Home / Technology / Malware Attack Hijacks Websites Via Fake Verification
Malware Attack Hijacks Websites Via Fake Verification
18 Sep
Summary
- A hacker exploited a Brevo API key to infect thousands of websites.
- Malicious code displayed fake Cloudflare pages to trick users.
- The attack, known as ClickFix, aimed to install malware on Windows PCs.

A hacker has compromised thousands of websites by exploiting a security vulnerability at online marketing provider Brevo. The incident, which occurred on Monday, involved the theft of a long-lived API key, enabling the attacker to tamper with Brevo's services and related domains. Malicious computer code was injected into JavaScript files used by Brevo's customers, including a WordPress widget.
Selected visitors were presented with a fake "Cloudflare, verify you are human" page. This page used a social-engineering tactic called ClickFix, instructing users to paste and run a command on their computer. Executing this command, disguised as a verification step, resulted in the download and installation of malware onto visitors' Windows machines.
The ClickFix attack persisted for approximately five and a half hours. Cybersecurity provider Sansec estimates that the hacker may have spread this attack to over 100,000 websites. Evidence suggests the compromised API key was first misused in late August 2026. Brevo has since revoked the key and associated credentials.