Stolen Ribon app keys expose shopper data across BigCommerce stores
Daily Cyber News: Stolen Ribon app keys expose shopper data across BigCommerce stores
Shoppers had personal information exposed after attackers compromised credentials belonging to the third-party Ribon and Ribon 1.5 applications. Between September 13th and September 17th, those credentials were used to access customer records and inject malicious scripts into a small number of BigCommerce storefronts. Reported exposed information included names, email addresses, phone numbers, and shipping addresses.
Key context: The company also said its own platform wasn’t breached.
Additional detail: For leaders, the key point is that third-party application keys can function as privileged access to customer environments.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, Stolen Ribon, Stolen, Ribon, keys, expose, shopper, data.