Brevo supply-chain attack: one leaked key, 100,000 websites
On 14 September 2026 attackers used a leaked Cloudflare API key to inject malicious code into scripts that marketing platform Brevo serves to its customers’ websites. For roughly five and a half hours, forms, chat widgets and sign-up pages on sites that had done nothing wrong became a delivery route for malware. Days earlier, a separate Brevo incident had been used to phish Trezor’s customers. Together they show how quickly a trusted supplier can become your biggest exposure.
What happened
Brevo’s own incident write-up is unusually detailed. A Cloudflare API key with full account permissions had been hardcoded in application source code and was compromised. The attacker used it to deploy a malicious Cloudflare Worker that rewrote content at the edge of Brevo’s content delivery network, so checks on Brevo’s origin servers saw nothing wrong. BleepingComputer reports that Brevo said the Worker also stripped security headers such as Content-Security-Policy.
According to Brevo, impact began at 15:01 UTC on brevo.com. From 16:07 UTC the injection extended to sibforms.com and to files embedded on customer sites, including the Brevo forms script, the Conversations chat widget and the SDK loader. The Worker was removed at 20:30 UTC. Brevo says its application platform, API, email sending and customer account data were not affected.
Researchers at Sansec estimated that up to 100,000 websites using Brevo components could have been affected. Visitors were shown a fake verification page and ClickFix instructions persuading them to run attacker-supplied commands. BleepingComputer reports that visitors logged in as WordPress administrators were targeted with a malicious plugin upload giving the attackers a backdoor.
Separately, BleepingComputer reports that a Brevo incident on 9 September affecting 120 customer accounts was used to send phishing emails from Trezor’s account. Trezor said the phishing reached its newsletter list of roughly 347,000 addresses and that around 2,500 people clicked before it took the phishing domain down.
- Root cause
- A hardcoded, over-privileged cloud API key in source code.
- Exposure window
- About five and a half hours on 14 September 2026.
- Who was hit
- Visitors to customer websites embedding Brevo scripts, not only Brevo’s direct users.
Why this is a third-party risk story, not just a Brevo story
Most of the websites affected had no relationship with Cloudflare and no visibility of Brevo’s secrets management. They had simply embedded a trusted script. That is the essence of fourth-party risk: your supplier’s supplier, and your supplier’s internal hygiene, become your attack surface.
Three lessons stand out:
- Embedded scripts run with your authority. A third-party JavaScript file on your page can do anything your own code can, including reading form inputs and targeting logged-in administrators.
- Questionnaires miss this. Annual vendor questionnaires rarely ask how secrets are stored, whether edge configuration changes are alerted on, or how quickly a supplier would detect tampering.
- Your customers see your brand, not your vendor’s. If a visitor is compromised on your website, the reputational and potentially regulatory fallout lands on you.
“Every third-party script on your website is a supplier with write access to your customers’ browsers. Treat it that way.”
— Praeferre analysisWhat to do now
- If you embed Brevo components, follow Brevo’s guidance: WordPress administrators should check for unauthorised plugins installed on 14 September, and anyone who ran commands from a fake verification prompt should treat the device as compromised.
- Inventory third-party scripts. List every externally hosted script on your sites, who owns it and why it is there. Remove what you do not need.
- Use Subresource Integrity and a strict Content Security Policy where the supplier supports versioned files, and monitor for script changes in production.
- Tier suppliers by access, not spend. A low-cost marketing tool that injects code into your pages may deserve closer scrutiny than a large but isolated contract.
- Ask sharper questions. Add secrets management, edge and CDN change monitoring, and incident notification timelines to your vendor assessments and contracts.
- Monitor continuously. Point-in-time reviews cannot catch a five-hour window. Continuous monitoring and fast supplier breach alerts can.
Praeferre’s Third-Party Risk Management platform helps you tier suppliers by real exposure, run targeted assessments and track remediation. Our penetration testing team can also review how third-party code behaves on your web estate. Under DORA and NIS2, supply-chain security is now an explicit regulatory expectation.
See which of your suppliers could put your customers at risk, and track them continuously.
Explore TPRMCommon questions
Brevo says its application platform, API, email sending and customer account data were not affected. The attack injected malicious scripts into web assets, including files embedded on customer websites.
ClickFix is a social engineering technique where a web page shows a fake verification or error message and instructs the visitor to copy and run a command on their own computer, which installs malware.
Keep an inventory of external scripts, remove unnecessary ones, use Subresource Integrity and Content Security Policy where possible, monitor scripts for changes, and include script security in vendor assessments.
Sources
- Security incident write-up (14 September 2026) — Brevo, 14 September 2026
- Brevo supply-chain attack injected ClickFix scripts on customer sites — BleepingComputer, 17 September 2026
- Trezor: 347,000 users targeted in phishing attacks after Brevo breach — BleepingComputer, 11 September 2026