:

BIGCOMMERCE WARNS OF DATA BREACH VIA RIBON APPS

SECURITY DESK1 MIN READ
MON, SEP 21, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

BigCommerce has alerted merchants to a data breach stemming from compromised Ribon app credentials. Attackers used the stolen access to inject malicious scripts into online stores.

The ecommerce platform notified affected merchants after third-party Ribon applications were compromised. Attackers leveraged the credentials to deploy malicious code across storefronts, potentially exposing customer data and enabling unauthorized transactions. Ribon apps integrate with BigCommerce to handle various merchant functions. The breach highlights risks associated with third-party integrations in ecommerce ecosystems. BigCommerce has not disclosed the number of compromised merchants or specific data accessed. The company recommends merchants review account activity, change credentials, and audit installed apps for unauthorized modifications. Merchants using Ribon applications should immediately check for suspicious scripts and monitor for fraudulent activity. BigCommerce continues investigating the incident and coordinating with affected parties.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Donating or recycling an old laptop is environmentally responsible, but failing to erase your data first can expose personal information to new owners or data recovery specialists.

JUST NOWIndustry Desk

Apple's Safari browser offers stronger default privacy protections than most competitors on iPhone, but users shouldn't assume it shields them from all threats. The built-in features have clear limitations.

2H AGOSecurity Desk

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert warning of active exploitation of three Linux kernel vulnerabilities, including one rated critical. Attackers are currently leveraging these flaws in the wild.

2H AGODev Desk

Chinese startup Z.AI has open sourced its ZCode coding assistant and disabled certain features following user complaints that the tool was uploading codebases to overseas servers without permission.

7H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.