Stolen Ribon app keys expose shopper data across BigCommerce stores

Stolen Ribon app keys expose shopper data across BigCommerce stores. Shoppers had personal information exposed after attackers compromised credentials belonging to the third-party Ribon and Ribon 1.5 applications.

Daily Cyber News: Stolen Ribon app keys expose shopper data across BigCommerce stores

Shoppers had personal information exposed after attackers compromised credentials belonging to the third-party Ribon and Ribon 1.5 applications. Between September 13th and September 17th, those credentials were used to access customer records and inject malicious scripts into a small number of BigCommerce storefronts. Reported exposed information included names, email addresses, phone numbers, and shipping addresses.

Key context: The company also said its own platform wasn’t breached.

Additional detail: For leaders, the key point is that third-party application keys can function as privileged access to customer environments.

For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

Topics: cybersecurity news, cybersecurity, cyber risk, Stolen Ribon, Stolen, Ribon, keys, expose, shopper, data.

Stolen Ribon app keys expose shopper data across BigCommerce stores
Broadcast by