← Brevo

2026 Brevo — stolen Cloudflare API key; ClickFix Worker on sites + customer embeds (~5.5h)

2026 Unknown records affected Share on X

Data compromised

No Brevo customer account database exfiltration reported. Impact was malware delivery: fake Cloudflare “verify you are human” ClickFix pages on brevo.com/sibforms.com and injected loaders into customer-embedded forms/Conversations/SDK scripts (Sansec: up to ~100k sites in exposure window). app.brevo.com, API, email delivery, and customer account data stated unaffected

Technical writeup

Verified Brevo status post-mortem — September 17, 2026. On Sep 14 attackers used a compromised full-permission Cloudflare API key (hardcoded in application source; may have been obtainable since late August) to create a Worker that rewrote responses at the CDN edge and stripped CSP. Impact window ~15:01–20:30 UTC (~5h29); ClickFix active on listed URLs from ~16:07–20:30. Affected brevo.com, sendinblue.com, login/onboarding hosts, sibforms.com, and three customer-embed JS files. Worker removed, key revoked, hardcoded credential removed, attacker hostnames deleted, caches purged. Distinct from Sep 10 Brevo SAML SSO incident. Sansec estimated ~100k websites using affected components during the window. recordsAffected 0 (no published PII census); companyConfirmed true.

Root cause

Long-lived Cloudflare API key hardcoded in source; attacker deployed edge Worker rewriting CDN responses

References