North America
BigCommerce
Ecommerce platform BigCommerce confirmed a supply-chain breach involving compromised credentials from third-party app Ribon, affecting multiple merchant customers.
BigCommerce is a cloud-based SaaS ecommerce platform that businesses use to build and operate online stores without needing to develop their own commerce infrastructure. The company confirmed the credential compromise on September 17, stating that credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by Be A Part Of, a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts.
The UK-based online spirits vendor Master of Malt is among the BigCommerce customers that received breach notifications, with the retailer confirming that attackers accessed shopper information, including full names, email addresses, phone numbers and shipping postal addresses.
How it could affect your business
Supply chain attacks are growing in both frequency and sophistication, with attackers increasingly targeting third-party apps and integrations as a way into larger platforms and their customers. A single compromised vendor can create a ripple effect that reaches hundreds or thousands of businesses downstream, as this incident demonstrates. Businesses should regularly audit the third-party tools and integrations connected to their platforms, ensure vendors meet their security standards and monitor for any unusual activity that could signal a compromise further up the supply chain.
