Brevo Supply-Chain Attack Hits Over 100,000 Websites
Brevo, a French cloud-based marketing platform formerly known as Sendinblue, was hit by a supply-chain attack on September 14, 2026, that injected malware into over 100,000 websites, according to security researchers. The attack exploited a compromised Cloudflare API key to deploy malicious code through Brevo's trusted infrastructure, turning it into a distribution channel for malware. The breach began when attackers used a long-lived Cloudflare API key with full account permissions, which had been hardcoded in Brevo's application source code. This key allowed them to create a malicious Cloudflare Worker that modified content at the CDN edge without triggering alerts. As a result, Brevo's own websites, including brevo.com and sendinblue.com, and three JavaScript files embedded on customer sites were affected. During the exposure window from approximately 1605 to 2013 UTC on September 14, the malware displayed a fake Cloudflare verification page to visitors, using the ClickFix technique to trick them into running a malicious command on their Windows computers.