Skip to content

Braintrust

Disclosed May 4, 20264 months agoConfirmed

Official notice

AI evaluation startup's AWS account breach exposed stored customer AI API keys

Braintrust confirmed unauthorized access to one of its AWS accounts that held API keys customers use to reach cloud AI models, and told every customer to rotate stored keys. It said one customer was known to be affected.

What is known

People affectedNot stated in the sources we have
DisclosedMay 4, 2026
AttackHacking
Data exposedAPI keys
SectorAI · US
StatusConfirmed

Sources

Source
AI evaluation startup Braintrust confirms breach, tells every customer to rotate sensitive keystechcrunch.com · News
Braintrust trust center updatestrust.braintrust.dev · Official notice

Notices filed

WhereFiledPeople
ResearchtotalMay 4
ResearchtotalMay 5
History of this record
  • 2026-09-25 · disclosed: 2026-05-05 to 2026-05-04 · seed source
  • 2026-09-25 · summary: AI evaluation platform Braintrust said an unauthorized party accessed an AWS account storing customers' API keys for cloud AI models, with one customer confirmed impacted. It rotated internal secrets and told every customer to rotate keys. to Braintrust confirmed unauthorized access to one of its AWS accounts that held API keys customers use to reach cloud AI models, and told every customer to rotate stored keys. It said one customer was known to be affected. · seed source
  • 2026-09-25 · title: AI eval startup Braintrust tells all customers to rotate AI API keys after AWS breach to AI evaluation startup's AWS account breach exposed stored customer AI API keys · seed source
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Braintrust

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.