Brevo Hack Injects Fake Cloudflare “Verify” Prompts

F5 Labs · High sophistication
Last updated September 22, 2026

Attackers compromised Brevo’s Cloudflare setup using a long-lived API key found in source code, then altered website content at the CDN edge. Visitors were shown fake Cloudflare verification prompts to run Windows commands, and logged-in WordPress admins were targeted with a hidden backdoor plugin disguised as a legitimate optimizer.

Key findings

  • Attackers used a compromised, hardcoded Cloudflare API key to deploy a malicious Cloudflare Worker and modify content at the CDN edge.
  • Injected scripts showed fake Cloudflare verification prompts that attempted to trick visitors into executing malicious Windows commands.
  • Logged-in WordPress administrators were targeted for a silent install of a persistent backdoor plugin disguised as “Web Media Optimizer.”
  • The malicious plugin was designed to hide, persist (must-use directory), fetch additional payloads, and included a hardcoded key to bypass admin passwords.
  • Brevo revoked the key, removed the Worker, purged edge caches, and advised WordPress admins to inspect for unauthorized plugins and rotate credentials.

Who’s being targeted

  • Commonly targeted roles: Web Administrators, WordPress Administrators, IT Operations, Security Awareness / Helpdesk, Marketing Operations (teams that manage web tags and embedded assets).
  • Affected industries: SaaS / Marketing technology, Website operators / Digital marketing, Content management systems (WordPress site owners), E-commerce and online services (websites embedding affected assets).
  • Attack channels: website.
  • Impersonated: Cloudflare, WordPress plugin / site optimization tool.

Awareness takeaways

  • Treat any web ‘verification’ prompt that asks you to run commands as malicious; stop and report it.
  • Tightly control WordPress admin access and monitor for unauthorized plugin installs, especially “must-use” plugins.
  • Block and investigate unknown outbound connections from websites/CMS servers to unfamiliar domains used for ‘updates’ or scripts.
  • Reduce the blast radius of secrets: avoid hardcoding API keys and rotate long-lived keys quickly when exposure is suspected.

Red flags to watch for

  • A website asks you to run Windows commands to “verify” you are human
  • Unexpected verification prompt on a site you normally trust
  • Instructions that require copy/paste into PowerShell/Command Prompt
  • A new plugin appears without an approved change request
  • Plugin behavior that hides from the active plugin list
  • Outbound connections to unfamiliar domains for ‘updates’ or scripts
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine a site you trust suddenly shows a big Cloudflare box saying, “Verify to continue”… and then tells you to run a Windows command. That’s what hit Brevo: a hardcoded Cloudflare API key got stolen, attackers dropped a malicious Cloudflare Worker, and it injected fake Cloudflare prompts telling visitors to paste commands into PowerShell. If you were a logged‑in WordPress admin, it got worse: a hidden backdoor plugin called “Web Media Optimizer” could silently install, hide in the must‑use directory, phone home to glegchner.com and corralos.beer, and even bypass admin passwords with a hardcoded key. Your move: if any site ever tells you to copy a command into PowerShell or Command Prompt to ‘verify’ you’re human, stop right there and report it to security immediately.

Similar attacks

Fake SSO + MFA Push Used in Real Breaches

Fake SSO + MFA Push Used in Real Breaches

This weekly roundup includes two real social-engineering-driven incidents. Attackers used social engineering to access Apollo Global Management’s cloud platforms and steal sensitive personal data, and separately attempted a ShinyHunters phishing attack against ReliaQuest using a fake SSO login page…

August 28, 2026
Fake Claude & Perplexity Lures Push Malware

Fake Claude & Perplexity Lures Push Malware

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings…

August 21, 2026
Trusted Channels Hijacked for Phishing and Malware

Trusted Channels Hijacked for Phishing and Malware

The article describes multiple real-world social engineering operations this week, including phishing sent from a legitimate Trezor newsletter channel and malware pushed through a verified HBO Max Reddit ad account. It also highlights a large-scale network of fake online stores impersonating real…

September 18, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Poisoned AI Agent Files Turn Dev Tools Into Spies

Poisoned AI Agent Files Turn Dev Tools Into Spies

Researchers found real GitHub repositories containing poisoned AI-agent instruction/config files (like CLAUDE.md and .cursorrules) that silently tell coding assistants to steal prompts, environment variables, and credentials. The malicious instructions can trigger hidden commands (for example, curl…

August 4, 2026
Hotel Wi‑Fi DNS Scam Steals Microsoft 365 Logins

Hotel Wi‑Fi DNS Scam Steals Microsoft 365 Logins

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in pages. Victims are then tricked into completing a device-code login that grants attackers a legitimate session token, often bypassing MFA. This…

July 28, 2026