
Episode notes
BigCommerce has confirmed that stolen API credentials for two third-party storefront apps, Ribon and Ribon 1.5, were used to take shopper data from merchant stores and inject malicious scripts into a small number of storefronts. BigCommerce says its own platform was not breached.
Who's involved. BigCommerce, founded in Sydney in 2009 and now operated by Nasdaq-listed Commerce.com, hosts online stores for tens of thousands of businesses and supports more than 1,200 third-party apps. Ribon and Ribon 1.5 are run by Be A Part Of, a Fastr company. Several retailers have notified customers; UK retailer Master of Malt is the only one to publish a detailed account so far.
Timeline (UK time, per Master of Malt as reported). 13 September, 17:21 — unauthorised use of the Ribon app key begins. 16 September — Ribon's developers become aware of the misuse. 17 September — BigCommerce confirms the compromise, uninstalls the apps from affected stores, and the key is revoked. 18 September — BigCommerce notifies merchants; Master of Malt emails customers. 19 September — the UK ICO opens a case. From 21 September — major security-press coverage.
What was exposed. Shopper names, email addresses, phone numbers and shipping addresses, pulled page by page through BigCommerce's own interfaces. Not exposed, per BigCommerce and Master of Malt: passwords and payment card data. BigCommerce says the credentials were compromised "due to a Fastr system compromise." Unknown: total merchants and shoppers affected, how Fastr was breached, and what the injected scripts did. No CVE is involved and no group has claimed the attack. A different BigCommerce app was compromised in 2024 to skim ZAGG customers' cards.
Lessons. Audit your store's installed apps and remove anything unused or unowned. Grant apps the minimum permissions they need. Monitor for unusual bulk API reads. Ask vendors how they protect the keys they hold for you and how quickly they'll notify you of a breach. Under Australia's Notifiable Data Breaches scheme, a breach that starts at a third party can still be your obligation. Warn affected customers about targeted phishing.
Visit www.kinsoft.com.au to talk through your security and IT needs.
Sources: BleepingComputer; SecurityWeek; TechRadar; GBHackers; CyberPress; Shopifreaks; Born City; Emery Reddy; Digital Commerce 360.
