
A recent cyberattack targeting Brevo, a company specializing in marketing and communication solutions, has raised alarms among cybersecurity experts as it may have compromised more than 100,000 websites.
The attackers used a stolen Cloudflare API key to create a harmful Cloudflare Worker, embedding this malicious code into JavaScript files provided by Brevo.
How Was the Attack Executed?
The breach began when hackers managed to gain access to various customer accounts within Brevo. They then utilized the stolen Cloudflare API key to manipulate files used by Brevo’s clients. Given Brevo’s extensive reach in the digital marketing space, the implications of this attack could ripple across many additional websites.
Researchers estimate that the attack impacted over 100,000 sites and remained active for several hours before it was eventually shut down.

Phishing Scheme: A Counterfeit Cloudflare Verification Page
The hackers exploited the malicious code to present a fake Cloudflare security verification page. Victims were prompted to copy a command and run it on their computers—part of the ClickFix scam tactic. This could lead to malware installation on their systems.
Certain WordPress sites have also suffered from this breach, particularly if an administrator was logged in, as attackers may attempt to deploy the harmful WordPress plugin.
Brevo Responds to the Threat
In response to the attack, Brevo reported that it managed to neutralize the threat posed by the malicious Cloudflare Worker shortly after the breach was identified. The company also blocked the compromised API key to prevent any further incidents. Importantly, Brevo confirmed that its primary platform, API, and email delivery services remained secure during this event.

Action Required for Website Owners
Those utilizing Brevo services should closely inspect their websites for any unauthorized changes or unknown plugins. Additionally, anyone who interacted with the instructions on the fraudulent Cloudflare verification page is urged to perform a malware scan on their systems.
This incident highlights the vulnerability of even trusted third-party services and underscores how hackers can exploit them to affect a vast number of websites simultaneously.
