The Brevo ClickFix attack used a compromised Cloudflare API key to inject malicious content into company pages and three scripts embedded on customer sites for about five and a half hours.
Everyone else is reporting the launch or headline metric; we are explaining the operating mechanism, limits and evidence needed next.
Brevo ClickFix attack moved through the CDN edge
Brevo’s post-mortem identifies a long-lived Cloudflare API key with full account permissions as the root cause. The key had been stored in application source code. An attacker used it to create workers, routes and DNS records that changed responses after they left Brevo’s origin systems.
That edge position explains why normal file-integrity checks did not detect the injection. Brevo says the worker also removed Content-Security-Policy headers and selectively displayed a fake Cloudflare verification page. Visitors who followed its instructions pasted and ran a command on Windows, the social-engineering pattern known as ClickFix.
The affected surfaces included brevo.com, sendinblue.com, sibforms.com, a forms script, the Conversations widget and the SDK loader. On WordPress sites, the injected code also attempted to install a plugin when an administrator visited while logged in. Brevo advises treating any machine that ran the command as compromised.
Sansec first documented the wider supply-chain path and estimated that embedded components could have exposed more than 100,000 sites. BleepingComputer independently examined the malicious plugin and reported persistence and backdoor behaviour. Cybernews later covered the same broad reach. The exact affected-user count remains unverified.
Brevo’s incident record says the first broad impact began at 15:01 UTC and ended at 20:30, with embedded files affected from 16:07. The company revoked the key and attacker-created credentials, removed hostnames, purged edge caches and began customer notification the next day.
The distinction between origin and edge is the security lesson. A clean repository does not prove that users received clean JavaScript when a privileged CDN account can rewrite responses. Organisations need external monitoring, audit-event alerts, short-lived tokens and integrity controls that observe what browsers actually download.
For Indian businesses using third-party marketing widgets, the response should begin with an inventory of remotely loaded code. WordPress administrators who were logged in on September 14 should review plugins installed or activated that day, rotate administrator credentials where suspicious activity appears and follow Brevo’s remediation guidance.
Brevo says hardening remains in progress, including narrower short-lived tokens, Vault storage and streamed Cloudflare logs. Those changes address the disclosed path, but customers still need independent controls because every centrally hosted script creates downstream reach beyond the provider’s own pages.
Facts at a glance
| Item | Detail | Source |
|---|---|---|
| Impact date | 14 September 2026 | Brevo |
| Broad impact window | 15:01–20:30 UTC | Brevo |
| Root cause | Compromised full-permission Cloudflare API key | Brevo |
| Independent reach estimate | More than 100,000 sites | Sansec; not confirmed by Brevo |
Why it matters
Brevo ClickFix Attack Reached Embedded Scripts is best understood through its disclosed mechanism and boundaries. The primary record establishes what changed; independent reporting confirms the event and helps separate a measurable consequence from a marketing claim.
For related context, see smart-home agents and our reporting on model misalignment incidents.
FAQ
What was the Brevo ClickFix attack?
An attacker used a compromised Cloudflare key to alter Brevo pages and embedded scripts at the CDN edge.
Was Brevo customer-account data affected?
Brevo says its application, API, email delivery and stored customer-account data were not affected by this incident.
What should WordPress administrators check?
Brevo advises administrators who visited affected sites while logged in to review plugins installed or activated that day and change credentials if compromise is found.
Sources
- Brevo incident post-mortem (2026-09-17; primary)
- Sansec (2026-09-16; independent)
- BleepingComputer (2026-09-17; independent)
- Cybernews (2026-09-18; independent)
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



