HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Supply‑Chain Attack on Brevo Compromises Cloudflare Integration, Infects Over 100,000 Customer Websites

Brevo’s SAML SSO breach led to theft of a long‑lived Cloudflare API key, which attackers used to deploy a malicious edge worker. The worker rewrote responses for thousands of sites that embed Brevo scripts, potentially exposing over 100 k websites to malware. This underscores the importance of continuous third‑party risk monitoring for audit readiness.

Verisq™ Intelligence · 📅 September 19, 2026 · 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

Supply‑Chain Attack on Brevo Compromises Cloudflare Integration, Infects Over 100,000 Customer Websites

What Happened — Attackers first exploited a vulnerability in Brevo’s SAML SSO to steal 138 accounts, then used a long‑lived Cloudflare API key to create a malicious Cloudflare Worker. The worker rewrote HTTP responses at the edge, stripping security headers and injecting malicious JavaScript into Brevo‑hosted assets, which were then served to visitors of more than 100 k websites that embed Brevo scripts.

Why It Matters for Trust & Control Assurance

  • Demonstrates how a single third‑party credential can turn a trusted service into a malware distribution platform, a scenario continuous control‑assurance programs are built to detect and evidence.
  • Highlights the need for ongoing vendor‑risk monitoring, immutable API‑key management, and real‑time alerting on privileged cloud‑service actions.
  • Provides a concrete example of why organizations must maintain auditable evidence of third‑party security controls to satisfy multiple framework requirements (e.g., NIST CSF, ISO 27001).

Who Is Affected – SaaS marketing platforms, their downstream customers (e‑commerce, media, luxury brands), and any website that loads Brevo’s tracking or email‑widget scripts.

Recommended Actions

  • Inventory all Cloudflare API keys and enforce short‑lived, scoped credentials; rotate any long‑lived keys immediately.
  • Implement continuous monitoring of third‑party cloud configurations (Workers, DNS records, routes) and integrate alerts into your security operations center.
  • Review and harden SAML SSO configurations; enforce MFA and anomaly detection on privileged account logins.

Technical Notes – The initial breach leveraged a SAML SSO vulnerability (details not disclosed). The subsequent supply‑chain stage used a compromised Cloudflare API token to create a Worker that stripped CSP headers and injected a malicious WordPress plugin and click‑jacking overlay. No public CVE was assigned at the time of reporting. Source: SecurityAffairs

📰 Original Source
https://securityaffairs.com/199355/hacking/brevo-supply-chain-attack-infected-over-100000-websites.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →