2024 BigCommerce marketplace — FreshClick (third-party) compromise; checkout skimming
Data compromised
Cardholder names, addresses, payment-card data, and related order fields for affected storefront sessions
Technical writeup
BigCommerce notified merchants after discovering that the third-party FreshClick checkout widget available through its ecosystem had been compromised so that malicious scripts could harvest payment and order PII during checkout. Trade and breach-notification reporting placed active malicious transaction windows roughly in late October–early November 2024, with merchants such as ZAGG and tobacco-pipe retailers filing state breach notices. BigCommerce stated core platform systems were not breached and removed or disabled the integration for affected stores.
Root cause
Supply-chain compromise of a marketplace application leading to client-side skimming