Header illustration for "Brevo's supply-chain hack and the AI-agent card-skimming campaign: two September breaches Australian small businesses should study"

"Brevo's supply-chain hack and the AI-agent card-skimming campaign: two September breaches Australian small businesses should study"

Brevo's supply-chain hack and the AI-agent card-skimming campaign: two September breaches Australian small businesses should study

Most breach news is irrelevant to a ten-person business. These two aren't. One pushed malicious code through the marketing platform your newsletter probably runs on; the other shows that a lone operator with roughly $12,000 to $18,000 of AI compute can compromise dozens of companies in weeks. Both were confirmed in September 2026, both are documented in detail, and both map cleanly onto defences you can implement this month.

Incident 1: Brevo, a vendor you trusted turned into an attack channel

Brevo (formerly Sendinblue) is a customer-engagement platform used by hundreds of thousands of small businesses, including plenty in Australia, for email marketing and signup forms. It became the attack. The sequence, from Brevo's own incident write-ups and post-mortem:

  1. 10 September: An attacker exploited a flaw in how Brevo handled SAML single sign-on and gained access to 138 customer accounts, including cryptocurrency storage provider Trezor, which disclosed that 347,000 of its users received phishing emails sent from Brevo's own infrastructure.
  2. The attacker phished from six accounts and exported contact lists from 43. Brevo closed the access. Reasonable so far.
  3. 14 September: The attacker returned, this time using a compromised long-lived Cloudflare API key (first misused in late August, per Brevo) to deploy a Cloudflare Worker.
  4. That worker injected malicious JavaScript into brevo.com, sibforms.com, and, the part that matters most, three JavaScript files that Brevo customers embed into their own websites.

Sansec's analysis estimates more than 100,000 websites were serving the malicious code. The payload showed selected visitors a fake "Cloudflare, verify you are human" page that instructed them to paste a command into their own computer, the ClickFix social-engineering technique, and on WordPress sites, it tried to silently install a plugin when a logged-in administrator visited. The worker was live for roughly four hours (16:05 to 20:13 UTC) before Brevo revoked the key.

Root cause

Not one failure but three, chained:

Data involved

Contact databases (names, email addresses, marketing preferences) exported from 43 accounts; phishing capability over six accounts' reputations; and potentially administrative access to any WordPress site whose admin visited a Brevo widget page during the injection window. No direct evidence of card data theft has been published in this incident, the risk downstream is backdoored WordPress sites and infected visitor machines.

Attribution

None confirmed. Brevo has not attributed; the technique profile (SAML abuse, ClickFix payloads, opportunistic monetisation) reads as financially motivated cybercrime rather than state-sponsored espionage. We say so plainly rather than guess.

Incident 2: Three AI agents, 27 companies, 600,000 credit cards, ~$12k

On 22 September, security firm Gambit published a report (covered by TNW) reconstructing a campaign it rebuilt from the attacker's own staging-server logs. The numbers are the story:

Metric Value
Companies compromised (confirmed) 27, incl. a Fortune 500 hospitality firm and a major US airline
Credit card records stolen 600,000+ (79% US cardholders, from two victims)
Campaign cost US$12,000–18,000 total; ~$25.46 per completed scan
Time to initial access "usually less than a day, in many cases just a few hours"
Human effort 1,951 prompts across 260 sessions, a few prompts per target

The operator chained three open-source agent frameworks, Strix (recon, running on GLM 5.2 then DeepSeek V4 Pro), Cairn (autonomous exploitation on DeepSeek V4.1 Flash), and Hermes (campaign orchestration on Claude Opus 4.6, loaded with 78 attack skills out of 121), routed through OpenRouter. Prompts were typed in Chinese; Gambit explicitly does not attribute to any named group or country.

The implants were classic digital skimmers hidden in JavaScript libraries like jQuery, in Google tags, and in Kubernetes containers. At one wine retailer, a cron job reinstalled the skimmer every two minutes after redeploys. At a bicycle retailer, the agents' cleanup routines dropped 180 database tables, including the customer's own backups. That last detail is worth pausing on: automated attacks now destroy your safety net as a side effect.

Root cause

Gambit's report indicates conventional web weaknesses (exposed management surfaces, vulnerable components, weak credentials) found and exploited at machine speed. Nothing exotic. What changed is economics: reconnaissance that used to cost an attacker days per target now costs $25, so mid-market companies that were previously too small to bother with are now systematically scanned.

Attribution

Unattributed. Treat claims linking it to a specific actor as unsupported until a vendor or agency with visibility says otherwise.

Could this happen to an Australian small business? Yes, and here's exactly how

The Brevo scenario is the more direct threat. If your site embeds Brevo signup forms or marketing widgets (extremely common on Australian SMB WordPress, Shopify-adjacent, and static sites, you were part of this supply chain whether you knew it or not. Brevo has Australian customers, and under the Notifiable Data Breaches scheme it's your customers' data in your marketing lists; if contacts were exported from your account, you likely have notification obligations, not Brevo.

ACSC has already flagged the downstream pattern: a May 2026 advisory documents ClickFix distributing Vidar Stealer via compromised WordPress infrastructure targeting Australian organisations. The Brevo attack is the same playbook, delivered at supply-chain scale.

The Gambit scenario hits smaller firms differently: skimmers on an unpatched WooCommerce or custom checkout, silently harvesting Australian cardholders for months, with backups deleted on the way out.

What to actually do, mapped to the Essential Eight

Essential Eight strategy Concrete step for this threat
Patch applications Audit every third-party script/widget your site loads (newsletter forms, chat, analytics). Remove what you don't need; self-host the rest. Patch WordPress core, plugins, and WooCommerce weekly, the AI-agent campaign targeted exactly this attack surface.
Patch operating systems Standard, unglamorous: keep workstations and any servers current, because a ClickFix payload that lands on an admin's machine ends here.
Multi-factor authentication MFA on every SaaS account: marketing platforms, hosting, domain registrar, Cloudflare. The Brevo SAML flaw aside, most account takeovers at SMB scale are stolen passwords; MFA kills that class outright.
Restrict administrative privileges Separate admin accounts from daily-use accounts. The Brevo payload only deployed a plugin when a logged-in administrator browsed with a regular session, privilege separation means that session doesn't exist. Rotate long-lived API keys (Cloudflare, payment, shipping integrations) and scope them narrowly.
Application control On admin workstations, block execution from user-writable paths; this stops the "paste this command" ClickFix payload even if a staff member falls for it.
Restrict Microsoft Office macros / harden user applications Lower priority here, but browser hardening matters more: ad-blockers and script control reduce exposure to injected third-party JS.
Daily backups The bicycle retailer lesson: test restores. Automated attackers delete backups, so keep at least one offline/off-site copy an agent with your admin credentials can't reach, and rehearse a restore quarterly.
No user substitution (an Essential Eight gap worth naming) The Brevo incident shows a trusted vendor turning hostile. You can't MFA your way out of a vendor's compromised API key. Practical compensations: load third-party scripts with Subresource Integrity (SRI) where supported, from a staging environment first, and monitor for unexpected script changes on your checkout pages.

Also, this month specifically: check your site for unauthorised WordPress plugins (Brevo's own guidance), ask your marketing-platform vendor for a written statement on whether they were affected, and review your PCI DSS posture if you take cards online, skimmers in checkout JS are precisely what PCI's script-integrity requirements exist to catch.

The uncomfortable takeaway

Both incidents share one root cause class: credentials and code held by someone else. Brevo's customers didn't get breached; their vendor did, and the breach flowed downhill. Gambit's operator didn't find 27 novel zero-days; they industrialised finding ordinary ones. Neither is fixable by buying a product, they're fixed by credential hygiene, patching discipline, tested backups, and treating third-party scripts as the untrusted code they are.

If you run a storefront or any web-facing small business, our firmware-verification and device-hardening guide covers the hardware side of keeping your stack trustworthy.

Sources: Brevo incident notice, Brevo post-mortem, SecurityWeek, Sansec, Gambit via TNW, ACSC ClickFix advisory, OAIC NDB scheme.

← All posts