BigCommerce Data Breach: Customer Data Exposed via Third-Party App Vulnerabilities
BigCommerce has informed multiple merchants of a security incident involving unauthorized access to customer data via compromised credentials for third-party applications.
Overview of the Breach
BigCommerce has informed multiple merchants of a security incident involving unauthorized access to customer data via compromised credentials for third-party applications. Attackers exploited these credentials to inject malicious code into online stores, potentially compromising sensitive information. The breach occurred between September 13 and September 17, during which unauthorized parties accessed shopper data within BigCommerce environments.
Timeline of the Incident
The breach occurred between September 13 and September 17, during which unauthorized parties accessed shopper data within BigCommerce environments. BigCommerce confirmed the breach on September 17 and took immediate action to remove the compromised applications from its platform.
Affected Merchants
Affected merchants, including UK-based online spirits retailer Master of Malt, reported that customer details such as full names, addresses, phone numbers, and shipping postal codes may have been exposed. The incident specifically targeted third-party applications operating within the BigCommerce ecosystem rather than the platform itself.
Compromised Application Key
A compromised application key associated with Ribon, a third-party tool managed by Be A Part Of, was identified as a critical factor in the breach. BigCommerce supports over 1,200 third-party applications, including Ribon, which focuses on enhancing shopping experiences.
Platform Security Measures
BigCommerce clarified that account passwords and payment card information were stored separately and remained unaffected. The company emphasized that its core systems and the BigCommerce platform itself were not breached. However, attackers reportedly used the stolen application key to access existing customer records through the platform.
Aftermath and Response
Master of Malt reported the incident to the UK Information Commissioner’s Office and initiated an investigation into potential impacts on its customers and other connected stores. The breach also prompted legal firms like Emery Reddy to seek potential claimants, as affected retailers notified customers of data exposure linked to the Ribon application key theft.
Similar Past Incidents
This incident bears similarities to a 2024 breach involving electronics accessories provider ZAGG, where attackers exploited a third-party application called FreshClick to inject payment-skimming code. In both cases, the attack vector relied on compromised third-party access rather than direct breaches of the e-commerce platform.
Risks of Third-Party Integrations
The event underscores the risks associated with integrating third-party applications into online stores. Even if the primary platform remains secure, stolen credentials for external tools can provide attackers with access to merchant environments and customer data. BigCommerce stated it had removed the affected applications following detection of unauthorized activity.
Recommendations for Merchants
The breach highlights the importance of monitoring third-party integrations and implementing strict access controls. Organizations are advised to review their application ecosystems, verify credential security, and ensure compliance with data protection regulations.
“Master of Malt reported the incident to the UK Information Commissioner’s Office and initiated an investigation into potential impacts on its customers and other connected stores.”
Conclusion
This breach serves as a critical reminder of the vulnerabilities introduced by third-party integrations. While BigCommerce acted swiftly, the incident emphasizes the need for continuous vigilance in securing external tools and data access points.
