← Back to Tech & Science

Hackers Exploit Stolen Cloudflare Key to Inject Malware into Brevo Customer Sites

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

PARIS — Cyberattackers compromised the email marketing platform Brevo on Monday, using a stolen Cloudflare API key to inject malicious scripts into the company's infrastructure and the websites of its global customer base. The intrusion, detected late Monday afternoon, allowed threat actors to distribute malware through deceptive "ClickFix" lures and install persistent backdoors across numerous domains.

The attack began when unauthorized actors obtained a valid Cloudflare API credential associated with Brevo's network configuration. Using this access, they modified DNS settings and injected malicious JavaScript code into files hosted on brevo.com and sendinblue.com, as well as the external websites of thousands of Brevo clients. The compromised scripts were designed to redirect users to fraudulent pages or execute drive-by downloads that install malware on visitor devices.

Security researchers identified the presence of "ClickFix" lures, a tactic in which attackers display fake error messages claiming a user's browser is infected. These prompts urge visitors to click a link to "fix" the issue, which instead triggers the download of malicious software. Beyond the immediate lure, the injected code established persistent backdoors, granting attackers long-term access to modify website content or further compromise visitor systems.

Brevo confirmed the incident on Monday evening, stating that it had identified the unauthorized API key usage and immediately revoked the compromised credentials. The company initiated a rapid response to purge the malicious scripts from its own domains and is working with affected customers to clean their sites. Brevo reported that no customer data was accessed during the intrusion, as the attack focused specifically on the injection of code into public-facing web pages.

The breach highlights the critical risk posed by compromised API keys in cloud infrastructure management. By hijacking a single credential with elevated privileges, attackers were able to bypass standard security controls and manipulate traffic for multiple domains simultaneously. The use of Cloudflare's platform as an entry point suggests the attackers targeted the configuration layer rather than attempting to break into Brevo's internal servers directly.

While Brevo has secured its own environment, the full scope of the impact on customer websites remains unclear. Many small businesses and organizations relying on Brevo for email campaigns and landing pages may not yet be aware that their sites have been altered. Security experts warn that even after the malicious scripts are removed from the source, cached versions of the infected pages could continue to serve malware to users for hours or days.

Investigations are ongoing to determine how the API key was initially stolen and whether the attackers have moved laterally within other systems. Authorities have not yet identified the group responsible for the intrusion, and it remains unknown if the malware distributed through this campaign is linked to a specific criminal organization or state-sponsored actor. Brevo has urged all customers to audit their website files and monitor for unusual traffic patterns as the situation develops.

Discussion

0 / 2000