A third-party app supply chain attack happens when criminals compromise a tool connected to a platform, then use it to reach the platform’s customers. In September 2026, two well-known platforms were hit this way, through the tools connected to them rather than their own front doors. At BigCommerce, attackers used stolen credentials for a third-party app called Ribon to reach merchant stores. At Brevo, attackers used a long-lived Cloudflare API key, stored in source code, to push malicious scripts to websites that embed Brevo’s widgets.
The lesson for third-party risk teams is direct: your vendor’s integrations, API keys and service accounts are part of your attack surface. A vendor can pass every questionnaire and still be exposed through a connected app or a forgotten credential. That kind of exposure only shows up if you watch continuously and from the outside, the way an attacker does.
What happened in the BigCommerce and Brevo supply chain attacks?
Both attacks started with a credential that belonged to something other than the victim’s core platform. Neither company says its main platform was breached. That is exactly the point.
BigCommerce and the Ribon apps
On September 17, 2026, BigCommerce confirmed that credentials for two third-party apps, Ribon and Ribon 1.5, had been compromised. The apps are run by Be A Part Of, a Fastr company. BigCommerce said the credentials were used to inject malicious scripts into a small number of merchant storefronts, and it uninstalled the apps from affected stores.
One affected retailer, Master of Malt, said the attacker used the compromised application key to access shopper data between September 13 and September 17. Exposed details included names, email addresses, phone numbers and shipping addresses. BigCommerce says it stores passwords and payment card data separately and that those were not exposed.
BigCommerce supports more than 1,200 third-party apps and integrations. Any one of them holds keys into merchant environments.
Brevo and the Cloudflare API key
Brevo, a customer engagement platform, had two incidents in one week. On September 10, an attacker exploited a flaw in Brevo’s SAML SSO handling to access 138 customer accounts, sent phishing from six of them and exported contacts from 43.
On September 14, the attacker came back with a different credential. According to Brevo’s post-mortem, a long-lived Cloudflare API key with full account permissions had been stored in application source code. The attacker used it to deploy a Cloudflare Worker that injected a malicious script into Brevo’s websites and into three JavaScript files customers embed on their own sites.
The script showed some visitors a fake “verify you are human” page that tricked them into running a command that installed malware, a technique known as ClickFix. On WordPress sites with a Brevo widget, it also tried to install a plugin when an administrator was logged in. Brevo puts the impact window at about five and a half hours. Security firm Sansec estimated more than 100,000 websites were likely affected.
Two details matter most for risk teams. Brevo says the key was first misused in late August, about two weeks before the injection. And because the script was added at the CDN edge, Brevo’s own servers and files were unchanged, so standard integrity checks did not catch it.
Timeline
| Date (2026) | Event |
| Late August | Brevo’s Cloudflare API key first misused, per Brevo |
| September 10 | Attacker exploits Brevo SAML SSO flaw, accesses 138 accounts |
| September 13 | Ribon app key used to access BigCommerce shopper data, per Master of Malt |
| September 14 | Malicious Cloudflare Worker serves scripts via Brevo for about 5.5 hours |
| September 17 | BigCommerce confirms Ribon credential compromise and removes the apps |
Why are vendor integrations a blind spot in third-party risk programs?
Most third-party risk programs assess the vendor you signed a contract with. They rarely assess the apps, plugins, CDNs and API keys that vendor depends on. In both September incidents, that unassessed layer was where the attacker got in.
Three patterns explain the gap:
- The contract map is not the access map. A merchant on BigCommerce may never have reviewed Ribon. Yet a Ribon key could reach that merchant’s shopper data. Your vendor inventory lists who you pay, not everything that can touch your data.
- Credentials outlive their purpose. Brevo’s key was long-lived and had full account permissions. Keys like this rarely appear in a questionnaire answer, and nobody notices when they leak until they are used.
- The vendor’s own checks can miss it. Brevo’s servers were never modified. The change happened at the edge, between Brevo and the visitor. If the vendor’s integrity checks did not see it, a yearly self-assessment will not either.
This is fourth-party risk in practice. The question is not only “Is my vendor secure?” It is also “What is connected to my vendor, and would anyone notice if one of those connections were abused?”
What do security questionnaires miss?
Questionnaires tell you what a vendor says about its controls at one point in time. They still have a place, especially for policy and contract checks. But neither September incident would likely have surfaced in a questionnaire, because the problem lived in a connected app and a leaked key, not in a stated control.
| Question a risk team needs answered | Point-in-time questionnaire | Continuous, outside-in monitoring |
| Which apps, plugins and services can reach our data through this vendor? | Only what the vendor lists | Can map public-facing assets and related services over time |
| Is a vendor credential or API key exposed or for sale? | Not covered | Can watch criminal forums and leak sites for the vendor’s domain |
| Did something change in what the vendor serves to the public? | Not covered until next review | Can flag new or changed external exposure between reviews |
| How quickly would we know? | At the next annual or quarterly cycle | Days or hours, depending on the signal |
| Does it need the vendor’s cooperation? | Yes | No |
The goal is not to replace one with the other. It is to stop treating a passed questionnaire as proof that nothing has changed.
What should security teams monitor about a vendor’s connected ecosystem?
Start with the vendors that can touch customer data or put code in front of your users. For those, track five things:
- Connected apps and integrations. Ask which third-party apps have keys into your environment through the vendor platform. Remove any you no longer use. The BigCommerce case shows an app you never reviewed can still hold access.
- Scripts you load from vendors. List every external script on your websites and checkout pages, and who serves it. Brevo’s embedded files were the delivery route to customer sites.
- Leaked vendor credentials. Watch for your vendors’ domains in credential dumps, infostealer logs and access-for-sale listings. Brevo’s key was misused about two weeks before the attack, which is the window where early warning helps.
- Changes in vendor exposure. New subdomains, new hosting, changed DNS or a sudden spike in risk signals are reasons to look again, not to wait for the next review cycle.
- A trigger for reassessment. Decide in advance what news or signal reopens a vendor review, so a public breach at a vendor’s vendor starts a check the same day.
For teams under DORA or NIS2, documenting this monitoring also builds the evidence trail regulators now expect for ongoing third-party oversight.
How Sling looks at vendor risk from the attacker’s side
Attackers do not read your vendor’s questionnaire. They look for a working way in: a leaked key, an exposed service, an app with too much access. Sling is built to show you that same view of your vendors.
- Darknet and threat intelligence. Sling’s score draws on more than 10 years of in-house darknet and criminal intelligence, including forums and marketplaces where stolen credentials and access are traded.
- Attack surface mapping. Sling maps a vendor’s domains, subdomains, IPs and related organizations, including assets nobody listed.
- No vendor consent needed. Monitoring starts from a domain name, with no agent and or integrations, and gives a full picture within 24 hours.
- Continuous updates and alerts. Scores update as new signals appear, so a change at a vendor surfaces between review cycles.
- Remediation you can share. Each vendor gets a plan that lists findings by severity, so you can start a specific conversation with them.
We are not claiming any tool would have stopped these two attacks. The point is narrower: signals like exposed credentials and changes in a vendor’s external footprint are visible from the outside, and they are worth watching continuously.
Want to see how your vendors look from an attacker’s point of view? Request a Sling assessment.
FAQ
What is a third-party app supply chain attack? It is an attack where criminals compromise an app, plugin or integration that connects to a larger platform, then use that access to reach the platform’s customers. The BigCommerce incident in September 2026 followed this pattern through the Ribon apps.
Was BigCommerce itself breached? BigCommerce says its platform and systems were not breached. The attacker used compromised credentials belonging to the third-party Ribon apps.
How did the Brevo attack reach 100,000 websites? The attacker used a stolen Cloudflare API key to inject a script into JavaScript files that Brevo customers embed on their own sites. Security firm Sansec estimated more than 100,000 sites were likely affected.
What is fourth-party risk? Fourth-party risk is the risk that comes from your vendors’ own vendors and connected services. You usually have no contract with them, but they can still affect your data.
Can a security questionnaire detect a leaked vendor API key? Rarely. A questionnaire records what a vendor says about its controls at one point in time. A leaked key shows up in outside signals, such as criminal forums or changes in public-facing assets, which need continuous monitoring.
What should I do if a vendor I use was affected? Follow the vendor’s guidance first. For Brevo, that includes checking WordPress sites for plugins installed on September 14 and changing passwords. Then review which other apps and keys connect to that vendor and add it to your list for closer monitoring.