Over 100,000 websites showed users ClickFix scams for hours after Brevo compromise
The company acknowledged the compromise and is hardening its infrastructure.

Image by Cybernews.
- Brevo was compromised and served malicious scripts through tools embedded on customer websites.
- Visitors saw fake CAPTCHA prompts that tried to make them run malware on their computers.
- Logged-in WordPress administrators were targeted with a malicious plugin that could create a lasting backdoor.
- Brevo says a compromised Cloudflare API key let attackers alter content at its delivery network edge.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Brevo, a popular marketing platform used by over 100,000 websites, was compromised and turned into a launchpad for a massive supply chain attack, infecting websites with malware and ClickFix overlays.
For a 4-hour window on September 14th, websites using Brevo served ClickFix scams to their visitors. WordPress admins were additionally targeted with malware that could leave a persistent backdoor on the websites.
Brevo offers popular tools – public scans find 117,000 web pages referencing Brevo infrastructure, like brevo.com, sibforms.com, or sibautomation.com. The company lists eBay, Louis Vuitton, Michelin, and Amnesty International among its clients.
According to the Sansec report, attackers injected a malicious script that ran directly on brevo.com and on thousands of customers’ sites. The malicious script was included in 2 JavaScript assets that merchants embed on their own websites.
The attack consisted of 2 parts.
The script loaded a ClickFix overlay, attempting to trick visitors into solving a fake CAPTCHA puzzle and copy pasting malicious code into the terminal.
However, if the site visitor was logged in to WordPress as an administrator, the malicious script quietly attempted to install a plugin, likely granting attackers a permanent backdoor into the website.
“Brevo is no longer serving malicious code. However, your WordPress site may have been backdoored, and your customers may have fallen for the Clickfix scam,” Sansec warns in the report.
In this incident, Sansec found evidence that the attackers gained write access to Brevo’s DNS records. Weeks before the attack, they created a certificate for cdn.sendibt1.com, a subdomain of Brevo’s owned domain. Later, they created more subdomains and pointed them to the hosted malware.
Just days prior to this incident, on September 10th, Brevo disclosed a security issue, stating that an attacker exploited a flaw in how Brevo handles SAML SSO to access 138 Brevo accounts. Attackers abused 6 accounts to send phishing emails, and exported contacts from 43 accounts.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
“We closed the route the attacker used and signed out every user on the platform. There has been no further attacker activity since,” the company said previously in the incident report.
Later, the company confirmed a new incident, saying that an attacker used a compromised Brevo Cloudflare API key to deploy a Cloudflare Worker on its account.
“For about 5 and a half hours, the Worker injected a malicious script into pages of brevo.com and sibforms.com and into 3 JavaScript files that customers embed on their own websites,” the new security incident report reads.
“No Brevo systems were modified at their source – the content was altered in transit at our CDN edge.”
The company acknowledged that users were selectively seeing a full-screen Cloudflare-branded page, sometimes appearing right after a genuine Cloudflare checkbox. It asked the visitor to press Win+R, then Ctrl+V, then Enter. Following these steps delivered malware.
“If you or a visitor ran the pasted command, treat that computer as compromised: disconnect it, run a full antivirus scan, and change passwords used on it, starting with your Brevo password,” the company warns.
Impacted WordPress site administrators are urged to check for any plugins installed or activated on September 14th – remove them, change administrator passwords, and review API keys as a precaution.