Skip to content
Brevo Supply Chain Attack Infects Over 100,000 Websites

Brevo Supply Chain Attack Infects Over 100,000 Websites

First seen 17 Sep 2026, 16:29 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 18:24 UTC
  • Attackers exploited a compromised Cloudflare API key to inject malware into Brevo's services.
  • Over 100,000 websites were affected, with a focus on WordPress sites where admins were targeted.
  • Brevo's infrastructure was used to serve malicious scripts, leading to significant downstream impacts.

On September 14, 2026, a compromised Brevo Cloudflare API key allowed attackers to deploy a malicious Cloudflare Worker that injected malware into brevo.com and over 100,000 customer websites. The attack utilized social engineering techniques, displaying a fake CAPTCHA page to visitors, prompting them to execute a command that downloaded malware. Additionally, logged-in WordPress administrators were targeted with a malicious plugin intended to create a backdoor. The malware was served through modified JavaScript assets embedded in customer sites, affecting both Brevo's own domains and its clients, including major brands like eBay and Louis Vuitton. Brevo confirmed that its application at app.brevo.com was unaffected, and the malicious activity ceased by 20:30 UTC on the same day. Independent verification confirmed that all affected pages were cleaned shortly after the incident. Brevo had previously disclosed a separate security issue on September 10, indicating prior vulnerabilities in its systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-10
Brevo discloses prior security issue
An attacker exploited a flaw in SAML SSO, affecting 138 accounts and exporting contacts from 43.
Cybernews
2026-09-14
Malicious Cloudflare Worker deployed
Attackers used a compromised API key to inject malware into Brevo's sites and customer domains.
Article 1
2026-09-14
Malware served to visitors
Malicious scripts displayed fake CAPTCHA prompts to users and targeted WordPress admins with a backdoor plugin.
Article 3
2026-09-14
Attack window confirmed
Sansec reported the malicious activity occurred between 16:05 and 20:12 UTC, affecting numerous sites.
Article 2
2026-09-15
Malicious hosts stopped resolving
Brevo confirmed that the malicious domains were taken down and affected files restored.
Article 4

More articles in this cluster (4)

Following this threat?

Track ClickFix and Amnesty International in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed