HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Third‑Party App Credential Compromise Exposes Shopper Data on BigCommerce Stores

Attackers stole Ribon app keys and injected malicious scripts into BigCommerce merchant sites, exposing names, emails, phone numbers and shipping addresses. The breach highlights the need for continuous third‑party credential monitoring and audit‑ready evidence for supply‑chain risk management.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Third‑Party App Credential Compromise Exposes Shopper Data on BigCommerce Stores

What Happened – Attackers stole the application key for the third‑party Ribon and Ribon 1.5 apps, then used those credentials to inject malicious scripts into a handful of BigCommerce merchant storefronts. Between September 13‑17 2026 the attackers accessed shopper records (names, emails, phone numbers, shipping addresses). BigCommerce removed the apps, revoked the keys and supplied logs to the affected merchants.

Why It Matters for Trust & Control Assurance

  • Continuous monitoring of third‑party application credentials is a core control that a trust‑and‑assurance program must evidence.
  • Demonstrable due‑diligence on vendor‑managed keys provides a defensible audit trail for supply‑chain risk management (NIST CSF 2.0 Identify → Supply Chain Risk Management).
  • The incident shows why real‑time evidence collection and rapid remediation are essential to maintain a trustworthy posture.

Who Is Affected – Retail and e‑commerce merchants using BigCommerce, SaaS platform providers, and the Ribon app developer.

Recommended Actions

  • Inventory all third‑party apps and map each to a privileged‑access control.
  • Rotate compromised keys immediately and enforce short‑lived secrets where possible.
  • Deploy continuous credential‑use monitoring and log aggregation to detect anomalous script injections.
  • Update third‑party risk assessments to include script‑injection testing and supply‑chain vetting.

Source: BleepingComputer

Technical Notes – Attack vector: stolen third‑party application credentials (credential compromise). Data exposed: shopper full name, email, phone, shipping address. Payment card data remained segregated and was not accessed. Source: same as above

📰 Original Source
https://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →