BREVO suffered a supply-chain attack that injected malicious code into more than 100,000 websites, according to cybersecurity firm Sansec. The incident began on 10 September, when an attacker exploited a vulnerability in Brevo’s handling of SAML single sign-on (SSO) to access 138 accounts. Brevo said six accounts were used to send phishing emails, while contacts were exported from 43 accounts, including an account belonging to cryptocurrency storage provider Trezor.
After Brevo blocked the unauthorised access, the attacker returned on 14 September using a compromised long-lived Cloudflare API key to deploy a worker. The worker modified brevo.com and sibforms.com, as well as three JavaScript files that customers embed in their websites. It displayed a fake “Cloudflare, verify you are human” page to selected visitors, directing them to paste and run a command on their computers in a ClickFix social-engineering attack. On WordPress sites using a Brevo widget, the script also attempted to install and run a plugin when the visitor was logged in as an administrator.
Brevo removed the worker and revoked the compromised key and credentials after approximately five and a half hours; Sansec said the malware was served for roughly four hours. Brevo said its investigation found no malicious content injected into customer-facing pages before 14 September, although the API key may have been misused as early as late August 2026.
Brevo customers are advised to review their sites for compromise, particularly unauthorised WordPress plugins, while visitors who encountered the fake verification page should check their computers for malware.