BigCommerce warns customers of potential data leaks following cyber incident

Ecommerce platform BigCommerce has confirmed a supply-chain security breach involving the third-party application Ribon. Between September 13 and September 17, 2026, unauthorized actors compromised Ribon’s application credentials, allowing them to inject malicious scripts into various merchant storefronts. The breach resulted in the exposure of customer personal information, including names, email addresses, phone numbers, and physical addresses. While BigCommerce characterized the incident as affecting a small number of stores, reports from affected merchants like Master of Malt suggest the impact may be broader, potentially involving hundreds of retailers. The company has since revoked the compromised access keys and uninstalled the application from affected stores. No passwords or payment information were accessed, as these are stored in separate, secure systems. BigCommerce is currently providing log data to assist in the ongoing investigation, and affected retailers have been notified to mitigate further risks.
This is a summary. Read the full article at the original source:
TechRadarRelated stories
More Than a Third of Industrial Organizations Identify Cybersecurity Risk as a Primary Growth Obstacle
A recent study reveals that over one-third of industrial organizations now view cybersecurity risk as a significant barrier to their business growth.…
Meta has released a security patch for its Muse macOS application after security researcher Patrick Wardle identified a critical zero-day vulnerabilit…
CISA issues urgent three-day patch deadline for critical Linux kernel vulnerabilities
The US Cybersecurity and Infrastructure Security Agency (CISA) has added three critical Linux kernel vulnerabilities—CVE-2025-39682, CVE-2026-53266, a…



