An alarming breach has impacted BigCommerce, a notable eCommerce platform, as a supply chain attack led to the theft of sensitive customer data. This incident underscores vulnerabilities within third-party applications.
Details of the BigCommerce Breach
BigCommerce, a SaaS provider that supports merchants in establishing and managing online shops, became the target of a cyberattack. The breach involved the compromise of an application key associated with Ribon, a storefront optimization tool created by Fastr’s subsidiary, Be A Part Of.
The attack occurred between September 13 and September 17, when hackers exploited the compromised key to access customer details such as names, emails, phone numbers, and addresses. This was reported by UK spirits retailer Master of Malt, which provided a technical account of the breach.
Timeline and Response to the Incident
Master of Malt revealed that the attackers systematically downloaded customer information until the compromised key was deactivated on September 17, following its misuse detection by Ribon developers. BigCommerce subsequently began informing affected merchants on September 18, after the deactivation of the key and removal of the compromised Ribon applications.
The attack’s focus was on Ribon, a third-party application installed on numerous BigCommerce stores. Once the attackers breached Ribon’s access key, they managed to infiltrate data within the BigCommerce environment, according to Master of Malt.
BigCommerce’s Actions and Future Considerations
Despite the breach not directly involving BigCommerce’s core systems, the platform took decisive measures to mitigate the impact. By uninstalling the affected application from merchants’ stores, it aimed to prevent further unauthorized access and limit potential damage.
BigCommerce confirmed the breach of Ribon and Ribon 1.5 application credentials, which were used by hackers to inject harmful scripts into a few merchant sites. These applications were independent from BigCommerce, with the relationship existing solely between merchants and the third-party app.
The incident highlights the ongoing challenges of securing third-party applications and underscores the need for comprehensive security protocols. The incident’s full scope remains uncertain as Fastr and Be A Part Of have yet to publicly address the breach. SecurityWeek has reached out for comments and will provide updates when available.
This breach serves as a critical reminder of the complexities involved in securing digital commerce platforms, especially those relying heavily on third-party applications.
