Brevo supply-chain attack injected ClickFix scripts on customer sites
Brevo confirms attackers used a stolen Cloudflare API key to inject malicious ClickFix scripts into its and its customers' sites, affecting up to 100,000 websites.
Intelligence analysis by Qwen 2.5 (3B)

Brevo reports a supply chain attack where attackers used a stolen API key to inject malicious ClickFix scripts into Brevo and its customers' sites, affecting up to 100,000 websites.
Bad guys stole a special code from Brevo and used it to put sneaky stuff on Brevo's and other websites. This made other websites show fake messages and let the bad guys do bad things.
Analysis
{"heading_1":"The Attack","paragraph_1":"Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware.","paragraph_2":"The attack affected pages on brevo.com, sendinblue.com, login/account/my/onboarding.brevo.com, and sibforms.com. The Cloudflare worker also modified the Brevo forms script, Brevo Conversations widget, and the Brevo SDK loader scripts that customers embed on their websites.","paragraph_3":"Brevo says the attackers used the API key to create a malicious Cloudflare Worker that modified content at the CDN edge for approximately five and a half hours on September 14. The attack was detected and mitigated by Brevo within a few hours of the compromise.","paragraph_4":"Brevo says the key may have been compromised as early as late August, but there's no evidence of prior malicious activity. Upon detecting the compromise, Brevo removed the Worker and its routes, revoked the compromised key and credentials created with it, removed the hardcoded credential from its source code, deleted attacker-controlled hostnames, and purged its edge caches."}
Key points
- Brevo confirmed the attack and says it affected up to 100,000 websites.
- The attack was detected and mitigated within a few hours of the compromise.
- Brevo says the key may have been compromised as early as late August, but there's no evidence of prior malicious activity.
The attack was quickly detected and mitigated, and Brevo took steps to prevent it from happening again. This shows that security teams can respond to such attacks effectively.
The attack could have affected more sites if Brevo had not acted quickly. The incident also highlights the importance of securing API keys and monitoring for suspicious activity.



