Executive Summary
In September 2026, attackers compromised Brevo's Cloudflare API key and deployed malicious Workers that injected ClickFix scripts into the company's websites and customer-embedded JavaScript components for approximately 5.5 hours. The attack affected brevo.com, sendinblue.com, and customer sites using Brevo forms, conversation widgets, and SDK loaders, potentially impacting up to 100,000 websites. Victims were presented with fake Cloudflare verification pages prompting them to execute malicious commands, while WordPress administrators faced additional risks through backdoor plugin installations that created persistent access points with hardcoded authentication bypasses.
This incident highlights the growing sophistication of supply-chain attacks targeting content delivery networks and the increasing prevalence of ClickFix social engineering tactics that exploit user trust in legitimate cloud services to distribute malware at scale.
Why This Matters Now
Supply-chain attacks targeting CDN infrastructure are escalating as attackers exploit the widespread trust in cloud services and the difficulty of detecting edge-based content manipulation, making comprehensive egress controls and traffic inspection critical for preventing similar compromises.
Attack Path Analysis
Attackers compromised a hardcoded Cloudflare API key from Brevo's source code to create malicious Cloudflare Workers that injected ClickFix scripts into customer websites. The Workers modified content at CDN edge, bypassing security headers and integrity checks. Victims were presented with fake verification pages prompting malicious command execution. On WordPress sites, the attack attempted to install backdoor plugins for persistent access. The campaign distributed infostealer malware and established command channels through attacker-controlled domains.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers obtained a hardcoded Cloudflare API key with full account permissions from Brevo's application source code, potentially as early as late August 2026
MITRE ATT&CK® Techniques
Supply Chain Compromise: Compromise Software Supply Chain
Valid Accounts: Cloud Accounts
Unsecured Credentials: Credentials In Files
Phishing: Spearphishing Link
Server Software Component: Web Shell
Masquerading: Match Legitimate Name or Location
Command and Scripting Interpreter: JavaScript
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software engineering techniques for secure development
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – ICT third-party risk
Control ID: Article 11
CISA ZTMM 2.0 – Identity and Access Management
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity risk-management measures
Control ID: Article 21
GDPR – Processor obligations
Control ID: Article 28
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Marketing/Advertising/Sales
Brevo supply-chain attack directly compromised marketing widgets and forms, enabling ClickFix malware distribution through customer relationship management platforms affecting up to 100,000 websites.
E-Learning
WordPress-based educational platforms face heightened risk from malicious plugin injection targeting administrator accounts, potentially compromising learning management systems and student data through backdoor access.
Computer Software/Engineering
Hardcoded API credentials in source code enabled Cloudflare Worker manipulation, highlighting critical secure development practices gaps and supply-chain vulnerabilities in software engineering workflows.
Financial Services
Cryptocurrency wallet phishing attacks via compromised Brevo accounts affected 347,000 users, demonstrating significant financial sector exposure to customer communication platform supply-chain compromises and regulatory compliance risks.
Sources
- Brevo supply-chain attack injected ClickFix scripts on customer siteshttps://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/Verified
- Brevo Incident Post-mortem - Cloudflare Worker Compromisehttps://status.brevo.com/incidents/01M2QBC4EZ24ZACW6SWQYVW8N3/write-upVerified
- Sansec Research - Brevo Supply Chain Attackhttp://sansec.io/research/brevo-supply-chain-attackVerified
- Trezor 347,000 users targeted in phishing attacks after Brevo breachhttps://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius and lateral spread of this supply chain attack by constraining cross-zone access and implementing segmented policies for API-driven resource creation. The segmentation controls could limit how compromised credentials enable widespread infrastructure modifications across multiple domains.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Identity-aware access controls may have limited the scope of API key permissions and constrained which cloud resources could be modified through automated policy enforcement across the fabric.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation policies could constrain the attacker's ability to create workers across multiple zones and limit cross-domain resource modification through identity-scoped access controls.
Control: East-West Traffic Security
Mitigation: East-west traffic controls may have constrained the lateral spread of malicious workers across domain boundaries and reduced the reachability between different organizational zones and customer environments.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility controls could have detected and constrained suspicious outbound connections to attacker-controlled domains and limited the establishment of persistent command channels through policy enforcement.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies may have limited the attacker's ability to exfiltrate stolen credentials and constrained outbound data flows to unauthorized external destinations through enforced security boundaries.
While CNSF segmentation would likely reduce the overall blast radius, residual impact may still affect a constrained subset of customer sites that were reached before security controls fully contained lateral spread.
Impact at a Glance
Affected Business Functions
- Email Marketing Campaigns
- Customer Relationship Management
- Web Forms and Lead Generation
- Customer Communication Widgets
Estimated downtime: 1 days
Estimated loss: N/A
Up to 100,000 websites were potentially affected by malicious JavaScript injection. WordPress administrator credentials were compromised on sites where admins visited affected pages while logged in. The attack deployed ClickFix social engineering tactics to distribute malware to end users and installed persistent backdoor plugins on WordPress sites.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement between cloud zones and limit API key scope through least privilege access controls
- • Deploy Egress Security & Policy Enforcement to block unauthorized outbound connections to attacker-controlled domains and prevent data exfiltration
- • Enable Multicloud Visibility & Control to detect anomalous Worker creation, DNS record modifications, and suspicious automation across CDN infrastructure
- • Utilize Cloud Native Security Fabric (CNSF) for real-time inline inspection of edge modifications and autonomous detection of supply chain compromise indicators
- • Establish Threat Detection & Anomaly Response capabilities to baseline normal CDN behavior and alert on unauthorized content modifications or security header removal



