← BigCommerce

2024 BigCommerce marketplace — FreshClick (third-party) compromise; checkout skimming

2024 Unknown records affected Share on X

Data compromised

Cardholder names, addresses, payment-card data, and related order fields for affected storefront sessions

Technical writeup

BigCommerce notified merchants after discovering that the third-party FreshClick checkout widget available through its ecosystem had been compromised so that malicious scripts could harvest payment and order PII during checkout. Trade and breach-notification reporting placed active malicious transaction windows roughly in late October–early November 2024, with merchants such as ZAGG and tobacco-pipe retailers filing state breach notices. BigCommerce stated core platform systems were not breached and removed or disabled the integration for affected stores.

Root cause

Supply-chain compromise of a marketplace application leading to client-side skimming

References