The Sept 10 SSO account-hijacking incident and the Sept 14 Cloudflare/ClickFix incident are connected
Assessment
Both incidents hit Brevo within a four-day window and both involve unauthorized access to Brevo-controlled systems (customer SSO accounts in the first case, a Cloudflare API key in the second). BleepingComputer directly asked Brevo whether the two incidents were connected, and Brevo did not respond to that question. No source reviewed for this paper confirms or rules out a shared root cause, and treating them as either "definitely the same campaign" or "definitely unrelated" would both go beyond what has been publicly established.
Where this claim appeared
BleepingComputer · 2026-09-17
https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/What “Unverified” means
Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.
2 of 5 · rating scale
Assessed in
Brevo Supply-Chain Attack: Stolen Cloudflare API Key Used to Inject ClickFix Malware Across 100,000+ SitesThink this assessment is wrong? Report an error.