// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
ColdRecon / Breach Radar / BigCommerce
Breach Record

BigCommerce

DISCLOSED 2026-09-23 · STOLEN CREDS

BigCommerce alerted merchants to a data breach after attackers compromised credentials for third-party applications and used them to inject malicious scripts into online stores, potentially exposing customer information. The breach involved third-party apps, not BigCommerce's core systems. Customer details may have been exposed.

The record

What we know

Disclosed
2026-09-23
Attack vector
Stolen Creds
Sector
E-commerce
Domain
bigcommerce.com
Data classes exposed
customer information
Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the BigCommerce disclosure. It updates if new public reporting emerges. All tracked breaches →

BigCommerce just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →