← Back to feed
PhishingEmerging1 sourceSep 18, 2026 · 21:38via Security Affairs

Brevo Supply-Chain Attack Infected Over 100,000 Websites

Brief

A Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over 100,000 sites.

Brevo, formerly known as Sendinblue, is a French cloud-based marketing and customer communication platform whose clients include eBay, Louis Vuitton and Michelin.

The company was first compromised on September 10, when attackers exploited a vulnerability in its SAML SSO system and gained access to 138 accounts, including one belonging to cryptocurrency hardware wallet maker Trezor. Six accounts were used to send phishing emails, while contact data was exported from 43 accounts.

Brevo blocked the unauthorized access, but attackers returned four days later using a compromised, long-lived Cloudflare API key.

Read more on Security Affairs→