---
title: BigCommerce 通知多家商家数据泄露 与 Ribon 应用密钥被盗
url: https://www.dataloco.com/zh/bigcommerce-ribon
published: 2026-09-24T07:31:42+00:00
language: zh
section: 安全
source: https://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/
organizations: BigCommerce, Ribon, Be A Part Of, Fastr, Master of Malt, Emery Reddy
publisher: Dataloco
---

# BigCommerce 通知多家商家数据泄露 与 Ribon 应用密钥被盗

BigCommerce 通知多家商家其在线店铺数据被泄露。攻击者通过窃取第三方 Ribon 应用的凭证，将恶意脚本注入这些店铺。该平台于 2026 年 9 月 17 日确认凭证被窃取，并立即下架相关应用以保护客户。

英国在线烈酒零售商 Master of Malt 是受影响的商家之一，其表示攻击者在 9 月 13 日至 17 日期间访问了购物者信息。泄露的细节包括全名、电子邮件地址、电话号码和邮寄邮政地址。

Master of Malt 在声明中称，攻击者利用被盗的 Ribon 应用密钥进入其系统，获取了 BigCommerce 环境中的购物者数据。

BigCommerce 表示其平台未被直接侵入，且仅在少数店铺中注入了恶意脚本。该公司已对受影响的商家进行直接通知，并提供日志数据以支持开发者的调查。

Master of Malt 已向英国信息专员办公室（ICO）报告此事件，并指出该泄露可能影响数百家其他店铺。

Emery Reddy 律所正在寻找与该事件相关的潜在索赔人，多家零售商正在向客户报告数据暴露，但未点名具体受影响的企业。

BleepingComputer 已联系 Be A Part Of 与 Fastr 获取更多信息，但截至发布时仍未获回复。

此事件与 2024 年 ZAGG 受攻击相似，当时攻击者利用受感染的 FreshClick BigCommerce 应用植入支付窃取代码。不同之处在于，Ribon 攻击者并未窃取支付信息，而是通过被盗密钥访问已有客户记录。

## This story in other languages

- [Polski](https://www.dataloco.com/pl/bigcommerce-ostrzega-sprzedawcow-o-naruszeniu-danych-powiazanym-z-aplikacjami-ribon)
- [日本語](https://www.dataloco.com/ja/bigcommerceribon)
- [Deutsch](https://www.dataloco.com/de/bigcommerce-warnt-handler-vor-datenverletzung-durch-kompromittierte-ribon-apps)
- [ไทย](https://www.dataloco.com/th/bigcommerce-ribon)
- [Español](https://www.dataloco.com/es/bigcommerce-alerta-a-comerciantes-de-brecha-de-datos-vinculada-a-aplicaciones-ribon)
- [Français](https://www.dataloco.com/fr/bigcommerce-alerte-les-marchands-dune-fuite-de-donnees-liee-aux-applications-ribon)
