Brevo, a popular customer engagement platform, experienced a severe supply chain attack that affected over 100,000 websites. The breach began on September 10 when attackers exploited Brevo's vulnerability in handling SAML SSO, gaining unauthorized access to 138 accounts, including one from cryptocurrency storage provider Trezor. The attackers leveraged this access to send phishing emails and export contacts from 43 accounts.

Although Brevo initially closed the breach, the attackers returned on September 14, utilizing a compromised Cloudflare API key to deploy a worker that injected malicious scripts. These scripts targeted brevo.com, sibforms.com, and several JavaScript files used by Brevo's clients. The attack introduced a fake verification page, employing a social-engineering tactic known as ClickFix, which tricked users into running commands on their machines.

On WordPress sites embedding Brevo widgets, the script tried to install and execute a plugin if the visitor was an administrator. The malicious activity continued for about five and a half hours before Brevo removed the worker and revoked the compromised credentials. Brevo's investigation suggests the API key misuse began in late August 2026, with no customer-facing page injections before September 14.

Sansec, a cybersecurity firm, estimates that over 100,000 websites were affected during the four-hour window the malware was active. Brevo advises all users to review their sites for unauthorized plugins, and visitors who encountered the fake page should scan their systems for malware. Although Brevo has stopped serving malicious code, there is a risk that WordPress sites may still be compromised, and customers may have fallen victim to the ClickFix scam.