← Braintrust

2026 Braintrust — AWS account breach; customers told to rotate API keys

2026 Unknown records affected Share on X

Data compromised

Customer API keys for cloud AI models; company said one impacted customer contacted, no broader exposure evidence at disclosure

Technical writeup

AI observability startup Braintrust detected suspicious activity on May 4, 2026 and confirmed unauthorized access to one Amazon Web Services account containing customer API keys used to reach cloud-hosted AI models. The company published a May 5 trust-center notice, locked down the account, rotated internal secrets, and emailed all customers to rotate keys stored with Braintrust out of caution—stating it had contacted one impacted customer and found no evidence of broader exposure at that time. TechCrunch and SecurityWeek reported the incident in early May 2026.

Root cause

Unauthorized access to AWS cloud account storing customer AI provider API keys

References