Incident
Published 2026-09-14
Verified 2026-09-19

Brevo: stolen Cloudflare API key → edge Worker ClickFix on customer embeds (~5.5h)

Brevo status write-up (and BleepingComputer 17 September 2026) confirms that on 14 September 2026 an attacker used a compromised long-lived Cloudflare API key (hardcoded in Brevo application source; first misuse indicated late August) to deploy a Cloudflare Worker that rewrote responses at the CDN edge for about five and a half hours (approx. 16:07–20:30 UTC). Affected: brevo.com, sendinblue.com, login/account/my/onboarding.brevo.com, sibforms.com, plus Brevo forms script, Conversations widget, and SDK loader that customers embed. The Worker stripped CSP and served a fake Cloudflare “verify you are human” ClickFix lure (Win+R / Ctrl+V / Enter) downloading malware on Windows; on WordPress sites with a logged-in admin, Sansec/Bleeping also report attempted silent install of a malicious “Web Media Optimizer” plugin backdoor. Not affected per Brevo: app.brevo.com, API, email delivery, and customer account data held in Brevo. Remediation: Worker/routes/hostnames removed, key revoked, hardcoded credential removed, Vault + Cloudflare audit alerting planned. Distinct from Brevo’s earlier 9–10 September SSO boundary incident (Trezor phishing wave). Primary: Brevo status write-up; wire: BleepingComputer; Sansec first flagged customer-site impact (up to ~100k sites cited).

Product
Brevo (Sendinblue) marketing platform — Cloudflare CDN / embedded forms, Conversations widget, SDK loader
Versions
n/a (CDN-edge Worker rewrite; origin files unmodified). Customer WordPress sites embedding affected widgets during the window were at risk.
Exploited in Australia?
unknown
Patch to
If you embed Brevo forms/Conversations/SDK: confirm scripts are clean; WordPress admins who visited affected pages during the window should audit plugins (esp. unexpected “Web Media Optimizer” / must-use copies), rotate admin sessions, and scan for backdoors. Prefer integrity checks on third-party embeds; treat ClickFix clipboard lures as malware.

Primary: Brevo status — Cloudflare Worker ClickFix write-up (14 Sep 2026 incident) · Vendor: Brevo (status write-up) · BleepingComputer — Brevo supply-chain ClickFix (17 Sep 2026)

breaches cloud