Attackers spent roughly four hours on 14 September rewriting Brevo’s JavaScript as it left Cloudflare’s edge without touching a single file on Brevo’s servers. The French marketing platform, formerly Sendinblue, confirmed in a post-mortem published on 17 September that an attacker stole a Cloudflare API key and used it to deploy a malicious Cloudflare Worker across Brevo’s zones. The Worker rewrote responses for brevo.com, sendinblue.com and sibforms.com along with the forms script, Conversations widget and SDK loader that Brevo customers embed on their own websites.
Dutch security firm Sansec which first reported the wider scope, observed the malicious activity between 16:05 and 20:13 UTC and estimates that more than 100,000 customer sites loaded the modified code. That figure comes from a company that sells a malware scanner and Brevo has not confirmed it. Treat it as an upper bound until someone independent counts.
A Full-Permission API Key, Hardcoded in Source
Brevo’s own account of the root cause is the part that matters. The stolen credential was a long-lived Cloudflare API key with full account permissions, hardcoded in application source code. It carried enough authority to create Cloudflare Workers, routes and DNS records across every Brevo zone.
Editing at the edge is what made this difficult to spot. The files on Brevo’s origin servers stayed exactly as they were. Any check of file hashes, modification dates or origin content would have come back clean because nothing was wrong there. The rewrite happened in transit. Brevo also confirmed the Worker could strip security headers including Content-Security-Policy which removes the one browser-side control that might have blocked the injected script.
Two Payloads, Sorted by Who Was Looking
Sansec’s analysis found that the injected code branched on the visitor. A logged-in WordPress administrator opening their own site got a malicious plugin upload, built for persistence and capable of loading further JavaScript. Everyone else got a full-screen overlay imitating a Cloudflare verification page followed by ClickFix instructions telling them to paste a command into Windows and run it.
The overlay also reached anyone who clicked an unsubscribe link in a campaign email sent through Brevo. The code skipped crawlers, developer tools and automated scanners.
The Second Brevo Incident in Five Days
This was not Brevo’s first problem that week. On 10 September the company disclosed that an attacker had exploited improperly scoped SAML SSO access to reach 138 customer accounts, exporting contacts from 43 of them and sending phishing emails from 6. Brevo says it closed the access path at 08:30 UTC and reset active sessions.
Trezor, the Czech hardware wallet maker, published its own account the same day and put the figure at 120 Brevo accounts. The two numbers do not reconcile and neither company has explained the gap. Trezor’s newsletter database of roughly 347,000 addresses was used to send a phishing email with the subject line “Critical Security Alert: STM32 Entropy Vulnerability”, linking to an application that asked recipients for their wallet backup. Trezor killed the domain at DNS level within 20 minutes and says 2,500 people had already clicked.
Brevo Is Clean. Your Site May Not Be.
Brevo revoked the key and every credential created with it, removed the hardcoded secret from its source code, deleted the attacker’s hostnames and purged its edge caches. Sansec confirmed on 15 September that the malicious subdomains had stopped resolving and that Brevo’s files were serving clean.
That closes Brevo’s side of it. It does not close yours. If a WordPress administrator at your organisation opened the site between 16:00 and 21:00 UTC on 14 September, a plugin may have been installed and a revoked key at Brevo does nothing about a plugin sitting in your own wp-content directory.
Audit your installed WordPress plugins for anything added on or after 14 September. Find out whether any workstation ran a pasted PowerShell command that afternoon because a ClickFix infection usually ends in an infostealer and stolen browser credentials. Then inventory every third-party script your site loads and decide which ones still earn their place.
Brevo says app.brevo.com, its API, email delivery infrastructure and customer account data were untouched. The statement is accurate and beside the point. The attack ran on customer websites, in customer visitors’ browsers, under Brevo’s domain names.
References
- Brevo Supply-Chain Attack Injected ClickFix Scripts on Customer Sites
- Brevo Supply Chain Attack Hits 100k+ Sites with WordPress Backdoors and Clickfix Malware
- Security Incident at Brevo, Our Third-Party Email Provider
- 100,000+ WordPress Sites Infected Via Brevo Supply Chain Attack
This post is also available in:


