Back Uk.Pcmag Hack at Marketing Vendor Exploited To Widely Spread ClickFix Malware Attack
A breach at an online marketing provider paved the way for a hacker to tamper with thousands of websites to display a fake verification screen meant to trick users into installing malware. The incident involves Brevo, a French company that supplies email and text marketing services. A hacker was able to steal a “long-lived” Brevo API key with Cloudflare, an internet infrastructure provider used to host content. The key provided a way for the hacker to widely tamper with Brevo’s services to its customer base on Monday. To do so, the culprit injected malicious computer code that appeared on brevo.com, a related domain sendinblue.com, and into “three JavaScript files that customers embed on their own websites,” including Brevo’s widget for WordPress sites. “The script showed selected visitors a fake ‘Cloudflare, verify you are human’ page that instructed them to paste and run a command on their computer, a social-engineering technique known as ClickFix,” Brevo wrote in a security incident write-up. ClickFix attacks work by pretending to be an error screen, or a “verify you’re human” page, that shows instructions on how to resolve the issue. But in reality, the posted instructions will cause your computer to manually download and install malware, if you follow them. Although a ClickFix attack won’t fool expert computer users, it can dupe casual consumers unaware they’re actually pasting a malicious URL and triggering their computer to run the downloaded file. In this case, the ClickFix attack persisted for “five and a half hours.” The fake Cloudflare page also asked the visitor “to press Win+R, then Ctrl+V, then Enter. Following those steps ran a command placed on the clipboard by the script, which downloaded malware onto the visitor's Windows computer. The page was shown selectively, so most visitors and repeat visits saw nothing,” Brevo added. Still, the hacker may have been able to spread the ClickFix attack to over 100,000 websites, according to the cybersecurity provider Sansec, citing a source code of the affected Brevo web components. How the hacker stole the API key is unclear, but Brevo discovered evidence that the key “was first misused in late August 2026.” The company has since revoked the compromised key and login credentials associated with it. The incident highlights how hackers are finding new ways to expand and evolve ClickFix-style attacks by hijacking official services. Earlier this month, a hacker pulled this off by briefly taking over HBO Max’s official account on , and using it to circulate fake ads designed to dupe users into installing malware. To stay safe, avoid any websites that randomly ask you to manually perform instructions on your keyboard. That’s a red flag that you’re encountering a ClickFix-style attack.
The incident involves Brevo, a French company that supplies email and text marketing services. A hacker was able to steal a “long-lived” Brevo API key with Cloudflare, an internet infrastructure provider used to host content. The key provided a way for the hacker to widely tamper with Brevo’s services to its customer base on Monday. To do so, the culprit injected malicious computer code that appeared on brevo.com, a related domain sendinblue.com, and into “three JavaScript files that customers embed on their own websites,” including Brevo’s widget for WordPress sites. “The script showed selected visitors a fake ‘Cloudflare, verify you are human’ page that instructed them to paste and run a command on their computer, a social-engineering technique known as ClickFix,” Brevo wrote in a security incident write-up. ClickFix attacks work by pretending to be an error screen, or a “verify you’re human” page, that shows instructions on how to resolve the issue. But in reality, the posted instructions will cause your computer to manually download and install malware, if you follow them. Although a ClickFix attack won’t fool expert computer users, it can dupe casual consumers unaware they’re actually pasting a malicious URL and triggering their computer to run the downloaded file. In this case, the ClickFix attack persisted for “five and a half hours.” The fake Cloudflare page also asked the visitor “to press Win+R, then Ctrl+V, then Enter. Following those steps ran a command placed on the clipboard by the script, which downloaded malware onto the visitor's Windows computer. The page was shown selectively, so most visitors and repeat visits saw nothing,” Brevo added. Still, the hacker may have been able to spread the ClickFix attack to over 100,000 websites, according to the cybersecurity provider Sansec, citing a source code of the affected Brevo web components. How the hacker stole the API key is unclear, but Brevo discovered evidence that the key “was first misused in late August 2026.” The company has since revoked the compromised key and login credentials associated with it. The incident highlights how hackers are finding new ways to expand and evolve ClickFix-style attacks by hijacking official services. Earlier this month, a hacker pulled this off by briefly taking over HBO Max’s official account on , and using it to circulate fake ads designed to dupe users into installing malware. To stay safe, avoid any websites that randomly ask you to manually perform instructions on your keyboard. That’s a red flag that you’re encountering a ClickFix-style attack.
To do so, the culprit injected malicious computer code that appeared on brevo.com, a related domain sendinblue.com, and into “three JavaScript files that customers embed on their own websites,” including Brevo’s widget for WordPress sites. “The script showed selected visitors a fake ‘Cloudflare, verify you are human’ page that instructed them to paste and run a command on their computer, a social-engineering technique known as ClickFix,” Brevo wrote in a security incident write-up. ClickFix attacks work by pretending to be an error screen, or a “verify you’re human” page, that shows instructions on how to resolve the issue. But in reality, the posted instructions will cause your computer to manually download and install malware, if you follow them. Although a ClickFix attack won’t fool expert computer users, it can dupe casual consumers unaware they’re actually pasting a malicious URL and triggering their computer to run the downloaded file. In this case, the ClickFix attack persisted for “five and a half hours.” The fake Cloudflare page also asked the visitor “to press Win+R, then Ctrl+V, then Enter. Following those steps ran a command placed on the clipboard by the script, which downloaded malware onto the visitor's Windows computer. The page was shown selectively, so most visitors and repeat visits saw nothing,” Brevo added. Still, the hacker may have been able to spread the ClickFix attack to over 100,000 websites, according to the cybersecurity provider Sansec, citing a source code of the affected Brevo web components. How the hacker stole the API key is unclear, but Brevo discovered evidence that the key “was first misused in late August 2026.” The company has since revoked the compromised key and login credentials associated with it. The incident highlights how hackers are finding new ways to expand and evolve ClickFix-style attacks by hijacking official services. Earlier this month, a hacker pulled this off by briefly taking over HBO Max’s official account on , and using it to circulate fake ads designed to dupe users into installing malware. To stay safe, avoid any websites that randomly ask you to manually perform instructions on your keyboard. That’s a red flag that you’re encountering a ClickFix-style attack.
“The script showed selected visitors a fake ‘Cloudflare, verify you are human’ page that instructed them to paste and run a command on their computer, a social-engineering technique known as ClickFix,” Brevo wrote in a security incident write-up. ClickFix attacks work by pretending to be an error screen, or a “verify you’re human” page, that shows instructions on how to resolve the issue. But in reality, the posted instructions will cause your computer to manually download and install malware, if you follow them. Although a ClickFix attack won’t fool expert computer users, it can dupe casual consumers unaware they’re actually pasting a malicious URL and triggering their computer to run the downloaded file. In this case, the ClickFix attack persisted for “five and a half hours.” The fake Cloudflare page also asked the visitor “to press Win+R, then Ctrl+V, then Enter. Following those steps ran a command placed on the clipboard by the script, which downloaded malware onto the visitor's Windows computer. The page was shown selectively, so most visitors and repeat visits saw nothing,” Brevo added. Still, the hacker may have been able to spread the ClickFix attack to over 100,000 websites, according to the cybersecurity provider Sansec, citing a source code of the affected Brevo web components. How the hacker stole the API key is unclear, but Brevo discovered evidence that the key “was first misused in late August 2026.” The company has since revoked the compromised key and login credentials associated with it. The incident highlights how hackers are finding new ways to expand and evolve ClickFix-style attacks by hijacking official services. Earlier this month, a hacker pulled this off by briefly taking over HBO Max’s official account on , and using it to circulate fake ads designed to dupe users into installing malware. To stay safe, avoid any websites that randomly ask you to manually perform instructions on your keyboard. That’s a red flag that you’re encountering a ClickFix-style attack.
ClickFix attacks work by pretending to be an error screen, or a “verify you’re human” page, that shows instructions on how to resolve the issue. But in reality, the posted instructions will cause your computer to manually download and install malware, if you follow them. Although a ClickFix attack won’t fool expert computer users, it can dupe casual consumers unaware they’re actually pasting a malicious URL and triggering their computer to run the downloaded file. In this case, the ClickFix attack persisted for “five and a half hours.” The fake Cloudflare page also asked the visitor “to press Win+R, then Ctrl+V, then Enter. Following those steps ran a command placed on the clipboard by the script, which downloaded malware onto the visitor's Windows computer. The page was shown selectively, so most visitors and repeat visits saw nothing,” Brevo added. Still, the hacker may have been able to spread the ClickFix attack to over 100,000 websites, according to the cybersecurity provider Sansec, citing a source code of the affected Brevo web components. How the hacker stole the API key is unclear, but Brevo discovered evidence that the key “was first misused in late August 2026.” The company has since revoked the compromised key and login credentials associated with it. The incident highlights how hackers are finding new ways to expand and evolve ClickFix-style attacks by hijacking official services. Earlier this month, a hacker pulled this off by briefly taking over HBO Max’s official account on , and using it to circulate fake ads designed to dupe users into installing malware. To stay safe, avoid any websites that randomly ask you to manually perform instructions on your keyboard. That’s a red flag that you’re encountering a ClickFix-style attack.
In this case, the ClickFix attack persisted for “five and a half hours.” The fake Cloudflare page also asked the visitor “to press Win+R, then Ctrl+V, then Enter. Following those steps ran a command placed on the clipboard by the script, which downloaded malware onto the visitor's Windows computer. The page was shown selectively, so most visitors and repeat visits saw nothing,” Brevo added. Still, the hacker may have been able to spread the ClickFix attack to over 100,000 websites, according to the cybersecurity provider Sansec, citing a source code of the affected Brevo web components. How the hacker stole the API key is unclear, but Brevo discovered evidence that the key “was first misused in late August 2026.” The company has since revoked the compromised key and login credentials associated with it. The incident highlights how hackers are finding new ways to expand and evolve ClickFix-style attacks by hijacking official services. Earlier this month, a hacker pulled this off by briefly taking over HBO Max’s official account on , and using it to circulate fake ads designed to dupe users into installing malware. To stay safe, avoid any websites that randomly ask you to manually perform instructions on your keyboard. That’s a red flag that you’re encountering a ClickFix-style attack.
Still, the hacker may have been able to spread the ClickFix attack to over 100,000 websites, according to the cybersecurity provider Sansec, citing a source code of the affected Brevo web components. How the hacker stole the API key is unclear, but Brevo discovered evidence that the key “was first misused in late August 2026.” The company has since revoked the compromised key and login credentials associated with it. The incident highlights how hackers are finding new ways to expand and evolve ClickFix-style attacks by hijacking official services. Earlier this month, a hacker pulled this off by briefly taking over HBO Max’s official account on , and using it to circulate fake ads designed to dupe users into installing malware. To stay safe, avoid any websites that randomly ask you to manually perform instructions on your keyboard. That’s a red flag that you’re encountering a ClickFix-style attack.
The incident highlights how hackers are finding new ways to expand and evolve ClickFix-style attacks by hijacking official services. Earlier this month, a hacker pulled this off by briefly taking over HBO Max’s official account on , and using it to circulate fake ads designed to dupe users into installing malware. To stay safe, avoid any websites that randomly ask you to manually perform instructions on your keyboard. That’s a red flag that you’re encountering a ClickFix-style attack.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
