The Brevo ClickFix supply-chain attack used a compromised full-permission Cloudflare API key to alter Brevo-delivered web content at the CDN edge. Brevo says the attacker deployed a malicious Cloudflare Worker that injected ClickFix content into Brevo pages and later into customer-embedded JavaScript. For customer websites, the key exposure window was 16:07 to 20:30 UTC on September 14, 2026.
What matters now: loading an affected Brevo asset during the incident window means a site was potentially exposed, but it does not prove that the site or a visitor was successfully compromised. WordPress administrators who were logged in while visiting an affected site should inspect plugins installed or activated that day. Anyone who actually followed the ClickFix instructions and ran the attacker-supplied Windows command should treat that endpoint as compromised and follow Brevo’s remediation guidance.
What Brevo says was compromised
Brevo says an attacker obtained a long-lived Cloudflare API key with full account permissions. The key had been stored in application source code. Using that credential, the attacker could create Cloudflare Workers, routes and DNS records on Brevo-controlled zones.
The attacker then deployed a Worker that modified responses at the Cloudflare edge. Brevo says its origin files and servers were not modified by the injection. That distinction matters because normal checks showing unchanged origin files would not by themselves rule out exposure during this incident.

When were customer websites exposed?
Brevo’s broader impact began at 15:01 UTC on September 14. At 16:07 UTC, the attacker updated the Worker to append a malicious loader to three customer-embedded JavaScript surfaces and routed it to sibforms.com. Brevo removed the malicious Worker and routes at 20:30 UTC.
For website operators investigating customer-site exposure, the relevant Brevo-confirmed embedded-script window is therefore 16:07–20:30 UTC on September 14. Brevo says independent verification at 20:42 UTC confirmed the affected pages and scripts were clean.
Which Brevo surfaces were affected?
Brevo says the incident affected content delivered through brevo.com and related Brevo pages, sibforms.com, its forms script, the Brevo Conversations widget and the Brevo SDK loader. Independent security researchers also preserved malicious versions of Brevo-hosted JavaScript during the incident.
Brevo says app.brevo.com, the Brevo API, email sending and customer account data held in Brevo were not affected by this ClickFix incident.
How to decide whether you need to act
If not, this specific customer-embed exposure path does not apply based on the reviewed evidence.
That is Brevo’s confirmed window for malicious injection into customer-embedded JavaScript.
If an administrator visited the affected site while logged in, inspect plugins installed or activated that day and remove anything unauthorized.
If a user actually ran the attacker-supplied command, Brevo says to treat that Windows computer as compromised.
Affected-script delivery, a displayed ClickFix prompt, successful command execution and persistent WordPress compromise are different states and should not be treated as equivalent.
What did visitors see?
Brevo says selected visitors were shown a fake Cloudflare verification page. The social-engineering flow instructed the visitor to run a command that had been placed on the clipboard. Brevo says following those steps downloaded malware onto a Windows computer.
The page was shown selectively, so Brevo says most visitors and repeat visits saw nothing. The absence of a visible prompt therefore does not prove whether a site loaded the affected JavaScript, while simply loading the script does not prove successful endpoint compromise.
What should someone do if they ran the ClickFix command?
Brevo says anyone who followed the instructions and ran the pasted command should treat that computer as compromised. Its guidance is to disconnect the device, run a full antivirus scan and change passwords that were used on the computer, starting with the Brevo password.
This article does not reproduce the malicious command or provide execution details because they are not necessary for identifying or responding to exposure.
What should WordPress administrators check?
Brevo says that on WordPress sites embedding its widget, the malicious script could attempt to silently install and activate a plugin when a visitor was already logged in as a WordPress administrator. Administrators who meet that exposure condition should inspect plugins installed or activated on September 14, remove anything unauthorized and change administrator passwords.
Secondary forensic reporting identified an attempted malicious plugin called Web Media Optimizer. That plugin detail comes from security analysis rather than Brevo’s primary post-mortem, so it should not be treated as proof that every exposed WordPress site received or installed it.
Does the reported 100,000-site reach mean 100,000 websites were hacked?
No. Independent researcher Sansec estimated that affected Brevo components were embedded on more than 100,000 websites. That figure describes potential supply-chain reach. It is not a confirmed count of websites with a successful backdoor installation, visitors who executed ClickFix, or infected Windows endpoints.
Are Brevo’s scripts safe now?
Brevo says it removed the malicious Worker and routes, revoked the compromised API key and credentials created with it, purged edge caches and verified the affected pages and scripts were serving clean content. It says the Conversations widget, SDK and forms are currently safe to use.
Central containment does not automatically clean a Windows endpoint or WordPress installation where attacker actions succeeded during the incident, so local verification remains important for readers who meet the exposure conditions above.
What Brevo changed after the attack
Brevo says it removed the hardcoded Cloudflare credential from source code, replaced broad long-lived access with narrowly scoped short-lived tokens, is moving Cloudflare credentials into HashiCorp Vault, and is adding monitoring for changes to Workers, routes, DNS and account access. It also says Cloudflare logs will be streamed to its security monitoring platform and third-party edge configurations will be reviewed.
What remains unknown
Brevo’s post-mortem does not establish how many visitors actually executed the ClickFix command, how many WordPress plugin-install attempts succeeded, or the final number of compromised endpoints. Attacker attribution also remains unresolved in the reviewed evidence. A separate Brevo account-security incident occurred on September 10, but the evidence reviewed for this article does not establish that the two incidents were part of the same intrusion chain.
Verification and limitations
The central compromise path, Cloudflare-key root cause, incident timeline, affected Brevo surfaces and official customer actions were checked against Brevo’s incident post-mortem. Independent Sansec research was used to corroborate poisoned asset delivery and the estimated supply-chain reach, while secondary security reporting was used for the detailed WordPress plugin analysis. Potential exposure must not be reported as confirmed compromise without evidence of successful attacker execution on the individual site or endpoint.
Bottom line: if a site loaded affected Brevo assets between 16:07 and 20:30 UTC on September 14, investigate the relevant exposure state. A logged-in WordPress administrator should inspect plugin activity, while anyone who actually executed the ClickFix command should treat that Windows endpoint as compromised. Do not interpret Brevo’s potential site reach as a confirmed infection count.