Skip to content
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

Feeds.Feedburner Ionut Arghire September 18, 2026

Customer engagement platform Brevo fell victim to a supply chain attack that resulted in malicious code being injected into over 100,000 websites.

Brevo was initially hacked on September 10, when a threat actor exploited a vulnerability in Brevo’s handling of SAML SSO to access 138 accounts, including one belonging to cryptocurrency storage provider Trezor .

The attackers sent phishing emails from six of the accounts and exported the contacts of 43 accounts, Brevo said in an incident notice .

The company closed the unauthorized access, but the attackers returned on September 14, when they used a compromised long-lived Cloudflare API key to deploy a worker.

That worker injected malicious scripts into brevo.com and sibforms.com, and into three JavaScript files that Brevo’s customers embed into their websites, the company said in a post-mortem .

“The script showed selected visitors a fake ‘Cloudflare, verify you are human’ page that instructed them to paste and run a command on their computer, a social-engineering technique known as ClickFix,” Brevo explains.

On the WordPress websites embedding a Brevo widget, the script attempted to deploy and run a plugin if the visitor was logged in as an administrator.

The malicious worker was active for roughly five and a half hours before Brevo removed it and revoked the compromised API key and credentials.

“Our investigation indicates the key was first misused in late August 2026. We have found no injection of malicious content into customer-facing pages before 14 September,” Brevo said.

According to cybersecurity firm Sansec , the malware was served for roughly four hours, and more than 100,000 websites were likely impacted.

The company recommends that all sites using Brevo be reviewed for potential compromise. Administrators should check for unauthorized plugin installations, and site visitors should check their machines for malware if they were served the fake verification pages.

Brevo is no longer serving malicious code. However, your WordPress site may have been backdoored, and your customers may have fallen for the ClickFix scam,” Sansec notes.

Related: Critical Orkes Conductor Vulnerability Exploited in Attacks

Related: OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

Related: Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

Related: Rust Supply Chain Attack Linked to North Korean Hackers

Ionut Arghire is an international correspondent for SecurityWeek.

More from Ionut Arghire

Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

Comp AI Raises $34 Million for AI-Native Compliance and Security

ISC Patches 14 Vulnerabilities in BIND 9 Security Update

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

AIUC Raises $40 Million to Certify Enterprise AI Agents

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

NightmareStresser DDoS Service Disrupted in International Operation

Critical Orkes Conductor Vulnerability Exploited in Attacks

MIND Secures $72 Million for AI-Powered DLP

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels

OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

Flipboard Whatsapp Whatsapp Email