Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (11 days ago).

← Intel index

This coverage is stale.

Last updated May 14, 2026 (about 4 months ago).

people · May 14, 2026

AI Firm Braintrust Prompts API Key Rotation After Data Breach

Share the canonical public link.

Share as image

Braintrust discovered unauthorized access to one of its AWS accounts on May 4, 2026, leading to the compromise of API keys for AI providers stored in the platform. Hackers exploited the breach to potentially access AI models used by Braintrust customers, including organizations like Box, Cloudflare, Dropbox, Notion, Ramp, and Stripe. The company locked down the affected account, audited systems, restricted access, and rotated internal secrets while notifying customers on May 5 with indicators of compromise and remediation guidance. At least one customer confirmed impact, with three others noting suspicious usage spikes in their AI provider accounts. Nudge Security CTO Jaime Blasco highlighted the supply chain risks, as AI tools aggregate credentials targeted by attackers, affecting downstream AI stacks for multiple enterprises.

The body justifies a high significance score as it details a major data breach with unauthorized access to AWS accounts, compromise of API keys affecting prominent customers like Box, Cloudflare, Dropbox, Notion, Ramp, and Stripe, and includes response actions and confirmed impacts, aligning with 'clearly major' criteria for a noteworthy security incident. Information density is high with multiple named entities (Braintrust, AWS, specific customers, Jaime Blasco), precise dates (May 4, 2026; May 5), and quantifiable impacts (one confirmed, three suspicious cases), exceeding 3 concrete specifics. Analysis value is zero since the field explicitly states '(none)', providing no strategic insight beyond the headline.

Supporting evidence