Canadian Cyber Security Journal
SOCIAL:
Filed under: Trends

A Compromised API Key Turned Brevo Into a Launchpad for a ClickFix Attack on 100,000 Websites

What Happened

Customer-engagement platform Brevo, first breached on September 10 through a flaw in its SAML single sign-on handling, suffered a second intrusion on September 14 when attackers used a compromised, long-lived Cloudflare API key to deploy a malicious worker script. The worker injected code into brevo.com, sibforms.com, and three JavaScript files Brevo customers embed directly into their own websites, showing selected visitors a fake “verify you are human” page instructing them to paste and run a command on their computer, a technique known as ClickFix. On sites running WordPress with a Brevo widget, the script attempted to install a malicious plugin if the visitor was logged in as an administrator. Security firm Sansec estimates the malware served for roughly four hours and likely reached more than 100,000 websites before Brevo removed the worker and revoked the compromised credentials. Read the disclosure from SecurityWeek.

Why This Matters for Canadian Organizations

Brevo counts small and mid-sized Canadian businesses among its customers for email marketing and contact-form widgets, meaning a compromise at the platform level reaches Canadian website visitors without those businesses doing anything wrong. Because the injected script ran through code the sites already trusted, the visible warning signs stayed minimal, leaving customers of Canadian retailers and service businesses exposed to credential theft or malware installation through a page resembling routine bot verification. Third-party marketing and widget platforms sit outside most organizations’ direct security controls, exactly the gap PIPEDA’s accountability principle asks businesses to account for when choosing vendors.

What to Do

Organizations embedding Brevo forms or widgets on their websites should review Brevo’s incident notices, confirm their embedded scripts match the vendor’s current, clean versions, and check WordPress installations for unauthorized plugins installed between September 14 and the takedown. Anyone who saw the fake verification prompt during this window and followed its instructions should scan the affected device for malware and change any passwords entered afterward. Security teams should treat embedded third-party widgets as an active attack surface and monitor for unexpected script changes rather than assuming a vendor’s code stays static.

Enjoy this article? Don’t forget to share.