News

Attackers Hijacked Brevo Widgets and Hit 100,000 Sites Before Anyone Noticed the Supply Chain

Brevo's 14 September 2026 post-mortem says a compromised Cloudflare API key injected ClickFix scripts from 15:01 to 20:30 UTC. Sansec estimates more than 100,000 sites. WordPress admins faced silent plugin-install attempts.

Attackers Hijacked Brevo Widgets and Hit 100,000 Sites Before Anyone Noticed the Supply Chain

Brevo published a status post-mortem for a 14 September 2026 Cloudflare Worker injection. CyberInsider (Alex Lekander, 17 September 2026), citing Sansec, put the downstream reach at more than 100,000 sites. BleepingComputer carried the same incident.

This is a company post-mortem on Brevo's status portal. It is not a CVE, and it is not a CISA Known Exploited Vulnerabilities listing. The 100,000-plus figure is Sansec's scale estimate. Brevo's write-up does not cite that number.

An attacker used a compromised Brevo Cloudflare API key to deploy a Worker that rewrote responses at the CDN edge. The impact window ran from 15:01 to 20:30 UTC on 14 September 2026, about 5 hours and 29 minutes. The embedded JavaScript loader append started at 16:07 UTC and was removed at 20:30.

Affected surfaces included pages on brevo.com and sibforms.com, plus three customer-embedded JavaScript surfaces: the SDK loader, the Conversations widget, and forms. The ClickFix lure was a fake Cloudflare "verify you are human" page telling Windows users to press Win+R, Ctrl+V, and Enter, then run a clipboard command that downloaded malware.

On WordPress sites embedding Brevo widgets, if the visitor was a logged-in administrator, the script also tried to silently install and activate a plugin. Sansec said the plugin was fetched from cdn10.sendibt1.com/p/wm.zip and that it did not recover the binary, so Sansec could not confirm what the plugin did.

Not affected: app.brevo.com, the Brevo API, email sending, and customer account data held in Brevo. Origin source files were unmodified. The root cause was a long-lived Cloudflare API key with full account permissions stored in application source code. Brevo says the key was first misused in late August 2026, and it found no customer-facing injection before 14 September.

A separate Brevo SAML SSO incident on 10 September, affecting 138 accounts, is prior-week context. It is not the same attack.

Related ClickFix and WordPress tape includes the HBO Max Reddit ClickFix campaign, the All-in-One WP Migration takeover risk, and OpenAI rogue agents on Hugging Face.

If you embed Brevo widgets, treat 14 September as a live incident window: scan Windows hosts that ran a pasted "verify you are human" command, and on WordPress, hunt for any plugin installed or activated that day, then rotate administrator passwords.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free