Cyber Incident Victim: Braintrust
Timeline
Summary
Braintrust detected unauthorized access to an AWS account storing customer API keys, promptly locked down the account, rotated internal credentials, and notified affected users. The breach resulted in one confirmed customer impact and three additional customers under investigation for unusual AI usage spikes, with no evidence of broader data exfiltration. Investigation points to compromised cloud credentials consistent with MITRE ATT&CK T1078.004, and the company has engaged incident response experts while implementing further safeguards.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On May 4, 2026, Braintrust detected unauthorized access to one of its Amazon Web Services cloud accounts that contained customer API keys. Upon detection, the company immediately locked down the affected AWS account and restricted access to related systems. Braintrust also rotated all internal credentials associated with the compromised account. The initial access vector has not been publicly disclosed, but the response actions indicate a compromise of cloud credentials. The incident was identified through monitoring of suspicious activity within the cloud environment. No malware deployment or persistence mechanisms were observed at the time of detection.

Braintrust notified its customers on May 5, 2026, advising them to revoke and regenerate any API keys stored with the platform. As of the latest verified reports, only one customer has been confirmed as directly affected by the breach. Three additional customers reported unusual spikes in their AI provider usage, which are under investigation. There is no evidence of broader exposure or data exfiltration from the compromised account. The breach did not result in the loss of other customer data beyond the API keys stored in the affected AWS account.
In response to the incident, Braintrust engaged external incident response experts to assist with the investigation and conducted a comprehensive audit of the affected systems. The company also began implementing additional safeguards, including timestamps and user attribution for API key changes, to improve detection of future unauthorized access. Braintrust provided customers with indicators of compromise and remediation guidance as part of its notification process. The cause of the breach remains under investigation, and the company continues to monitor for any further anomalous activity. No specific threat actor has been attributed to the incident at this time.