Braintrust Confirms AWS Breach, Customers Urged to Rotate API Keys

Braintrust Confirms AWS Breach, Customers Urged to Rotate API Keys

First seen 9 May 2026, 10:39 UTC TechcrunchSecurityaffairs.CoRescana 87% similarity 58.5

Article Content

Browse articles
ThreatCluster

Braintrust, an AI evaluation startup, confirmed a breach involving unauthorized access to one of its AWS accounts, which contained API keys used by customers for accessing cloud-based AI models. The company notified customers to rotate their API keys as a precautionary measure. While Braintrust stated that it has contained the incident and locked down the compromised account, it is still investigating the cause of the breach. The breach may have downstream implications for customers relying on Braintrust's services. No evidence of broader exposure has been found, but the situation highlights vulnerabilities in the AI supply chain. The incident follows similar breaches in the industry, emphasizing the risks associated with cloud services. Braintrust's CEO noted that the company is taking steps to enhance security measures.

Key Points: • Braintrust confirmed unauthorized access to an AWS account containing customer API keys. • Customers have been advised to rotate their API keys to mitigate potential risks. • The breach raises concerns about security in the AI supply chain, with potential downstream impacts.

ThreatCluster AI

Timeline

2026-05-06
Braintrust confirms security breach
Braintrust disclosed unauthorized access to one of its AWS accounts, prompting a customer notification to rotate API keys.
Techcrunch
2026-05-06
Customer notification sent
An email was sent to customers urging them to revoke and replace their API keys stored with Braintrust.
Techcrunch
2026-05-09
Security incident raises supply chain concerns
The breach has been highlighted as a significant risk to the AI supply chain, affecting customers reliant on Braintrust's services.
Securityaffairs.Co

Community

Browse all →