← Back to blog Cybersecurity

Brevo supply-chain attack injects ClickFix scripts into customer sites: check the forms and third-party scripts on your Mexico website today

3 min read

On September 17, 2026, BleepingComputer reported a supply-chain attack on Brevo, the email and forms platform formerly known as Sendinblue. Someone tampered with the code Brevo serves to its customers and used it to inject ClickFix scripts into their websites.

If your company runs a plant, warehouse or sales office in Mexico, this lands close. The local landing pages, the WhatsApp widget the Mexico team added, the newsletter form for Mexican leads: each one is a script somebody else controls.

What ClickFix is and why it works

The visitor does the dirty work The page installs nothing. It talks the person into pasting the command themselves, which is why no filter stops it.

ClickFix is a social engineering trick. The page shows a captcha that ‘failed to load’ or a Chrome error and, to ‘fix it’, tells the visitor to press Windows plus R, paste something and hit Enter.

That something installs malware. No alarm goes off because the user did it by hand. In our experience, the sales rep in Querétaro opening a supplier catalog does not hesitate: the button says fix, so they fix.

What makes the Brevo case nasty is that the lure shows up on legitimate sites. A same-day piece on AI-powered attacks and identity security points the same way: lures keep getting more believable, and the target is the person at the keyboard.

Which third-party scripts your Mexico site loads

A five-minute inventory Everything your page pulls from a domain that is not yours is code another company controls.

A third-party script is code your site downloads from another domain on every visit. Your agency or the marketing team added it, but another company controls it. If that company gets breached, your site serves whatever they push.

TypeExamplesWhat it does on your site
Forms and newsletterBrevo, Mailchimp, HubSpotCaptures visitor data
ChatTawk, WhatsApp widgetOpens a conversation window
Pixels and analyticsMeta Pixel, Tag ManagerMeasures visits and campaigns
WidgetsMaps, reviews, videoShows external content

Open the site in Chrome, press F12, go to the Network tab and filter by JS. Anything from a domain that is not yours is a third party. Check the Mexico landing pages too, not only the corporate home: local teams add scripts headquarters never approved.

How to tell if your page already serves the lure

Test it from outside Attackers hide the lure from the site owner. Someone in Mexico, off your network, sees what your customers see.

The lure is selective. A marketing manager in Chicago can refresh all day and see a clean page while a customer in Monterrey gets the fake captcha. Ask someone in Mexico, outside your network, to open the site from a phone and from a PC in incognito mode.

Check Google Search Console for deceptive site warnings. And if you use Brevo, pull the script until they confirm the code is clean.

Tell your Mexico team today: nobody pastes commands

Send a short message to the local team, in Spanish. The rule fits on one line: no legitimate website asks you to open Run, PowerShell or Terminal to verify anything. If a page does, close it and call support.

It is the same rule we use against fake IT support calls via Teams and Quick Assist: urgency is the tell. If someone already pasted the command, skip the blame. Unplug the machine and get local hands on it the same day.

Locking it down: CSP and fewer dependencies

Fewer doors A CSP tells the browser which domains may load code. Removing forgotten scripts closes the rest.

A Content Security Policy, or CSP, is a list in your web server configuration of the domains your site may load code from. The browser blocks everything else. It will not save you from a compromised vendor on the list, but it stops that script from pulling extra code from an unknown domain.

The boring fix is the effective one: fewer scripts. Every chat nobody answers and every pixel from an old campaign is a door. If nobody can say what a script does, remove it. Same logic as auditing OAuth apps in your Google Workspace or Microsoft 365.

ProcessBi team reviewing a website
Tell us what your site loads: we will tell you what should go Foto: Daysof1971 · CC BY-SA 4.0 · Wikimedia Commons

And in your Mexico operation?

If you run a site with Mexican traffic and cannot list the scripts it loads, today is a good day to find out. At ProcessBi we review site and hosting, write a CSP that fits, audit the dependencies of your web development and back your local team with SLA support.

Book your free site review — we reply the same business day.

Your path

Running IT in Mexico from abroad

27 of 32
  1. Smart hands ✓ Read You are here 2 min
  2. Remote support ✓ Read You are here 3 min
  3. Nearshoring checklist ✓ Read You are here 2 min
  4. Retail rollouts ✓ Read You are here 2 min
  5. Fake IT support ✓ Read You are here 3 min
  6. Backups that restore ✓ Read You are here 3 min
  7. Secure M365 ✓ Read You are here 3 min
  8. Windows 10 deadline ✓ Read You are here 4 min
  9. Audit app access ✓ Read You are here 3 min
  10. CEO fraud ✓ Read You are here 4 min
  11. Office 2016 cutoff ✓ Read You are here 3 min
  12. Patch today ✓ Read You are here 4 min
  13. Patch VMware ✓ Read You are here 4 min
  14. Office 2021 EOL ✓ Read You are here 3 min
  15. Starlink for sites ✓ Read You are here 3 min
  16. Cardless access ✓ Read You are here 4 min
  17. Control AI on PCs ✓ Read You are here 4 min
  18. ScreenConnect flaw ✓ Read You are here 4 min
  19. Server 2022 EOL ✓ Read You are here 3 min
  20. Exposed cameras ✓ Read You are here 3 min
  21. Domain trust fix ✓ Read You are here 4 min
  22. Patch Cisco ISE ✓ Read You are here 3 min
  23. Protect the plant ✓ Read You are here 3 min
  24. Move to 25H2 ✓ Read You are here 4 min
  25. Outages and UPS ✓ Read You are here 3 min
  26. IT maintenance ✓ Read You are here 4 min
  27. Third-party scripts ✓ Read You are here 3 min
  28. License audit ✓ Read You are here 4 min
  29. Bajío fiber corridor ✓ Read You are here 3 min
  30. Check Point flaw ✓ Read You are here 4 min
  31. Cashless payments ✓ Read You are here 3 min
  32. AI that hacks alone ✓ Read You are here 3 min
  33. Field services
Next Up to 30% of software spend is wasted: how to audit the licenses and subscriptions of your Mexico operation before October