"Brevo's supply-chain hack and the AI-agent card-skimming campaign: two September breaches Australian small businesses should study"
Brevo's supply-chain hack and the AI-agent card-skimming campaign: two September breaches Australian small businesses should study
Most breach news is irrelevant to a ten-person business. These two aren't. One pushed malicious code through the marketing platform your newsletter probably runs on; the other shows that a lone operator with roughly $12,000 to $18,000 of AI compute can compromise dozens of companies in weeks. Both were confirmed in September 2026, both are documented in detail, and both map cleanly onto defences you can implement this month.
Incident 1: Brevo, a vendor you trusted turned into an attack channel
Brevo (formerly Sendinblue) is a customer-engagement platform used by hundreds of thousands of small businesses, including plenty in Australia, for email marketing and signup forms. It became the attack. The sequence, from Brevo's own incident write-ups and post-mortem:
- 10 September: An attacker exploited a flaw in how Brevo handled SAML single sign-on and gained access to 138 customer accounts, including cryptocurrency storage provider Trezor, which disclosed that 347,000 of its users received phishing emails sent from Brevo's own infrastructure.
- The attacker phished from six accounts and exported contact lists from 43. Brevo closed the access. Reasonable so far.
- 14 September: The attacker returned, this time using a compromised long-lived Cloudflare API key (first misused in late August, per Brevo) to deploy a Cloudflare Worker.
- That worker injected malicious JavaScript into brevo.com, sibforms.com, and, the part that matters most, three JavaScript files that Brevo customers embed into their own websites.
Sansec's analysis estimates more than 100,000 websites were serving the malicious code. The payload showed selected visitors a fake "Cloudflare, verify you are human" page that instructed them to paste a command into their own computer, the ClickFix social-engineering technique, and on WordPress sites, it tried to silently install a plugin when a logged-in administrator visited. The worker was live for roughly four hours (16:05 to 20:13 UTC) before Brevo revoked the key.
Root cause
Not one failure but three, chained:
- An SAML SSO implementation flaw that let the attacker impersonate or access accounts across tenants.
- A long-lived, over-privileged API credential sitting in Brevo's environment: a Cloudflare key that could deploy arbitrary workers across brevo.com's edge. Static secrets with no rotation and no scoping are the single most common root cause in modern supply-chain incidents.
- Trusted third-party scripts loaded with no integrity guarantee by 100,000+ downstream websites. Every site embedding Brevo's JS files gave Brevo (and whoever held Brevo's keys) arbitrary code execution in their visitors' browsers.
Data involved
Contact databases (names, email addresses, marketing preferences) exported from 43 accounts; phishing capability over six accounts' reputations; and potentially administrative access to any WordPress site whose admin visited a Brevo widget page during the injection window. No direct evidence of card data theft has been published in this incident, the risk downstream is backdoored WordPress sites and infected visitor machines.
Attribution
None confirmed. Brevo has not attributed; the technique profile (SAML abuse, ClickFix payloads, opportunistic monetisation) reads as financially motivated cybercrime rather than state-sponsored espionage. We say so plainly rather than guess.
Incident 2: Three AI agents, 27 companies, 600,000 credit cards, ~$12k
On 22 September, security firm Gambit published a report (covered by TNW) reconstructing a campaign it rebuilt from the attacker's own staging-server logs. The numbers are the story:
| Metric | Value |
|---|---|
| Companies compromised (confirmed) | 27, incl. a Fortune 500 hospitality firm and a major US airline |
| Credit card records stolen | 600,000+ (79% US cardholders, from two victims) |
| Campaign cost | US$12,000–18,000 total; ~$25.46 per completed scan |
| Time to initial access | "usually less than a day, in many cases just a few hours" |
| Human effort | 1,951 prompts across 260 sessions, a few prompts per target |
The operator chained three open-source agent frameworks, Strix (recon, running on GLM 5.2 then DeepSeek V4 Pro), Cairn (autonomous exploitation on DeepSeek V4.1 Flash), and Hermes (campaign orchestration on Claude Opus 4.6, loaded with 78 attack skills out of 121), routed through OpenRouter. Prompts were typed in Chinese; Gambit explicitly does not attribute to any named group or country.
The implants were classic digital skimmers hidden in JavaScript libraries like jQuery, in Google tags, and in Kubernetes containers. At one wine retailer, a cron job reinstalled the skimmer every two minutes after redeploys. At a bicycle retailer, the agents' cleanup routines dropped 180 database tables, including the customer's own backups. That last detail is worth pausing on: automated attacks now destroy your safety net as a side effect.
Root cause
Gambit's report indicates conventional web weaknesses (exposed management surfaces, vulnerable components, weak credentials) found and exploited at machine speed. Nothing exotic. What changed is economics: reconnaissance that used to cost an attacker days per target now costs $25, so mid-market companies that were previously too small to bother with are now systematically scanned.
Attribution
Unattributed. Treat claims linking it to a specific actor as unsupported until a vendor or agency with visibility says otherwise.
Could this happen to an Australian small business? Yes, and here's exactly how
The Brevo scenario is the more direct threat. If your site embeds Brevo signup forms or marketing widgets (extremely common on Australian SMB WordPress, Shopify-adjacent, and static sites, you were part of this supply chain whether you knew it or not. Brevo has Australian customers, and under the Notifiable Data Breaches scheme it's your customers' data in your marketing lists; if contacts were exported from your account, you likely have notification obligations, not Brevo.
ACSC has already flagged the downstream pattern: a May 2026 advisory documents ClickFix distributing Vidar Stealer via compromised WordPress infrastructure targeting Australian organisations. The Brevo attack is the same playbook, delivered at supply-chain scale.
The Gambit scenario hits smaller firms differently: skimmers on an unpatched WooCommerce or custom checkout, silently harvesting Australian cardholders for months, with backups deleted on the way out.
What to actually do, mapped to the Essential Eight
| Essential Eight strategy | Concrete step for this threat |
|---|---|
| Patch applications | Audit every third-party script/widget your site loads (newsletter forms, chat, analytics). Remove what you don't need; self-host the rest. Patch WordPress core, plugins, and WooCommerce weekly, the AI-agent campaign targeted exactly this attack surface. |
| Patch operating systems | Standard, unglamorous: keep workstations and any servers current, because a ClickFix payload that lands on an admin's machine ends here. |
| Multi-factor authentication | MFA on every SaaS account: marketing platforms, hosting, domain registrar, Cloudflare. The Brevo SAML flaw aside, most account takeovers at SMB scale are stolen passwords; MFA kills that class outright. |
| Restrict administrative privileges | Separate admin accounts from daily-use accounts. The Brevo payload only deployed a plugin when a logged-in administrator browsed with a regular session, privilege separation means that session doesn't exist. Rotate long-lived API keys (Cloudflare, payment, shipping integrations) and scope them narrowly. |
| Application control | On admin workstations, block execution from user-writable paths; this stops the "paste this command" ClickFix payload even if a staff member falls for it. |
| Restrict Microsoft Office macros / harden user applications | Lower priority here, but browser hardening matters more: ad-blockers and script control reduce exposure to injected third-party JS. |
| Daily backups | The bicycle retailer lesson: test restores. Automated attackers delete backups, so keep at least one offline/off-site copy an agent with your admin credentials can't reach, and rehearse a restore quarterly. |
| No user substitution (an Essential Eight gap worth naming) | The Brevo incident shows a trusted vendor turning hostile. You can't MFA your way out of a vendor's compromised API key. Practical compensations: load third-party scripts with Subresource Integrity (SRI) where supported, from a staging environment first, and monitor for unexpected script changes on your checkout pages. |
Also, this month specifically: check your site for unauthorised WordPress plugins (Brevo's own guidance), ask your marketing-platform vendor for a written statement on whether they were affected, and review your PCI DSS posture if you take cards online, skimmers in checkout JS are precisely what PCI's script-integrity requirements exist to catch.
The uncomfortable takeaway
Both incidents share one root cause class: credentials and code held by someone else. Brevo's customers didn't get breached; their vendor did, and the breach flowed downhill. Gambit's operator didn't find 27 novel zero-days; they industrialised finding ordinary ones. Neither is fixable by buying a product, they're fixed by credential hygiene, patching discipline, tested backups, and treating third-party scripts as the untrusted code they are.
If you run a storefront or any web-facing small business, our firmware-verification and device-hardening guide covers the hardware side of keeping your stack trustworthy.
Sources: Brevo incident notice, Brevo post-mortem, SecurityWeek, Sansec, Gambit via TNW, ACSC ClickFix advisory, OAIC NDB scheme.