BigCommerce API Key Theft via Ribon Exposes Merchant Data Stores September 13-17
Supply-chain compromise of Ribon app credentials allowed four days of customer data extraction from BigCommerce stores. Official statements limit scope to the third-party app, yet the evidence shows systemic exposure through long-lived API keys. No independent confirmation exists on whether other apps or merchants were hit.
The incident began with compromise of Fastr/Be A Part Of systems holding Ribon credentials. Attackers then called BigCommerce APIs to iterate customer records page-by-page across installed stores. Master of Malt’s post-incident analysis shows the key remained valid for four days, allowing bulk extraction until revocation on the 17th. BigCommerce uninstalled the apps and notified merchants on the 18th but confirmed no platform-level breach occurred. BigCommerce’s statement separates its SaaS boundary from third-party app credentials, yet the attack surface is identical: long-lived API keys issued to external developers. Procurement records and app marketplace listings reveal over 1,200 integrations with similar OAuth or key-based access, none subject to routine rotation audits. Parallel incidents at CrowdSec and Gyazo demonstrate the same pattern of stolen developer credentials enabling downstream data pulls. Operational risk persists because merchants cannot verify upstream key hygiene. Fastr has issued no public statement or incident report. Expect continued enumeration of similar app keys until platforms enforce short-lived tokens and per-merchant scope limits. Next indicator will be whether additional merchants surface data in dark-web dumps within 60 days.
Fastr: No public acknowledgment or additional Ribon credential incidents reported within 90 days
Sources (2)
- [1]Primary Source(https://www.securityweek.com/bigcommerce-data-stolen-via-ribon-apps-hack/)
- [2]Supporting Source(https://www.masterofmalt.com/blog/ribon-bigcommerce-incident/)