Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Hackers Abuse Brevo Cloudflare Key in Supply-Chain Attack Affecting 100,000+ Websites

Hackers Abuse Brevo Cloudflare Key in Supply-Chain Attack Affecting 100,000+ Websites

By: Jordan Vector — Cybersecurity Expert

Last updated: September 18, 2026

Human Written
Hackers Abuse Brevo Cloudflare Key in Supply-Chain Attack Affecting 100,000+ Websites
  • Attackers used a stolen Brevo Cloudflare API key to change content delivered through Brevo’s network.

  • Visitors saw fake Cloudflare checks that pushed them to run a malicious command on Windows.

  • WordPress admins faced a second threat: an attempt to install a hidden malicious plugin.

Brevo’s infrastructure became the delivery path for a major malware campaign on September 14, putting more than 100,000 customer websites at risk.

The French marketing and customer engagement company said attackers used a compromised Cloudflare API key to deploy a malicious Cloudflare Worker. The Worker changed content as it passed through Brevo’s CDN, without changing the company’s original files.

Brevo said the attack lasted five hours and 29 minutes. Its official impact window ran from 15:01 to 20:30 UTC.

Attackers Changed Brevo’s Web Traffic

Brevo said the attacker had a long-lived Cloudflare API key with full account permissions. The key was stored in application source code and was obtained by the attacker.

That access allowed the attacker to create Workers, routes and DNS records across Brevo’s Cloudflare zones. The Worker then rewrote web responses at the CDN edge.

Brevo said the edge-level change also meant normal checks on its original files could miss the attack. The Worker altered responses only when visitors requested affected resources, making the activity harder to spot.

The company said the stolen key had broad permissions and could create changes across several Brevo zones. That gave the attacker a way to reach both Brevo pages and customer-facing tools from one compromised credential.

The company said the attacker first misused the key in late August. However, Brevo found no evidence that the attacker injected malicious content into customer-facing pages before September 14.

Sansec independently observed malicious activity from 16:05 to 20:13 UTC. It found injected code in Brevo resources used by customer websites, including its tracker and chat tools. Sansec estimated that more than 100,000 sites could have been exposed.

Fake Cloudflare Checks Pushed Malware

The attack used ClickFix, a social engineering trick that makes a malicious action look like a normal fix. Visitors could see a full-screen page branded to look like Cloudflare. Some saw it after passing a real Cloudflare check.

The fake page told users to press Win+R, then Ctrl+V to paste what’s in their clipboard and Enter. Turns out, the clipboard already contained a malicious command.  Doing so will cause Windows to execute that code and download malware.

Cloudflare’s security tools have also become a target for attackers looking to bypass automated verification. In a separate case, a threat actor released alleged Cloudflare Turnstile bypass code on a cybercrime forum, highlighting another way criminals may try to get around Cloudflare’s defenses.

Brevo said only certain visitors saw the fake page. That wasn’t the end of it, though; the attack also made its way into Brevo forms, the Conversations widget, and even the SDK loader.

Sansec discovered that hackers had tweaked Brevo scripts so they’d pull extra code from subdomains under a Brevo-owned domain, but controlled by the attackers.  Sansec found modified versions of Brevo scripts that loaded additional code from attacker-controlled subdomains under a Brevo-owned domain.

WordPress Admins Faced a Second Threat

The attack was more serious for some WordPress sites. The malicious script checks whether a visitor is logged in as a WordPress administrator. It then attempted to install and activate a malicious plugin.

Security researchers analyzed a copy of the plugin and identified it as ‘Web Media Optimizer.’ The plugin acts as a persistent backdoor and JavaScript loader. Sansec advises site owners to review plugins installed or activated on September 14. Owners should also check server logs for unexpected plugin activity.

Brevo Says Core Services Remain Unaffected

The company removed the malicious Worker and its routes at 20:30 UTC. It also revoked the stolen API key and other credentials created through it.

Brevo then deleted attacker-created hostnames and cleared its edge caches. An independent check at 20:42 UTC found the affected pages and scripts clean, according to the company. Sansec later found that the malicious hostnames had stopped resolving on September 15.

Brevo is also changing how it protects its Cloudflare credentials. It plans to store keys in the HashiCorp Vault, rotate them automatically, and stop putting credentials in source code.

The Attack Followed Another Brevo Incident

The ClickFix attack came only four days after a separate Brevo security incident. On September 10, Brevo confirmed that a hacker took advantage of the vulnerability in its SAML single sign-on and accessed 138 customer accounts.

The attackers made use of six accounts for sending phishing emails. They exported contacts from 43 accounts, and 93 accounts showed no meaningful activity. Brevo closed that route and signed out all users. It said the September 14 incident was separate.

For businesses using Brevo tools, the latest attack highlights a wider risk. A supplier does not need to breach every customer site directly to affect them. A trusted script, widget or form can become the bridge.

WordPress site owners would need to check if an administrator accessed their website on September 14 while logged in. Those who have been using the fake verification process should consider their computers compromised, unplug them, and conduct a comprehensive antivirus scan, along with changing passwords.

Share this article

You might also like

Spain’s Data Regulator Reports First AI Agent Cyberattack Data Breach

Spain’s Data Regulator Reports First Personal Data Breach Carried Out by AI Agent

The AEPD of Spain announced the occurrence of a data breach where an AI agent independently accessed, scouted for vulnerabilities,…

September 18, 2026
FBI and Canadian Police Seize Domains Linked to Long-Running DDoS Service

FBI and Canadian Police Seize Domains of Long-Running NightmareStresser DDoS Service

The FBI and Royal Canadian Mounted Police seized domains for NightmareStresser, one of the world’s longest-running DDoS-for-hire services. The service…

September 18, 2026
Hacker Claims Mistral AI Source Code is for Sale on Cybercrime Forum

Threat Actor Claims Full Source Code of French AI Firm Mistral is for Sale

A hacker using the alias mrwho claims to have the full source code of Mistral AI and is advertising it…

September 18, 2026

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.