how deeply commerce platforms depend on the security of outside developers. Attackers obtained credentials associated with the Ribon and Ribon 1.5 applications, then used that access against a small number of merchant storefronts.
Third-Party Access Became the Entry Point
BigCommerce confirmed the compromise on September 17 and removed the applications from affected stores to revoke the unauthorized access. The company said attackers had not breached the central BigCommerce platform itself. Instead, they exploited trusted application credentials belonging to Ribon, which is operated by a third-party provider.
One affected retailer, UK spirits vendor Master of Malt, said unauthorized access occurred between September 13 and September 17. Exposed records included customer names, email addresses, telephone numbers and shipping addresses. BigCommerce said account passwords and payment card details are stored separately and were not exposed through this particular incident.
The attackers also used the compromised credentials to inject malicious scripts into storefronts. Even when payment data is not captured, script injection gives criminals a flexible foothold that can support surveillance, redirection, credential theft or additional payload delivery.
Why Application Keys Need Stronger Governance
BigCommerce supports more than 1,200 applications and integrations. That ecosystem gives merchants useful capabilities, but every authorized application becomes part of the store's effective security boundary. In my view, organizations should treat application keys with the same seriousness as privileged administrator accounts.
Recommended Actions
- Inventory all installed commerce applications and remove unused integrations.
- Rotate application credentials and revoke keys associated with former vendors or projects.
- Limit each integration to the minimum data and storefront permissions required.
- Monitor changes to checkout pages, templates and externally loaded scripts.
- Retain application access logs and review unusual customer-record queries.
- Require vendors to document credential storage, incident response and employee access controls.
I believe the most important lesson is that merchants cannot outsource accountability along with functionality. A platform may remain technically uncompromised while customers still suffer a real breach through an authorized integration. Continuous oversight of third-party applications must therefore become a routine part of ecommerce security, not an exercise performed only after an incident.
