Brevo's Sept 10 disclosure ('6 accounts hijacked') significantly understated the incident's true scope
Assessment
Brevo's September 10 public disclosure described the incident as six customer accounts being hijacked via an SSO-related weakness. Sansec's September 16 research opens by stating "the recent Brevo security incident is much larger than reported," and documents a September 14 compromise that served malware to visitors of Brevo's own site and more than 100,000 customer sites. Brevo has not stated whether the September 10 disclosure was an intentionally scoped-down initial report of a related, larger compromise, or a genuinely separate, smaller incident that happened to precede a second, unrelated one by four days. A reader could reasonably take the two events as either the same incident undercounted, or two coincidentally timed but distinct incidents — the public record does not resolve this.
Where this claim appeared
Sansec · 2026-09-16
https://sansec.io/research/brevo-supply-chain-attackWhat “Assessed, Not Confirmed” means
A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.
4 of 5 · rating scale
Assessed in
Brevo Supply-Chain Attack: Stolen Cloudflare API Key Used to Inject ClickFix Malware Across 100,000+ SitesThink this assessment is wrong? Report an error.