Brevo Hack Served ClickFix Malware to 100K Sites

Security Week Feed · Medium sophistication
Last updated September 18, 2026

Brevo suffered a supply-chain compromise where attackers injected malicious JavaScript into Brevo-hosted pages and customer-embedded website scripts, affecting over 100,000 sites. Visitors were shown a fake “Cloudflare, verify you are human” prompt designed to trick them into running a command on their computer (a ClickFix-style scam). On WordPress sites, the injected code also tried to install a plugin when an admin was logged in.

Key findings

  • Brevo was first breached on September 10 via an issue in how it handled SAML SSO, leading to access to 138 accounts.
  • Attackers used six compromised accounts to send phishing emails and exported contacts from 43 accounts.
  • On September 14, attackers reused a compromised long-lived Cloudflare API key to deploy a worker that injected malicious scripts into Brevo domains and customer-embedded JavaScript files.
  • Injected code showed some visitors a fake “Cloudflare, verify you are human” page that instructed them to paste and run a command (ClickFix).
  • On WordPress sites embedding a Brevo widget, the script attempted to deploy and run a plugin if the visitor was logged in as an administrator.
  • Sansec estimates the malicious content was served for roughly four hours and likely impacted more than 100,000 websites.

Who’s being targeted

  • Commonly targeted roles: All employees (end users/browsers), Web Administrators, IT/Security Operations, Marketing/Website owners using third-party widgets.
  • Affected industries: Information technology / SaaS, E-commerce websites, Marketing and customer engagement websites, Cryptocurrency services, Any organization operating a WordPress website.
  • Attack channels: website.
  • Impersonated: Cloudflare verification page, Website plugin/update mechanism (implied by plugin installation attempt).

Awareness takeaways

  • Train users: never run copy/pasted commands from a web page pop-up, even if it looks like a well-known brand (e.g., Cloudflare).
  • For web/IT teams: regularly review WordPress sites for unauthorized plugins and unexpected changes to embedded scripts/widgets from third parties.
  • Assume third-party platforms can be abused: add monitoring/alerting for changes to critical API keys and edge-worker deployments.

Red flags to watch for

  • A security check asking you to run a command on your computer is not normal.
  • Unexpected verification page appears while browsing a legitimate site.
  • Instructions involve copying/pasting commands rather than using standard CAPTCHA/checkbox challenges.
  • Unexpected new plugin installed or plugin list changes without approval.
  • Admin activity or prompts occurring when simply viewing pages with embedded widgets.
  • Unrecognized code changes in embedded JavaScript files/widgets.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re browsing a totally normal site and suddenly see: “Cloudflare, verify you are human.” In the Brevo hack, over a hundred thousand sites showed this fake Cloudflare page, telling people to copy and run a command on their computer. That’s a ClickFix malware scam. Real Cloudflare checks are just things like a checkbox or a quick challenge in the browser. They never ask you to paste commands, and they don’t silently install WordPress plugins in the background. If any website ever tells you to verify you’re human by running a command, stop, close the tab, and report it to IT immediately.

Similar attacks

Brevo Breach Spread Malware via ‘Prove You’re Human’

Brevo Breach Spread Malware via ‘Prove You’re Human’

Attackers breached Brevo and used a stolen Cloudflare API key to inject malicious code into Brevo-hosted scripts that thousands of customer websites load. Visitors saw a fake “prove you’re human” prompt meant to trick them into running a command, and logged-in WordPress admins risked having a…

September 18, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
Trusted Channels Hijacked for Phishing and Malware

Trusted Channels Hijacked for Phishing and Malware

The article describes multiple real-world social engineering operations this week, including phishing sent from a legitimate Trezor newsletter channel and malware pushed through a verified HBO Max Reddit ad account. It also highlights a large-scale network of fake online stores impersonating real…

September 18, 2026
Brevo Breach Fuels Crypto Newsletter Phishing

Brevo Breach Fuels Crypto Newsletter Phishing

Attackers abused access to Brevo (an email marketing platform) to send highly convincing phishing emails from legitimate cryptocurrency company domains to newsletter subscribers. The lures claimed urgent security issues (hardware vulnerability or data breach) and pushed victims to click links,…

September 11, 2026
HBO Max Reddit Ads Hijacked to Spread ClickFix Malware

HBO Max Reddit Ads Hijacked to Spread ClickFix Malware

Attackers compromised HBO Max’s verified Reddit advertising account and used it to run 108 malicious ads in about 48 hours. The ads sent people to attacker-controlled websites that used “ClickFix” instructions to trick users into running commands that installed malware on Windows and macOS.

September 16, 2026
Fake SSO + MFA Push Used in Real Breaches

Fake SSO + MFA Push Used in Real Breaches

This weekly roundup includes two real social-engineering-driven incidents. Attackers used social engineering to access Apollo Global Management’s cloud platforms and steal sensitive personal data, and separately attempted a ShinyHunters phishing attack against ReliaQuest using a fake SSO login page…

August 28, 2026