Brevo hit by network compromise
Incident
Summary
Hide ▲
Show ▼
Brevo confirmed a Cloudflare API key compromise that let attackers inject ClickFix scripts into its web properties, exposing customer-facing pages to malicious content injection. The compromise affected Brevo-hosted pages and customer-embedded JavaScript for roughly five and a half hours on September 14. Brevo said app.brevo.com, its email delivery infrastructure, and customer account data were not affected.
Related Happenings
Brevo-abused Trezor security-alert phishing campaign
Campaign
H score45
First: 11.09.2026 10:55
Last: 11.09.2026 10:55
Sources 1
About this happening:
A Brevo-abused phishing campaign targeted Trezor newsletter subscribers with fake security-alert emails, reaching 347,000 email addresses and driving 2,500 click...
Brevo-abused Trezor security-alert phishing campaign
CampaignAbout this happening: A Brevo-abused phishing campaign targeted Trezor newsletter subscribers with fake security-alert emails, reaching 347,000 email addresses and driving 2,500 click...
ShinyHunters-linked Salesforce intrusion campaign
Campaign
H score45
First: 14.07.2026 09:19
Last: 14.07.2026 09:19
Sources 1
About this happening:
A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
ShinyHunters-linked Salesforce intrusion campaign
CampaignAbout this happening: A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
Ghost CMS CVE-2026-26980 ClickFix campaign
Campaign
H score42
First: 24.05.2026 17:12
Last: 24.05.2026 17:12
Sources 1
About this happening:
A large-scale campaign is exploiting CVE-2026-26980 in Ghost CMS to plant malicious JavaScript and drive ClickFix lure pages, putting exposed sites and their visit...
Ghost CMS CVE-2026-26980 ClickFix campaign
CampaignAbout this happening: A large-scale campaign is exploiting CVE-2026-26980 in Ghost CMS to plant malicious JavaScript and drive ClickFix lure pages, putting exposed sites and their visit...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor Meta
H score82
First: 05.03.2026 08:51
Last: 05.03.2026 08:51
Sources 1
About this happening:
Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Latest development: 17.05.2026 17:43
eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.
Timeline
-
17.09.2026 20:11 2 articles · 2h ago
Brevo hit by network compromise
Initial DisclosureAttackers used a stolen Cloudflare API key to create a malicious Worker that rewrote Brevo content at the CDN edge on September 14. The injection window lasted from 16:07 to 20:30 UTC before the Worker was removed.
Show sources
- Brevo supply-chain attack injected ClickFix scripts on customer sites — www.bleepingcomputer.com — 17.09.2026 20:11
- Brevo supply-chain attack injected ClickFix scripts on customer sites — www.bleepingcomputer.com — 17.09.2026 20:11