← Databricks

2025 Databricks — BeyondTrust notice on audit log delay tied to unauthorized workspace activity

2025 Unknown records affected Share on X

Data compromised

Workspace configuration and query activity referenced in vendor disclosure—customer data categories depend on workspace contents

Technical writeup

BeyondTrust publicly described threat activity affecting a cloud-based Databricks environment in which an actor used a stolen credential to access a Databricks workspace, removed certain IP access rules, added a malicious IP allow rule, and ran queries; BeyondTrust noted delayed availability of audit logs during initial review.

Root cause

Credential theft / unauthorized workspace administration actions (per BeyondTrust security advisory narrative)

References