Independent tech news and plain advice
Technologicall

Security

Hijacked Store Apps Stole Shopper Names and Addresses on BigCommerce

Attackers used stolen logins for two add-on apps to plant code in online stores. Card numbers were not taken, but home addresses were.

A shopper holding a credit card in front of a laptop
Photo: Shixart1985, CC BY 2.0, via Wikimedia Commons.

BigCommerce, a platform that runs thousands of online stores, has warned some store owners that their shoppers' details were stolen. The store sites themselves were not hacked. The attack came through two add-on apps.

How It Happened

Attackers got hold of the login details for the Ribon and Ribon 1.5 apps, made by a company called Be A Part Of. They used that access to slip harmful code into some stores' checkout pages. The code then copied what shoppers typed in.

The break-in ran from September 13 to September 17. BigCommerce confirmed it on September 17 and removed the apps from the affected stores. The company says its own platform was not breached.

What Was Taken

Stolen details include shoppers' full names, email addresses, phone numbers and shipping addresses. BigCommerce says passwords and card numbers were not exposed.

UK spirits seller Master of Malt was one of the affected stores. A law firm quoted by BleepingComputer suggested hundreds of stores could be involved.

Why It Still Matters

A name, phone number and home address are exactly what scammers need for a convincing fake message. Expect texts or emails that claim a package is stuck, an order failed or a refund is waiting.

What to Do

  • Be wary of order, delivery or refund messages, especially from shops you used in mid-September.
  • Do not click links in surprise messages. Go to the store's website yourself.
  • If you run a store that used a Ribon app, check every script running on your storefront.

Questions Readers Ask

How do I know if my data was taken?

Affected stores are being told by BigCommerce. If you shopped online in mid-September, watch your inbox for a notice from the store.

Was my credit card stolen?

BigCommerce says payment card data and passwords were not exposed. Still, check your statements, since scammers may use your details to trick you later.

Where This Came From

We confirmed the facts in this story against these reports. The words above are our own.

Keep Reading