Skip to content
See the World Through ScienceA project of ALLATRA

Stolen API Key Let Attackers Push Fake Security Prompts Through Brevo to Customer Websites

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Photograph of a computer screen showing a counterfeit Windows Security Alert pop-up over a web browser, listing fake virus detections.
A fake security alert of the kind websites use to push visitors into running an attacker's instructions (illustrative)."virus" by Richard Corfield (M0RJC), via flickr, CC-BY-2.0 · CC-BY-2.0

Attackers stole a Cloudflare API key hardcoded in Brevo's source code and used it to inject ClickFix scripts into the company's own pages and into JavaScript components that customer websites embed, Brevo confirmed as reported by BleepingComputer.

ClickFix is a social-engineering technique in which a website shows visitors a fake browser or security warning, in this case a counterfeit Cloudflare verification page, and instructs them to run a command manually on Windows. The command delivers malware.

The stolen key had full account permissions and allowed the attackers to create a Cloudflare Worker, a piece of code that runs at the content-delivery edge and can rewrite web pages before they reach the browser. Brevo said the Worker "removed security headers such as Content-Security-Policy" so that "our origin servers and files remained unmodified and standard integrity checks did not detect the change." The exposure window ran from approximately 16:07 to 20:30 UTC on Sept. 14, roughly five hours.

Security firm Sansec, which first reported the incident, said the attack potentially reached up to 100,000 websites that embed Brevo's forms script, Conversations widget, or SDK loader: an estimate, not a confirmed count of compromised sites. The affected Brevo properties included brevo.com, sendinblue.com, and sibforms.com.

On WordPress sites where a logged-in administrator visited during the window, the injected script also attempted to install a malicious plugin that BleepingComputer identified on VirusTotal as a persistent backdoor and JavaScript loader. WordPress site operators who were logged in as administrator on Sept. 14 should audit plugins added that day. Brevo said its API, email delivery infrastructure, and customer account data were not affected.

The compromise is separate from a different Brevo incident disclosed Sept. 10, in which attackers hijacked customer accounts via a single sign-on flaw and launched phishing campaigns.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Stolen API Key Let Attackers Push Fake Security Prompts Through Brevo to Customer Websites

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.