Brevo supply-chain attack exposed over 100,000 sites
On 14 September 2026, files served by Brevo (formerly Sendinblue) were altered: on WordPress sites with a logged-in admin a malicious plugin was installed, while other visitors saw a fake "verify you are human" prompt. Sansec estimates more than 100,000 sites were exposed; Brevo has not yet commented on the incident.
- Altered files include sdk-loader.js, brevo-conversations.js and hosted form pages
- The attack ran on 14 September from 16:05 to 20:13 UTC
- Sansec estimates over 100,000 sites were exposed
- Earlier, on 10 September, Brevo reported access to 138 customer accounts
Read next
Security