Skip to content
DnsLister Forum

Where domain hunters compare notes

BigCommerce alerts merchants of data breach linked to Ribon apps

This is a supply chain attack hitting the ecommerce space. BigCommerce is notifying merchants that attackers compromised credentials for third-party Ribon apps and used that access to inject malicious scripts into online stores.

Technical Breakdown – Attack Vector: Credential compromise of third-party Ribon applications, not a direct breach of BigCommerce core infrastructure. – Impact: Malicious script injection into merchant storefronts, likely targeting payment data or customer PII via form grabbing. – Scope: Multiple merchants affected; specific number not disclosed. – Attribution: No named threat actor at this time.

Defense – If you're a BigCommerce merchant using Ribon apps, immediately rotate API keys and app credentials. – Audit your storefront for unauthorized script injections—check for unexpected JavaScript loaded from external domains. – Enable Content Security Policy (CSP) headers to restrict script sources and limit blast radius from compromised third-party apps. – Review third-party app permissions and remove any that are unused or have excessive access.

Source: https://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/

Source: r/SecOpsDaily · by /u/falconupkid

Leave a Reply

Your email address will not be published. Required fields are marked *