Brevo confirms ClickFix supply-chain attack tied to stolen Cloudflare key

Sept. 20, 2026 update: Brevo’s public status page marks the Sept. 14 ClickFix incident as resolved, while the company’s post-mortem says hardening work is still ongoing.

Brevo says a compromised Cloudflare API key allowed an attacker to serve a malicious ClickFix script through Brevo-controlled infrastructure on Sept. 14, 2026. The incident reached beyond Brevo’s own pages because the injected code also affected JavaScript files that customers embed on their websites, including Brevo forms, the Brevo Conversations widget, and the Brevo SDK loader.

The company said the overall impact window ran from 15:01 to 20:30 UTC on Sept. 14. The customer-embedded files and sibforms.com were affected from 16:07 UTC until the malicious Worker and routes were removed at 20:30 UTC.

What Brevo says happened

According to Brevo’s post-mortem, the attacker obtained a long-lived Cloudflare API key with full account permissions that had been stored in application source code. That key allowed the attacker to create Cloudflare Workers, routes, and DNS records across Brevo zones without triggering an alert.

The malicious Worker rewrote content at Cloudflare’s edge. Brevo said its origin servers and source files were not modified, which meant standard integrity checks did not detect the change. The Worker also removed security headers such as Content-Security-Policy from affected responses.

Brevo listed the affected surfaces as Brevo and Sendinblue web pages, sibforms.com and the Brevo forms script, the Brevo Conversations widget, and the Brevo SDK loader. The company said app.brevo.com, the Brevo API, email sending, and customer account data held in Brevo were not affected by this ClickFix incident.

What visitors may have seen

The malicious script showed some visitors a fake Cloudflare-style verification page. Brevo said the page asked visitors to press Win+R, then Ctrl+V, then Enter. The script placed a command on the clipboard, and following the instructions would run that command on the visitor’s Windows computer.

That tactic is known as ClickFix: a fake verification or error prompt tricks a person into running a command that installs malware. Brevo said the prompt appeared selectively, so many visitors and repeat visits would have seen nothing.

The WordPress risk

Brevo said that, on WordPress sites embedding an affected Brevo widget, the script also attempted to install and activate a plugin if the visitor was logged in as a WordPress administrator.

Security firm Sansec, which first reported the incident publicly, said the injected script checked whether the visitor was logged in to WordPress and then attempted to install a plugin. BleepingComputer later reported that a plugin archive it found on VirusTotal appeared to pose as a WordPress plugin named Web Media Optimizer, while acting as a persistent backdoor and JavaScript loader.

That distinction matters. The incident did not require each individual WordPress site to be hacked first. A logged-in administrator visiting a site that loaded the affected Brevo script during the exposure window could have created the opportunity for the malicious plugin attempt.

How broad the exposure may have been

Sansec reported that Brevo served malware to more than 100,000 customer sites that used affected Brevo components. That figure should not be read as a confirmed count of infected computers or backdoored websites. Actual harm depended on whether the affected script loaded during the window, whether the ClickFix prompt was shown, whether a visitor followed the instructions, and whether a WordPress administrator was logged in when visiting a vulnerable page.

Brevo’s post-mortem says the malicious Worker and routes were removed at 20:30 UTC on Sept. 14, and independent verification confirmed affected pages and scripts were restored at 20:42 UTC. Sansec reported that malicious hostnames stopped resolving on Sept. 15.

Why small business websites should pay attention

For Canadian small businesses using hosted forms, chat widgets, analytics tags, and marketing automation scripts, the incident shows how trusted third-party JavaScript can become part of a site’s attack surface.

A website’s own files can remain unchanged while visitors still receive malicious code from an embedded vendor script or CDN-edge rewrite. That makes third-party script inventory, browser-side protections, admin activity monitoring, and incident response planning more than technical housekeeping.

Checks site owners should make now

Website owners and administrators that used Brevo scripts on Sept. 14 should review whether the Brevo tracker, Conversations widget, SDK loader, hosted forms, or sibforms.com assets were present on public pages during the exposure window.

  • Check web access logs for WordPress plugin upload activity on Sept. 14, especially requests to /wp-admin/update.php?action=upload-plugin, followed by plugin activation activity.
  • Review plugins installed or activated on Sept. 14, including plugins that do not appear in the WordPress admin screen but exist in the site’s plugin directories.
  • Review administrator accounts, recent admin sessions, and any unexpected must-use plugins.
  • Rotate WordPress administrator passwords if suspicious plugin activity appears.
  • Treat any computer that followed the fake verification prompt as compromised. Brevo recommends disconnecting the device, running a full antivirus scan, and changing passwords used on it, starting with the Brevo password.
  • If a user logged in to Brevo through brevo.com on Sept. 14, Brevo recommends changing the Brevo password and reviewing API keys as a precaution.

Site owners that did not use Brevo during the incident window are not in scope for the Brevo-specific script exposure. Still, the same risk model applies to any third-party script that runs on a website.

Brevo also disclosed a separate SSO incident

The ClickFix incident was not Brevo’s only security disclosure that week. In a separate Sept. 10 write-up, Brevo said an attacker exploited a flaw in how it handled SAML SSO to access 138 Brevo accounts. Brevo said six of those accounts were used to send phishing emails, contacts were exported from 43 accounts, and 93 accounts showed no meaningful activity.

Brevo said it closed that access route and signed out every platform user at 8:30 UTC on Sept. 10. Public reporting reviewed for this draft does not establish a confirmed connection between the Sept. 10 SSO issue and the Sept. 14 Cloudflare/ClickFix incident.

What Brevo says it has changed

Brevo said it removed the malicious Worker, revoked the compromised key and credentials created with it, reviewed Cloudflare account access, purged edge caches, and removed the hardcoded credential from source code.

The company also said it is moving Cloudflare keys and tokens into HashiCorp Vault, adopting scoped short-lived tokens, alerting on Cloudflare audit events that change Workers, routes, DNS, or account access, streaming Cloudflare logs to its security monitoring platform, adding integrity protection for versioned embedded assets where technically possible, and reviewing third-party edge configurations across Brevo domains.

Further details may still emerge about affected sites, malware payloads, and any relationship between the two September incidents. For now, the practical priority is narrow: identify whether Brevo scripts were present during the Sept. 14 window, check WordPress admin activity from that day, and treat any device that ran the fake verification command as compromised.

Get new small business insights by email

Practical ideas and useful articles to help you make better business decisions.

HelperX Bot

Not sure what to read next?

I can suggest related Tech Help Canada articles based on the topic you’re reading now.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us

Leave a Comment

Tweet
Share
Share
Pin
WhatsApp
Reddit
Email