AI evaluation startup Braintrusthas urged its customers to revoke and replace API keys after a data breach customer. According to an email sent to customers on Monday, the startup confirmed “unauthorized access” to one of its Amazon Web Services cloud. The account in question contained API keys used by customers to access cloud-based AI models.

“We have reached out to one affected customer and so far have found no evidence of a wider exposure,” the email said. The email asked “each customer to change” any API keys they store with Braintrust.
Braintrust disclosed the security incident on its website on Tuesday.
“The incident has been contained, and in the meantime, we have locked the compromised account, checked and restricted access to related systems, and changed internal secrets“.
See also: MuddyWater uses Chaos ransomware for “cover”
The company said the cause of the breach is under investigation. Braintrust spokesperson Martin Bergmantold TechCrunch that the company sent the email to customers “out of an abundance of caution” and that it “has confirmed a security incident, but there is no evidence of a breach at this time.”
How does Braintrust work?
Braintrust provides a platform designed for companies to track AI models and products. Founder and CEO Ankur Goyal has described the company as “anoperating system for engineers building AI software.”
The startup raised $80 million in a Series B funding round in February, which valued the company at $800 million.

Jaime Blasco, co-founder of cybersecurity startup Nudge Security, which received a breach notification from Braintrust, told TechCrunch that the incident could have “significant implications for affected customers,” such as AI companies that rely on Braintrust.
Hackers often target corporate accounts on cloud services or third-party platforms so they can steal secrets, such as API keys. Once attackers gain access to API keys, they can log into corporate or customer systems impersonating legitimate users, without having to break into the targeted company's systems.
See also: DAEMON Tools Supply Chain Attack: Government organizations targeted
The Braintrust incident is yet another reminder that, in the era of artificial intelligence and cloud-native services, the security of API keys has become a critical factor for business continuity. As more and more companies rely on third-party platforms to develop, evaluate, and manage AI models, a breach at one intermediary provider can have ripple effects across the entire digital ecosystem. Even though Braintrust claims that there is no evidence of widespread exposure (so far), the precautionary recommendation to immediately replace access keys demonstrates the seriousness of such incidents.
At the same time, the case highlights a broader challenge for the rapidly expanding space of enterprise AI: the speed of development and adoption of new tools often exceeds the maturity of the security mechanisms that accompany them. With API keys essentially constituting the “passport” to access critical infrastructure and high-value models, protecting them now requires stricter management practices, continuous monitoring and zero-trust architectures. The Braintrust incident shows that, as the AI market grows and attracts huge investments, it will become a prime target for high-impact cyberattacks.

Similar incidents
CircleCI companythat provides development products for software engineers, suffered a similar data breach in 2023 and asked its customers to change “all secrets” they store with the company.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Chinese UAT-8302 hackers target governments with custom malware
More recently, a European cybersecurity agency said hackers managed to steal 92 gigabytes of data from a compromised Amazon Web Services (AWS) account used by the European Commission.
The breach affected 29 other EU entities and the data of dozens of internal European Commission clients.
