Brevo supply-chain attack injects ClickFix scripts into customer sites: check the forms and third-party scripts on your Mexico website today
On September 17, 2026, BleepingComputer reported a supply-chain attack on Brevo, the email and forms platform formerly known as Sendinblue. Someone tampered with the code Brevo serves to its customers and used it to inject ClickFix scripts into their websites.
If your company runs a plant, warehouse or sales office in Mexico, this lands close. The local landing pages, the WhatsApp widget the Mexico team added, the newsletter form for Mexican leads: each one is a script somebody else controls.
What ClickFix is and why it works
ClickFix is a social engineering trick. The page shows a captcha that ‘failed to load’ or a Chrome error and, to ‘fix it’, tells the visitor to press Windows plus R, paste something and hit Enter.
That something installs malware. No alarm goes off because the user did it by hand. In our experience, the sales rep in Querétaro opening a supplier catalog does not hesitate: the button says fix, so they fix.
What makes the Brevo case nasty is that the lure shows up on legitimate sites. A same-day piece on AI-powered attacks and identity security points the same way: lures keep getting more believable, and the target is the person at the keyboard.
Which third-party scripts your Mexico site loads
A third-party script is code your site downloads from another domain on every visit. Your agency or the marketing team added it, but another company controls it. If that company gets breached, your site serves whatever they push.
| Type | Examples | What it does on your site |
|---|---|---|
| Forms and newsletter | Brevo, Mailchimp, HubSpot | Captures visitor data |
| Chat | Tawk, WhatsApp widget | Opens a conversation window |
| Pixels and analytics | Meta Pixel, Tag Manager | Measures visits and campaigns |
| Widgets | Maps, reviews, video | Shows external content |
Open the site in Chrome, press F12, go to the Network tab and filter by JS. Anything from a domain that is not yours is a third party. Check the Mexico landing pages too, not only the corporate home: local teams add scripts headquarters never approved.
How to tell if your page already serves the lure
The lure is selective. A marketing manager in Chicago can refresh all day and see a clean page while a customer in Monterrey gets the fake captcha. Ask someone in Mexico, outside your network, to open the site from a phone and from a PC in incognito mode.
Check Google Search Console for deceptive site warnings. And if you use Brevo, pull the script until they confirm the code is clean.
Tell your Mexico team today: nobody pastes commands
Send a short message to the local team, in Spanish. The rule fits on one line: no legitimate website asks you to open Run, PowerShell or Terminal to verify anything. If a page does, close it and call support.
It is the same rule we use against fake IT support calls via Teams and Quick Assist: urgency is the tell. If someone already pasted the command, skip the blame. Unplug the machine and get local hands on it the same day.
Locking it down: CSP and fewer dependencies
A Content Security Policy, or CSP, is a list in your web server configuration of the domains your site may load code from. The browser blocks everything else. It will not save you from a compromised vendor on the list, but it stops that script from pulling extra code from an unknown domain.
The boring fix is the effective one: fewer scripts. Every chat nobody answers and every pixel from an old campaign is a door. If nobody can say what a script does, remove it. Same logic as auditing OAuth apps in your Google Workspace or Microsoft 365.
And in your Mexico operation?
If you run a site with Mexican traffic and cannot list the scripts it loads, today is a good day to find out. At ProcessBi we review site and hosting, write a CSP that fits, audit the dependencies of your web development and back your local team with SLA support.
Book your free site review — we reply the same business day.
Your path
Running IT in Mexico from abroad
27 of 32- Smart hands ✓ Read You are here 2 min
- Remote support ✓ Read You are here 3 min
- Nearshoring checklist ✓ Read You are here 2 min
- Retail rollouts ✓ Read You are here 2 min
- Fake IT support ✓ Read You are here 3 min
- Backups that restore ✓ Read You are here 3 min
- Secure M365 ✓ Read You are here 3 min
- Windows 10 deadline ✓ Read You are here 4 min
- Audit app access ✓ Read You are here 3 min
- CEO fraud ✓ Read You are here 4 min
- Office 2016 cutoff ✓ Read You are here 3 min
- Patch today ✓ Read You are here 4 min
- Patch VMware ✓ Read You are here 4 min
- Office 2021 EOL ✓ Read You are here 3 min
- Starlink for sites ✓ Read You are here 3 min
- Cardless access ✓ Read You are here 4 min
- Control AI on PCs ✓ Read You are here 4 min
- ScreenConnect flaw ✓ Read You are here 4 min
- Server 2022 EOL ✓ Read You are here 3 min
- Exposed cameras ✓ Read You are here 3 min
- Domain trust fix ✓ Read You are here 4 min
- Patch Cisco ISE ✓ Read You are here 3 min
- Protect the plant ✓ Read You are here 3 min
- Move to 25H2 ✓ Read You are here 4 min
- Outages and UPS ✓ Read You are here 3 min
- IT maintenance ✓ Read You are here 4 min
- Third-party scripts ✓ Read You are here 3 min
- License audit ✓ Read You are here 4 min
- Bajío fiber corridor ✓ Read You are here 3 min
- Check Point flaw ✓ Read You are here 4 min
- Cashless payments ✓ Read You are here 3 min
- AI that hacks alone ✓ Read You are here 3 min
- Field services →