Third‑Party App Credential Compromise Exposes Shopper Data on BigCommerce Stores
What Happened – Attackers stole the application key for the third‑party Ribon and Ribon 1.5 apps, then used those credentials to inject malicious scripts into a handful of BigCommerce merchant storefronts. Between September 13‑17 2026 the attackers accessed shopper records (names, emails, phone numbers, shipping addresses). BigCommerce removed the apps, revoked the keys and supplied logs to the affected merchants.
Why It Matters for Trust & Control Assurance
- Continuous monitoring of third‑party application credentials is a core control that a trust‑and‑assurance program must evidence.
- Demonstrable due‑diligence on vendor‑managed keys provides a defensible audit trail for supply‑chain risk management (NIST CSF 2.0 Identify → Supply Chain Risk Management).
- The incident shows why real‑time evidence collection and rapid remediation are essential to maintain a trustworthy posture.
Who Is Affected – Retail and e‑commerce merchants using BigCommerce, SaaS platform providers, and the Ribon app developer.
Recommended Actions
- Inventory all third‑party apps and map each to a privileged‑access control.
- Rotate compromised keys immediately and enforce short‑lived secrets where possible.
- Deploy continuous credential‑use monitoring and log aggregation to detect anomalous script injections.
- Update third‑party risk assessments to include script‑injection testing and supply‑chain vetting.
Source: BleepingComputer
Technical Notes – Attack vector: stolen third‑party application credentials (credential compromise). Data exposed: shopper full name, email, phone, shipping address. Payment card data remained segregated and was not accessed. Source: same as above