Customer engagement platform Brevo fell victim to a supply chain attack that resulted in malicious code being injected into over 100,000 websites.
Brevo was initially hacked on September 10, when a threat actor exploited a vulnerability in Brevo’s handling of SAML SSO to access 138 accounts, including one belonging to cryptocurrency storage provider Trezor.
The attackers sent phishing emails from six of the accounts and exported the contacts of 43 accounts, Brevo said in an incident notice.
The company closed the unauthorized access, but the attackers returned on September 14, when they used a compromised long-lived Cloudflare API key to deploy a worker.
That worker injected malicious scripts into brevo.com and sibforms.com, and into three JavaScript files that Brevo’s customers embed into their websites, the company said in a post-mortem.
“The script showed selected visitors a fake ‘Cloudflare, verify you are human’ page that instructed them to paste and run a command on their computer, a social-engineering technique known as ClickFix,” Brevo explains.
On the WordPress websites embedding a Brevo widget, the script attempted to deploy and run a plugin if the visitor was logged in as an administrator.
The malicious worker was active for roughly five and a half hours before Brevo removed it and revoked the compromised API key and credentials.
“Our investigation indicates the key was first misused in late August 2026. We have found no injection of malicious content into customer-facing pages before 14 September,” Brevo said.
According to cybersecurity firm Sansec, the malware was served for roughly four hours, and more than 100,000 websites were likely impacted.
The company recommends that all sites using Brevo be reviewed for potential compromise. Administrators should check for unauthorized plugin installations, and site visitors should check their machines for malware if they were served the fake verification pages.
“Brevo is no longer serving malicious code. However, your WordPress site may have been backdoored, and your customers may have fallen for the ClickFix scam,” Sansec notes.
Related: Critical Orkes Conductor Vulnerability Exploited in Attacks
Related: OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training
Related: Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related: Rust Supply Chain Attack Linked to North Korean Hackers

