Starting September 21, 2026, BigCommerce alerted merchants of a data breach after attackers compromised credentials for third-party Ribon payment applications and used them to inject malicious scripts into online storefronts, exposing customer data. The breach represented a supply-chain compromise affecting multiple merchants.
6 reportsother · tech
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. [...]
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. https://www. bleepingcomputer.com/news/secu rity/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/
BigCommerce Data Breach Linked to Compromised Ribon App Keys Attackers used compromised Ribon application keys to access customer records and inject malicious scripts into BigCommerce storefronts. The breach exposed personal information including names, contact details, and addresses, but not passwords or payment card data. **** # cybersecurity # infosec # incident # databreach https:// beyondmach
BigCommerce Merchants Suffer Data Breach via Compromised Ribon App API Credentials BigCommerce merchants suffered a data breach after attackers stole API credentials for the third-party Ribon application to steal customer records and inject malicious scripts. The incident affected multiple retailers, including Master of Malt, but did not compromise the core BigCommerce platform or payment systems.