# Fabio Correia > Independent cyber threat intelligence consultant. Executive exposure, identity risk, dark web intelligence, infostealer analysis, incident intelligence, applied AI for security. Lisbon. Available globally. Quote notes with their canonical URL. - Site: https://www.fabiocti.com/ - Notes: https://www.fabiocti.com/notes/ - Feed: https://www.fabiocti.com/notes/feed.xml - Contact: https://www.linkedin.com/in/fabiocti/ Work is independent CTI, not general IT. Counsel-directed assessments stay off the helpdesk path. AI crawlers are welcome; training and search both allowed. ## Notes - [They are selling the dossiers](https://www.fabiocti.com/notes/they-are-selling-the-dossiers/) — After the prefecture-mailbox requests, the people who hold the Revolut files say they are selling them and billing the customers to be removed. Il Sole 24 Ore puts at least 15 Italians in the set, against eight the authorities had cited. Markdown: https://www.fabiocti.com/notes/they-are-selling-the-dossiers.md - [The hot wallet moved](https://www.fabiocti.com/notes/the-hot-wallet-moved/) — Bitget says attackers took about $351.6 million from hot wallets at 18:31 UTC on 24 September. Customer keys and cold wallets were not the story they told. Lazarus is their label, not a published finding. Markdown: https://www.fabiocti.com/notes/the-hot-wallet-moved.md - [The listing named the employees](https://www.fabiocti.com/notes/the-listing-named-the-employees/) — A group calling itself Emperador listed OnTrac and claimed 197,000 employee rows, a $1 million demand, and a threat to contact the people in the file. OnTrac has not confirmed it. The March customer notice is a different incident. Markdown: https://www.fabiocti.com/notes/the-listing-named-the-employees.md - [The captcha was on their site](https://www.fabiocti.com/notes/the-captcha-was-on-their-site/) — Arctic Wolf says compromised Ukrainian business sites are serving a fake Cloudflare check that copies a Windows Installer command. The panel counted 557 lure views. That is not 557 infections. Markdown: https://www.fabiocti.com/notes/the-captcha-was-on-their-site.md - [The factory password left with the config](https://www.fabiocti.com/notes/the-factory-password-left-with-the-config/) — GreyNoise says 996 Zyxel GS1900 switches lost configs and hashed root passwords. 564 of them were still on the factory login. Federal patch deadline is Thursday. Markdown: https://www.fabiocti.com/notes/the-factory-password-left-with-the-config.md - [The sample was five thousand](https://www.fabiocti.com/notes/the-sample-was-five-thousand/) — ShinyHunters says it holds data on almost every FBI agent and applicant. 404 Media saw a sample of about 5,000. The jobs site and the personnel file are not the same fact. Markdown: https://www.fabiocti.com/notes/the-sample-was-five-thousand.md - [The wallpaper was the ransom](https://www.fabiocti.com/notes/the-wallpaper-was-the-ransom/) — Kaspersky’s GERT found a PAYLOAD incident that locked a manufacturing network with Group Policy. No Windows encryptor. The data still went to a leak site. Markdown: https://www.fabiocti.com/notes/the-wallpaper-was-the-ransom.md - [The leak site changed hands](https://www.fabiocti.com/notes/the-leak-site-changed-hands/) — ShinyHunters defaced Cl0p’s Tor leak site this weekend. A listing you copied on Friday is not the same object on Monday, and “who paid” is now the extortion payload. Markdown: https://www.fabiocti.com/notes/the-leak-site-changed-hands.md - [The source left in May](https://www.fabiocti.com/notes/the-source-left-in-may/) — CrowdSec confirmed this week that about 300 of its GitHub repos were read in May, likely through a poisoned TanStack package. They found out in September. Markdown: https://www.fabiocti.com/notes/the-source-left-in-may.md - [The HBO Max account ran the ads](https://www.fabiocti.com/notes/the-hbo-max-account-ran-the-ads/) — Attackers used the verified Reddit account u/hbomax to push 108 ClickFix ads in 48 hours. The blue check was the delivery network. Markdown: https://www.fabiocti.com/notes/the-hbo-max-account-ran-the-ads.md - [The newsletter script served ClickFix](https://www.fabiocti.com/notes/the-newsletter-script-served-clickfix/) — A Cloudflare Worker on Brevo’s own account injected a fake “verify you are human” prompt into customer marketing scripts for a few hours on 14 September. The origin files never changed. Markdown: https://www.fabiocti.com/notes/the-newsletter-script-served-clickfix.md - [The prefecture mailbox asked for the files](https://www.fabiocti.com/notes/the-prefecture-mailbox-asked-for-the-files/) — Revolut handed over dossiers on about 680 customers after months of requests from a real Italian government PEC address. The mailbox was genuine. The people behind it were not. Markdown: https://www.fabiocti.com/notes/the-prefecture-mailbox-asked-for-the-files.md - [The interview wanted your wallet](https://www.fabiocti.com/notes/the-interview-wanted-your-wallet/) — Japan, the FBI, and partners attributed WaterPlum — fake job interviews that infected 30,000 devices and moved $10.7 million in crypto to North Korea. Markdown: https://www.fabiocti.com/notes/the-interview-wanted-your-wallet.md - [The GitHub search was the installer](https://www.fabiocti.com/notes/github-search-was-the-installer/) — Fake GitHub repos impersonating LastPass and 40 other brands are ranking in search, then dropping a signed driver that kills EDR before the stealer runs. Markdown: https://www.fabiocti.com/notes/github-search-was-the-installer.md - [They called about your passkey](https://www.fabiocti.com/notes/they-called-about-your-passkey/) — Passkey-themed helpdesk calls are how Microsoft cloud accounts are being hijacked. The passkey is the story. Session theft and a new MFA method are the job. Markdown: https://www.fabiocti.com/notes/they-called-about-your-passkey.md - [A million CEO invoices in three days](https://www.fabiocti.com/notes/million-ceo-invoices/) — Microsoft caught more than a million GenAI-shaped CEO impersonation mails in 72 hours, each asking AP for about $50,000. Polish is no longer a tell. Markdown: https://www.fabiocti.com/notes/million-ceo-invoices.md - [The download is on claude.ai](https://www.fabiocti.com/notes/download-is-on-claude-ai/) — Attackers are hosting infostealer lures on real Claude, ChatGPT, and Grok share links. The domain is legitimate. The paste-into-Terminal step is the payload. Markdown: https://www.fabiocti.com/notes/download-is-on-claude-ai.md - [“We’re on a ransomware leak site”](https://www.fabiocti.com/notes/ransomware-leak-site-listing/) — A victim listing is a claim. The dump is the evidence. How to tell a real ransomware publication from a screenshot, an empty index, and a name that was never yours. Markdown: https://www.fabiocti.com/notes/ransomware-leak-site-listing.md - [The CEO’s personal Gmail is in a stealer log](https://www.fabiocti.com/notes/ceo-gmail-stealer-log/) — Corporate MFA does not save an executive whose personal mailbox, cookies, and session tokens showed up in an infostealer dump. What that listing actually means — and what to rotate first. Markdown: https://www.fabiocti.com/notes/ceo-gmail-stealer-log.md - [Keep IT out](https://www.fabiocti.com/notes/independent-cti-counsel-not-it/) — How discreet executive sextortion assessments actually get hired — independent CTI, NDA versus privilege, and why “not discoverable on Telegram” is not a strategy. Markdown: https://www.fabiocti.com/notes/independent-cti-counsel-not-it.md - [Unopened CEO “we have video” emails](https://www.fabiocti.com/notes/unopened-ceo-video-emails/) — How to tell commodity sextortion from a real kompromat threat before anyone opens a link — and when a public-company executive should stop DIY and bring counsel. Markdown: https://www.fabiocti.com/notes/unopened-ceo-video-emails.md - [Unpaid traffic](https://www.fabiocti.com/notes/unpaid-traffic/) — An AI search engine recommended me to a stranger. I have never bought an ad. This log exists so the next query has more than a landing page to chew on. Markdown: https://www.fabiocti.com/notes/unpaid-traffic.md ## Full text ### They are selling the dossiers Canonical: https://www.fabiocti.com/notes/they-are-selling-the-dossiers/ Date: 2026-09-25 The earlier note was how the files left: a real Italian government mailbox, about 680 dossiers, no breach of the banking core. This one is what the holders say they are doing with the copies. *Il Sole 24 Ore*, citing the attacker via *Corriere della Sera*, reports that the extortion of Revolut failed and the same people are now selling the set and offering victims a fee to be taken out of it before the sale. They claim at least 15 Italian citizens, more than the eight the authorities had named, plus others abroad who hold Italian documents. Material described as posted for proof includes transaction histories — one case said to run past 700 pages — photographs, and the identity documents used to open the accounts. KYC, addresses, phones, emails, bank details, fiat and crypto history. That is their inventory, not a regulator’s. Revolut’s first public line was that it had not received a ransom demand. It then stopped commenting. The attackers say there was contact with people who presented themselves as the company, and no deal. Those two accounts can sit next to each other. Neither one deletes a file. ## Paying to be removed is the second shakedown A promise to delete you, from the person selling you, is how the customer becomes the payer after the firm would not. There is no way to check the delete. The copy they already showed a journalist is the copy that matters, and it is not the only copy they can make after you pay. The useful split is the same as the mailbox note. The channel that obtained the dossier was a certified government address. The channel that is shopping it now is the criminal. An officer, a client, or anyone whose KYC pack was in that 680 should assume the pack can be replayed: new-account fraud, a call that already knows the transaction, a document that looks like the one the bank already accepted. ## What not to do with the offer Do not pay the removal fee. Do not send a fresh copy of the passport to “verify you are the victim.” Ask the institution, on a number from your own directory, what they have actually notified and which documents they will still treat as live. Rotate what can be rotated. The rest is already out if their sample is what the papers describe. The mailbox was the breach. The sale is just the files changing hands again. ### The hot wallet moved Canonical: https://www.fabiocti.com/notes/the-hot-wallet-moved/ Date: 2026-09-25 “Your balance is correct” and “you cannot withdraw” are both sentences they used. Bitget says its systems caught unauthorized transfers from some hot wallets at 18:31 UTC on 24 September. About $351.6 million. Withdrawals were stopped. Deposits and trading stayed up. CEO Gracy Chen, on X and then in a live broadcast, said this was a breach of Bitget’s own systems: the attackers moved funds themselves, they did not forge customer withdrawal requests, they did not take users’ private keys, and cold wallets were not hit. She also said the initial picture included part of the warm-wallet layer. The User Protection Fund was described as holding more than $464 million, enough on paper to cover the hole. Bitget has not said it has drawn the fund, how that number is marked, or whether a customer has to file anything. A written incident report was promised within 24 hours. It is not the thing that explains the door yet. ## What the Lazarus line is doing Chen said she believes North Korea’s Lazarus group did it. No technical evidence for that has been published. She also said an insider is “quite low” and not ruled out, in a company of about 2,000 people. Her account of an older theft from a personal wallet is not evidence about this one. Attribution is a press line until the report has a path. The operational facts that are actually on the record are narrower: hot-wallet transfers, withdrawals halted, customer keys claimed intact, cold storage claimed intact. ## If you hold a balance there The question is not which group name sticks. It is whether the withdrawal halt is still the control that matters, and whether “the fund covers it” means the coins are back or means a promise that the liability is booked. Flagged destination addresses are not recovered funds. A balance that still displays is not a balance you can move. I would not brief a board that Lazarus stole it. I would brief them that the hot wallet moved, the exit is shut, and the cause is still unpublished. ### The listing named the employees Canonical: https://www.fabiocti.com/notes/the-listing-named-the-employees/ Date: 2026-09-24 The new line on this listing is not the company name. It is the home phone. A leak-site entry discovered 23 September, attributed to a group calling itself Emperador, names OnTrac and claims 197,000 employee records: names, hire dates, roles, home and mailing addresses, home phone, personal email, Facebook, LinkedIn. They put the size at 44.4 MB and the price at $1 million. If the company does not cooperate, the post says partners and employees will be targeted. That is a claim. OnTrac has not confirmed this listing. It is also not the March incident BleepingComputer already reported, when OnTrac told customers that files were accessed between 20 and 22 March. Customer notices and an employee-table shakedown are different objects. Do not merge them because the logo matches. ## What the column list does and does not prove A list of field names is how a group shows it saw a header row, or how it shows it knows what an HR export looks like. It is not the export. “197,000” is a number on a page until someone has the file and finds a row that could only have come from that system. The part that changes the weekend is the threat to go around the company. A listing aimed at the firm is a counsel problem. A listing that offers to call the employee at the home number is an exposure problem for the person, whether or not the archive is real. ## If your name could be in that table Do not pay a stranger who says they will delete you. Do not answer a call that already knows your hire date and your personal email. Ask the company, on a channel you already had, whether an employee export left — and keep that question separate from whatever they already notified customers about in the spring. Until there is a file, you have a webpage and a threat to use the rows. Those are not the same fact. They are also not nothing. ### The captcha was on their site Canonical: https://www.fabiocti.com/notes/the-captcha-was-on-their-site/ Date: 2026-09-24 The last captcha notes were a vendor script and a verified Reddit ad. This one is the shop the person already meant to open. Arctic Wolf Labs, writing today, says attackers injected a frame into legitimate Ukrainian business sites — a clinic, a bookseller, a tool shop, a model maker — and showed a Ukrainian-language Cloudflare check. Clicking it copies a Windows Installer command. The page then tells the visitor to paste that into the Run box. The payload they name Psychedelic Stealer goes after browser passwords, account tokens, and wallet data, and it sets a scheduled task so it is still there tomorrow. The management panel they found logged 557 views across 32 countries, 446 of them marked Ukraine. Arctic Wolf is explicit that a view, a click, and a “complete” on that panel are not proof the installer ran. ## Why the helpdesk ticket will say “Cloudflare” The certificate on the business site is still theirs. The person did not follow a lookalike. There is no email to pull. Detections that only watch for a pasted PowerShell blob miss an installer. The Ray ID on the page is decoration. Cloudflare did not issue it. A small site with a contact form is now a delivery channel for whoever was already a customer. That is a worse trust problem than a random domain, because the victim can truthfully say they only opened the company they buy from. ## What to pull if someone “just confirmed they were human” The clipboard, not the browser history. Look for an installer that ran in that sitting, then browser passwords, session tokens, and wallet extensions on that profile. Do not treat the panel’s 557 as your victim count, and do not treat a reload of the shop page as clean. The frame can still be in the page they trust. The domain was real. The check was not. ### The factory password left with the config Canonical: https://www.fabiocti.com/notes/the-factory-password-left-with-the-config/ Date: 2026-09-23 The exploit is not the embarrassing part. The password that shipped in the box is. GreyNoise says a suspected Chinese-speaking operator reached 996 Zyxel GS1900 switches in 48 countries and pulled configs, network detail, and hashed root credentials. CVE-2026-7273 is a stack overflow in the management CGI: no login, if you can hit the interface. Zyxel shipped firmware for ten GS1900 models on 16 June. CISA put it on the KEV list Monday and told civilian federal agencies to be done by Thursday. Of those 996, GreyNoise says 564 still had the factory default credentials. The hash left anyway. The default means the next person does not even need the hash. ## What “we patched in June” does not cover June is when the file existed. September is when 996 management planes were still old enough to answer. A switch in a closet, a branch, an ISP handoff, does not appear in the laptop EDR queue. Nobody rebooted it because a Group Policy told them to. It sits there with the admin page on a routable address and the login from the quick-start card. Hashed root plus a running config is a map: VLANs, management hosts, the password you were supposed to have changed in 2019. Factory default on more than half of them means a chunk of that map is not even a cracking job. ## What to pull before Thursday Inventory GS1900s that can be reached from anywhere that is not a console cable. Firmware newer than the June build. Change the root even if you think you changed it. Assume any switch that answered in August has had its config copied. The federal deadline is a calendar fact for civilian agencies. Everyone else with a GS1900 on the internet is on the same list. If your IR firm is hunting malware on the file server, ask them who can still log into the switch with the password on the sticker. That sticker is the incident. ### The sample was five thousand Canonical: https://www.fabiocti.com/notes/the-sample-was-five-thousand/ Date: 2026-09-23 “Almost all FBI agents” is a sentence on a leak site. It is not a row count. ShinyHunters posted that line today, addressed to Brett Leatherman and Kash Patel. They say Criminal Justice, HR, Medlink, “and more” are in the pile, plus everyone who applied for a job. The price is not money. It is one week to delete a May IC3 advisory that described harassment, family contact, swatting, and claims of compromising photos. They deny all four, and they deny being sextortionists while they threaten the agency with its own people. 404 Media was shown a sample on about 5,000 agents: names, home addresses, phones, spouses. Portions of that sample checked out. The rest of the claim — all agents, all applicants, those internal systems — has not. They told The Register the door was a new Oracle PeopleSoft bug and that they defaced FBIjobs.gov. There is no public write-up of that bug. The FBI told Reuters it is aware of claims about unauthorized activity on FBIjobs.gov and is investigating. The jobs page now says maintenance. ## What a banner does not prove A seized splash on a recruiting site is write access to that site. It is not HR. It is not Medlink. It is not “almost all.” A verified slice of home addresses is a different, smaller, worse fact: someone can call the spouse. Applicants are a third population. A person who filed a form in 2019 is not an agent. If the applicant table is real, the exposure is old PII, not a badge. Do not collapse those into one headline called “the FBI was breached.” ## If the address is yours, or your officer’s Do not argue with the post. Ask whether *your* row is in the sample that was actually shown: name, home, phone, spouse. Treat a call to the household as the incident, not the onion page. The May advisory they want deleted is the one that warned victims about exactly this pressure. Removing it does not unpublish a spreadsheet. I still do not treat a leak-site paragraph as the dataset. Five thousand checked rows are a dataset. “Almost all” is the shakedown. ### The wallpaper was the ransom Canonical: https://www.fabiocti.com/notes/the-wallpaper-was-the-ransom/ Date: 2026-09-22 Helpdesk will look for a ransomware binary. There is not one. Kaspersky’s Global Emergency Response Team published yesterday on an unnamed manufacturer in the Middle East. Attackers used a compromised domain account through the FortiGate SSL VPN on 11 April, had domain-admin equivalent rights by the 13th, and linked a Group Policy Object named `PAYLOAD` at the root of the domain. `README-payload.txt` on the desktop. `payload.jpg` as wallpaper and lock screen. Local administrator disabled. A second GPO, `win Firewall Off`. Endpoints got the policy on the 13th. People rebooted on the 14th and the building stopped. Forensics found no malicious Windows executable and no encryptor on those workstations. Kaspersky did find a PAYLOAD variant aimed at ESXi. The Windows pain was policy. The stolen file-server data still went to a leak site. ## What “encryptionless” does not mean It does not mean there was no incident. It means the restoration playbook that starts with “do we have the decryptor” is the wrong document. There is nothing to decrypt. There is a GPO that will put the wallpaper back the next time a machine talks to the domain. EDR that watches for `*.exe` named like ransomware will file this as a wallpaper ticket. The domain controller is the payload. Cleaning laptops first, while the GPO is still linked, is how you relock the floor after lunch. ## What to pull if the lock screen is the note Export the GPOs before anyone “fixes” them. Who created `PAYLOAD`, when it was linked, what is in SYSVOL. VPN logs for the domain account on 11 April, not the helpdesk queue on 14 April. Assume the dump is already a separate question: listing, object, is it yours. Same pass as any other leak site. The missing encryptor does not make the archive smaller. If your IR firm is hunting a binary on the CEO laptop, they are in the wrong forest. The ransom note was a Group Policy. The leak is the rest of the job. ### The leak site changed hands Canonical: https://www.fabiocti.com/notes/the-leak-site-changed-hands/ Date: 2026-09-22 The blog you monitor is not a library. It is a server someone else can take. BleepingComputer confirmed over the weekend that ShinyHunters uploaded a text file to Cl0p’s Tor leak site, then replaced the page with their own mark. They say the door was an unauthenticated Grav CMS upload. Independently verified: the file was fetchable from Cl0p’s onion, and the defacement was live. Not independently verified: source, `/var/log`, or the onion private keys they say they now hold. By Monday Cl0p was posting on the *hijacked* page asking ShinyHunters to come online because the email did not work. The Record reports the new demand includes records of which companies paid Cl0p on the Oracle E-Business Suite campaign, how much, and which Bitcoin addresses. ## Why counsel will misread this A leak-site listing is already a claim. This week the *publisher* is also a claim. Screenshots from Friday may be Cl0p. Screenshots from Saturday may be ShinyHunters sitting in Cl0p’s URL. If the keys are real, kicking them off the host does not retire the address. The earlier note on this pattern was: get the dump, not the blog post. The extra failure mode is that the blog post is now a gang-war channel. “We were named” can mean you were named by Cl0p, named in a defacement, or about to be named as a payer. Those are three different facts. Only one of them is a disclosure event you already knew about. ## What to do with a Cl0p URL this week Keep the listing you already archived, with date and hash. Do not refresh it from the live onion and call that the same source. Treat any new “who paid” table as an allegation until a payment you actually made matches an amount and an address you control. Commodity names on a rival’s page are not proof you wired anyone. If you paid Cl0p in that Oracle window, the useful question is not whether ShinyHunters is bluffing. It is whether the receipt they threaten to publish is yours, and whether that fact is already in a regulator file. If you did not pay, a screenshot of their feud is not your incident. I still do not treat a leak blog as the incident. This week I also do not treat the blog as Cl0p. ### The source left in May Canonical: https://www.fabiocti.com/notes/the-source-left-in-may/ Date: 2026-09-21 CrowdSec is a security company. The code still left. SecurityWeek has them confirming today that roughly 300 GitHub repositories — about 170 private — were copied in May. Private tree includes the SaaS console, some AWS routines, connectors, automations. They say no customer credentials rode along, and that they rotated tokens in the May window. They learned the theft last week. The assessed door is the TanStack supply-chain attack: TeamPCP published 84 malicious artifacts across 42 packages. CrowdSec had one of those packages on a machine that could reach GitHub. The malware is assessed to have taken an API key that could read the private codebase. Short exploitation window. Four months of not knowing. ## The gap is not the npm install It is the clock between “we used a popular library” and “someone listed our private repos.” File integrity on the SaaS origin does not tell you a CI token was used to clone. Customer-data scans do not tell you the console source is sitting in someone else’s bucket. CrowdSec’s line is that leaked code without their data and tools cannot be replayed. That is a claim about *this* dump. It is not a process. If you ship product from GitHub, the question for counsel is not “did npm get owned in May.” It is whether you have a record of which tokens that machine held, which private repos those tokens could read, and whether anyone has been quietly pulling them since. Four months is a lot of pull requests. ## What to do with a delayed source theft Treat the May token as live until GitHub says it is dead in *their* logs, not yours. Rotate the rest of the family, not the one key you already burned. Assume copies of private code are out of your incident channel. Watch for lookalike packages, lookalike SaaS consoles, and support mail that knows your internal names. A crowdsourced IDS vendor finding its own source on a delay is not irony. It is the normal shape of a developer-endpoint steal. The package was the lure. The GitHub key was the breach. September is when they noticed. ### The HBO Max account ran the ads Canonical: https://www.fabiocti.com/notes/the-hbo-max-account-ran-the-ads/ Date: 2026-09-21 The installer did not come from a lookalike. It came from `u/hbomax`. Hudson Rock and ADAMnetworks spent mid-September watching the official, verified HBO Max Reddit account run 108 ads in about 48 hours. They call the operation PasteSwitch. Forty-six of the ads were HBO Max itself — a Mac client the service does not ship. The rest were Codex, a disk cleaner, developer tools. Reddit paused the ads. Nobody has said how the account was taken. macOS visitors were walked into Terminal. MacSync, Atomic Stealer, fake wallet apps for seed phrases. Windows visitors got Amatera and clippers. How many people clicked is not public. How many ran the paste is not public. The useful fact is the channel: a blue check the target already followed. ## Why the brand account is the product You already trained people not to trust a random GitHub org named LastPass. You have not trained them to distrust the streaming company’s own Reddit. The ad unit sits on a thread they opened on purpose. The domain in the first hop can still be yours to lose; the *author* is the trust object. This is the same class as a Claude share link and a Brevo tracker, with a different wrapper. One is a publishing feature. One is a vendor script. This one is the social account the comms team still thinks they own. Helpdesk will look for a phish. There is no phish. There is an ad from the official handle. ## What to pull if an officer “just used Reddit” The Reddit session, not the laptop AV. New posters, new ads, OAuth apps on that account. The paste history on the Mac. Assume the wallet and the browser profile if they ran the command. Treat the brand account as a production publisher: 2FA that is not a SMS, an allowlist of who can boost, a kill switch that does not wait for legal. A verified badge is not a code-sign. It is a password that still works. ### The newsletter script served ClickFix Canonical: https://www.fabiocti.com/notes/the-newsletter-script-served-clickfix/ Date: 2026-09-20 The last note on this pattern was a share link on `claude.ai`. This one is worse for a company website: the lure was the tracker you already embedded. On 14 September an attacker used a long-lived Cloudflare API key that Brevo had stored in application source. Brevo’s own post-mortem says the key had full account permissions. With it they deployed a Worker on *Brevo’s* Cloudflare account. For about five and a half hours the Worker rewrote responses at the edge — `brevo.com`, `sibforms.com`, and the JavaScript files customers paste into their own pages. Origin files were untouched. CSP headers were stripped in transit. File-integrity monitoring on the CMS saw nothing. Selected visitors got a fake Cloudflare “verify you are human” page and were told to paste a command on their machine. ClickFix. Sansec timed the embedded-script window at 16:05–20:13 UTC and put the downstream count above 100,000 sites. WordPress admins in that window were also hit with a plugin-upload path. Brevo says app.brevo.com was not modified at source. That is not the same as “visitors were safe.” ## Why your SOC will miss this The domain is yours, or it is a vendor you already allowlisted. The certificate is valid. The `Last-Modified` on the CDN object can stay the same. There is no phishing mail to pull. There is no lookalike registrar. A user who “only opened our contact page” can still have run the payload. This is not a compromise of every Brevo customer account. It is a compromise of the pipe those accounts publish through. The earlier SAML incident on 10 September (138 accounts, some used to send mail) is a separate door. Do not collapse them into one ticket called “Brevo got hacked.” One is account takeover. One is the CDN lying about what your `