In summary. Brevo, la plateforme française d'emailing utilisée par des dizaines de milliers de PME, a subi deux incidents de sécurité début septembre 2026 : une intrusion par faille d'authentification, puis le vol d'une clé technique ayant permis d'injecter du code malveillant sur des sites clients. Cette semaine, deux entreprises touchées ont détaillé l'ampleur des dégâts pour leurs utilisateurs.
What Happened
Brevo (formerly Sendinblue) is one of the most widely used email and marketing tools among French small and medium-sized businesses for sending newsletters and transactional emails, as well as for contact forms and chat widgets integrated into websites.
On September 10, 2026, a vulnerability in Brevo's single sign-on (SSO) system allowed an attacker to compromise 138 customer accounts. Six of these accounts were used to send fake security emails to users, and the contacts from 43 accounts were exported.
On September 14, a second incident occurred: a technical key granting access to Brevo’s delivery infrastructure was stolen. For about five and a half hours, the attackers used it to dynamically modify the code delivered by Brevo forms and widgets installed on client websites, displaying a fake verification message that prompted visitors to copy and paste a command onto their computers. On WordPress, a fake plugin called “Web Media Optimizer” was also used as a backdoor. The security firm Sansec estimates that more than 100,000 sites using Brevo components may have distributed this code during the attack window.
Brevo claims to have revoked the compromised key, removed the malicious code, and cleared its caches. But the fallout continues to unfold: this week, the crypto wallet manufacturer Trezor confirmed that 347,000 of its users had received a fake security alert email sent from a hacked Brevo account, and the French crypto platform Paymium announced on September 22 that its customers’ personal information (names, dates of birth, phone numbers, and countries of residence) had been leaked through this breach.
Does this apply to me?
The risk depends on how your company uses Brevo, but it can also come from outside sources.
If your small or medium-sized business uses Brevo for its email campaigns, transactional emails, or customer support, your login credentials and contacts may have been among the accounts affected on September 10, or may simply have been exposed due to the service’s overall vulnerability.
If your website includes a contact form, a chat widget, or a Brevo script, it may have distributed the malicious code from September 14 without your knowledge, exposing your own visitors to this attack.
Even if you don't use Brevo, your employees or customers may receive phishing emails that exploit this news by mimicking a credible security alert, similar to the one that affected Trezor users.
What to Do Now
Three checks to perform in the coming days, in order of priority:
1. Check your Brevo usage. If your company has a Brevo account, change the password, regenerate the API keys, and enable two-factor authentication if you haven't already. Also check the history of recent logins.
2. Check your website. If you have a form, chat, or Brevo SDK installed on your site, have your service provider verify that no unknown plugins or scripts appeared around September 14–15, especially on WordPress. If in doubt, a full scan is recommended.
3. Remind your teams of the proper precautions. No legitimate email asks you to copy and paste a command into a terminal or command window: this is exactly the method used here (a technique known as “ClickFix”). A brief reminder to your teams can prevent many infections. Our guide on phishing details the precautions to take when faced with this type of message.
In a nutshell
Brevo experienced two incidents in early September: compromised customer accounts, followed by the theft of a technical key that allowed malicious code to be injected into tens of thousands of websites. The full extent of the impact on its customers is still becoming clear this week. If your company uses Brevo or one of its widgets, a few targeted checks are all it takes to mitigate the risk.
Frequently asked questions
I don't use Brevo—should I be concerned? The immediate risk is low. Just be on the lookout for emails that appear to be security alerts from a service you use; that's the method being exploited in this incident.
How can I tell if my Brevo account is one of the 138 affected accounts? Brevo has notified the affected accounts directly. If you're unsure, change your login credentials and check the login history from your admin interface.
— Samir Amara, CEO — IT Systèmes

.png)




