Mastodon

Brevo Supply-Chain Attack: 100K+ Websites Infected

Digital illustration depicting the Brevo supply-chain attack injecting malicious script into customer websites.
Spread the love

One Compromised Marketing Tool, 100,000+ Websites Infected — The Brevo Supply-Chain Attack Explained

If you’ve ever embedded a chat widget or email form on your website, this breach should make you pause.

Customer-engagement platform Brevo just disclosed a supply-chain attack that turned its own trusted infrastructure into a malware delivery system across more than 100,000 customer websites.

Here’s how it unfolded:

  • → September 10: An attacker exploited a flaw in how Brevo handled SAML single sign-on, gaining access to 138 customer accounts. Phishing emails went out from 6 of them; contact lists were exported from 43
  • → Brevo contained that initial breach — but the attacker had already stolen something more dangerous: a long-lived Cloudflare API key
  • → September 14: The same attacker returned and used that stolen key to deploy a malicious Cloudflare Worker, injecting harmful JavaScript directly into Brevo-owned domains and the widget code thousands of customers embed on their own sites
  • → Some visitors landed on a fake “Cloudflare verification” page instructing them to copy and run a command on their own computer — a social-engineering technique known as ClickFix
  • → On WordPress sites using Brevo widgets, the script went further — attempting to silently install a plugin whenever a logged-in site administrator visited the compromised page

The scale here is the real story. Brevo didn’t need to be breached 100,000 times — it needed to be breached once. Every business trusting that one widget inherited the compromise automatically, with zero action of their own. That’s the structural risk of modern websites: they’re rarely built from scratch anymore, they’re assembled from dozens of third-party scripts, plugins, and embedded services — and each one is a door that isn’t yours to lock.

The second failure compounds the first: a long-lived API key is exactly the kind of credential that should expire, rotate, or get scoped down automatically. Instead, it survived past the point where the original breach was supposedly contained, letting the same attacker walk right back in four days later.

If your site uses any embedded third-party widget — chat, forms, analytics, email — this is worth an honest check: do you know what that script can inject into your pages, and would you even notice if it changed?

#Cybersecurity #SupplyChainAttack #WebSecurity #DataBreach #InfoSec #TechNews

Sandeep Raiza

Sandeep RaizaContent Writer, Website Designer, SEO Strategist, and WordPress Expert AI specialist delivering impactful digital solutions that drive business growth.Combining creative storytelling with technical expertise.

Spread the love

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top