Brevo did not lose its origin files. It lost the CDN edge — and the customers who embed its widgets rode along.
In a status-page post-mortem for the 14 September 2026 incident, Brevo said an attacker used a compromised Cloudflare API key that had been hardcoded in application source code with full account permissions. That key let the attacker create Workers, routes, and DNS records on Brevo’s zones without an alert. A malicious Cloudflare Worker then rewrote responses at the edge and stripped security headers such as Content-Security-Policy, so origin servers and files stayed unmodified and ordinary integrity checks missed the change.
Impact window (company): about five and a half hours on 14 September UTC (summary window 15:01–20:30; ClickFix on the listed URLs from 16:07 to 20:30 UTC). Affected surfaces: brevo.com, sendinblue.com, login/account/my/onboarding.brevo.com, sibforms.com and the Brevo forms script, the Brevo Conversations widget, and the Brevo SDK loader — the same scripts customers embed on their own sites. Not affected: app.brevo.com, the Brevo API, email sending, and customer account data held in Brevo.
What visitors saw: a full-screen Cloudflare-branded “verify you are human” page that told them to press Win+R, Ctrl+V, Enter — classic ClickFix. Running the pasted command downloaded malware onto Windows machines. The lure was selective, so many visitors saw nothing. On WordPress sites embedding a Brevo widget, if a visitor was logged in as a WordPress administrator, the script also tried to silently install and activate a plugin.
Brevo’s investigation says the key was first misused in late August 2026, with no injection of malicious content into customer-facing pages before 14 September. Remediation: Worker and routes removed, key and attacker-created credentials revoked, attacker hostnames deleted, edge caches purged, hardcoded credential removed in favor of narrowly scoped short-lived tokens, plus Vault, audit alerts, log streaming, and integrity scanning underway.
Independent research: Sansec (16 Sep) timed malware on Brevo domains roughly 16:05–20:13 UTC on the 14th, tied loaders to sendibt1.com CDN hostnames Brevo owns, and estimated the embed reach at over 100,000 customer sites. CyberMerge prints that as a researcher estimate. Brevo has not published a confirmed site tally — Undisclosed.
This is a separate track from Brevo’s 10 September SAML SSO write-up (customer-account access / phishing). Brevo has not publicly tied the two incidents together in the Cloudflare post-mortem.
POV: marketing SaaS with edge rewrite power is a supply-chain amplifier. Underwrite the company window, the hardcoded full-scope Cloudflare key, and the ClickFix + WordPress-admin plugin attempt; victim count: Undisclosed. If someone pasted the command, treat that endpoint as compromised; if a WP admin browsed an affected embed while logged in on the 14th, hunt plugins activated that day and rotate admin passwords.
