Brevo Supply Chain Hack Compromises 100K Websites with Malware Injection
Customer engagement platform Brevo experienced a supply chain compromise leading to malicious code deployment across over 100,000 websites.
The Breach Unveiled
Customer engagement platform Brevo experienced a supply chain compromise that led to the deployment of malicious code across over 100,000 websites. The breach began on September 10 when a threat actor exploited a flaw in Brevo’s SAML SSO implementation to gain access to 138 accounts, including one linked to cryptocurrency storage provider Trezor. The attackers leveraged compromised credentials to send phishing messages from six accounts and extract contact lists from 43 accounts, as disclosed in a company incident report.
The Second Intrusion
Brevo addressed the initial breach but detected a second intrusion on September 14 when adversaries utilized a stolen long-lived Cloudflare API key to deploy a malicious worker. This worker injected harmful scripts into brevo.com, sibforms.com, and three JavaScript files commonly embedded by Brevo customers. The malicious code prompted targeted users to interact with a deceptive “Cloudflare, verify you are human” prompt, urging them to execute a command on their devices—a tactic known as ClickFix.
Impact and Response
On WordPress sites utilizing Brevo widgets, the script attempted to install and activate a plugin if the visitor was logged in as an administrator. The malicious worker operated for approximately five hours and 30 minutes before Brevo detected and removed it, revoking the compromised API key and credentials. Brevo’s investigation revealed the API key had been misused as early as late August 2026, though no malicious content was detected on customer-facing pages prior to September 14.
Cybersecurity firm Sansec estimated the malware was active for about four hours, impacting more than 100,000 domains. The firm advises administrators to inspect websites using Brevo for signs of unauthorized modifications and to scan systems for malware if users encountered the fake verification page. Sansec emphasized that while Brevo no longer serves malicious code, compromised WordPress sites may still contain backdoors, and users could have fallen victim to the ClickFix scheme.
Implications and Recommendations
The incident highlights vulnerabilities in third-party service integrations and underscores the risks of compromised API keys in cloud environments. Organizations are urged to review their supply chain security practices and monitor for anomalous activity in embedded scripts.
