Cyberinsider Brevo Supply Chain Attack Infects Over 100,000 Websites
Article Content
- •Attackers exploited a compromised Cloudflare API key to inject malware into Brevo's services.
- •Over 100,000 websites were affected, with a focus on WordPress sites where admins were targeted.
- •Brevo's infrastructure was used to serve malicious scripts, leading to significant downstream impacts.
On September 14, 2026, a compromised Brevo Cloudflare API key allowed attackers to deploy a malicious Cloudflare Worker that injected malware into brevo.com and over 100,000 customer websites. The attack utilized social engineering techniques, displaying a fake CAPTCHA page to visitors, prompting them to execute a command that downloaded malware. Additionally, logged-in WordPress administrators were targeted with a malicious plugin intended to create a backdoor. The malware was served through modified JavaScript assets embedded in customer sites, affecting both Brevo's own domains and its clients, including major brands like eBay and Louis Vuitton. Brevo confirmed that its application at app.brevo.com was unaffected, and the malicious activity ceased by 20:30 UTC on the same day. Independent verification confirmed that all affected pages were cleaned shortly after the incident. Brevo had previously disclosed a separate security issue on September 10, indicating prior vulnerabilities in its systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track ClickFix and Amnesty International in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Russia's AI-Driven Cyber Espionage Targets Ukraine and Europe A Russian-linked hacking group, identified as GTG-20006, has utilized Anthropic's Claude AI to automate cyber espionage against over 20 organizations, primarily in Ukraine and Europe. The group targeted Ukrainian government officials, military personnel, and drone manufacturers through sophisticated phishing and…
Healthcare Cyberattacks Disrupt Patient Care and Expose Sensitive Data Two major healthcare companies, Boston Scientific and Nutex Health, reported cyberattacks that compromised patient data and disrupted operations. Boston Scientific's systems were breached on August 25, affecting the functionality of pacemakers and other heart devices, preventing remote monitoring. The company is…