Brevo Supply Chain Attack Infects 100,000 Sites

← Back to articles

Brevo Supply Chain Attack Infects 100,000 Sites

Hackers have compromised a Brevo API key and used it to launch a Cloudflare worker that injected malicious scripts into more than 100,000 websites. The attack was confirmed by security researchers and traced back to a supply‑chain breach of the Brevo email‑delivery platform.

The affected sites span a wide range of industries, from small blogs to large e‑commerce platforms, because many developers integrate Brevo’s API for transactional emails. The malicious Cloudflare worker intercepted web traffic and added hidden JavaScript code that could harvest credentials, deliver ransomware, or redirect visitors to phishing pages. The injection was invisible to most site owners, as it occurred at the edge of the network, not on the servers themselves.

The threat works by exploiting the trust placed in a legitimate third‑party service. Once the API key was stolen, the attackers could instruct Cloudflare to run custom code on any domain that used the compromised Brevo account. This supply‑chain method allows a single breach to affect thousands of unrelated sites with minimal effort.

Website owners should immediately rotate any Brevo API keys, revoke unused credentials, and audit access logs for suspicious activity. Checking Cloudflare worker configurations for unknown scripts is also essential. Users can scan their sites with free online tools available at ComputerScams.com to detect hidden malicious code. Keeping software, plugins, and dependencies up to date reduces the risk of similar attacks in the future.

For individuals, the safest approach is to treat any unexpected pop‑ups, redirects, or requests for login information as potential phishing attempts. Use a reputable password manager and enable two‑factor authentication wherever possible. Regularly monitor financial statements and credit reports for signs of identity theft, as compromised sites may be used to harvest personal data.

A practical step you can take right now is to run a quick security scan of your favorite websites using the free scanner on ComputerScams.com. Detecting hidden scripts early can stop an infection before it spreads.

Source: Read the original report

Scroll to Top