More than 100,000 websites may have been impacted by a cybersecurity incident involving Brevo, a French email marketing platform headquartered in Paris. Brevo provides tools for sending marketing emails to over 600,000 organizations, including well-known brands like Louis Vuitton, eBay, and Carrefour. The attack occurred when hackers gained access to a Cloudflare API key with wide-ranging permissions, which was embedded directly into Brevo's code. Using this key, the attackers created a malicious "Cloudflare Worker," a type of program that can alter content as it is distributed across the internet. This allowed them to inject and run their own code for about five and a half hours on September 14.
The attack used a technique known as ClickFix, which involved a deceptive verification screen that tricked users into copying and running a command on their computers, potentially installing malware. The malicious code specifically targeted WordPress administrators who were logged into their sites. Once detected, the script attempted to secretly install a harmful plugin called "Web Media Optimizer." This plugin could hide itself, replicate across the site, and create an administrator session without needing the user's password. This backdoor could have allowed attackers to maintain access to the site long after the initial attack.
The estimate of 100,000 affected websites comes from Sansec, a cybersecurity research firm, which calculated the number of sites that use Brevo's services. However, not all of these websites were infected, and not all visitors executed the malware. Brevo has stated that its main application, its API, and the data of its clients were not compromised in this incident.
This is the second security issue Brevo has faced in five days. On September 10, the company discovered a flaw in its SSO SAML authentication system, which allowed access to 138 client accounts. According to Brevo, six of these accounts were used to send real phishing emails, and the contact information from 43 accounts was exported. Notable clients like Trezor, a manufacturer of cryptocurrency wallets, experienced fake security alerts sent from their official systems.
The two incidents are described by Brevo as separate events. This new attack adds to a series of high-profile cyber incidents in France this summer, including the theft of data from nearly 700,000 taxpayers, a school system shutdown, a data leak involving 48 million property owners, and the exposure of 2 million customers' data. Other notable incidents include a breach of 24 million subscribers by Free, the theft of 450,000 IBANs by a student insurance company, a cyberattack on a cancer patient support platform, and the blackmail of hundreds of identity files from Revolut.
Brevo says it has blocked the hackers' access, revoked the compromised key, and strengthened its security infrastructure. The malicious domains involved no longer functioned as of September 15. The incident underscores the risks of supply chain attacks, where a vulnerability in a single service provider can affect many clients without directly targeting them. Brevo is advising website administrators who use its tools to review their extensions and API keys for any signs of compromise.
French Email Marketing Platform Brevo Suffers Major Cybersecurity Incident Affecting Thousands of Websites
AI-rewritten from original reportingHow it works
brevocyberattacksupplychainwordpresscloudflaremalware



