2026 Braintrust — AWS account breach; customers told to rotate API keys
Data compromised
Customer API keys for cloud AI models; company said one impacted customer contacted, no broader exposure evidence at disclosure
Technical writeup
AI observability startup Braintrust detected suspicious activity on May 4, 2026 and confirmed unauthorized access to one Amazon Web Services account containing customer API keys used to reach cloud-hosted AI models. The company published a May 5 trust-center notice, locked down the account, rotated internal secrets, and emailed all customers to rotate keys stored with Braintrust out of caution—stating it had contacted one impacted customer and found no evidence of broader exposure at that time. TechCrunch and SecurityWeek reported the incident in early May 2026.
Root cause
Unauthorized access to AWS cloud account storing customer AI provider API keys