2025 Databricks — BeyondTrust notice on audit log delay tied to unauthorized workspace activity
Data compromised
Workspace configuration and query activity referenced in vendor disclosure—customer data categories depend on workspace contents
Technical writeup
BeyondTrust publicly described threat activity affecting a cloud-based Databricks environment in which an actor used a stolen credential to access a Databricks workspace, removed certain IP access rules, added a malicious IP allow rule, and ran queries; BeyondTrust noted delayed availability of audit logs during initial review.
Root cause
Credential theft / unauthorized workspace administration actions (per BeyondTrust security advisory narrative)