
Braintrust, a startup specializing in AI evaluation, has alerted its customers to update their API keys in light of a recent security breach. An email sent to users on Monday, which was reviewed by TechCrunch, disclosed that unauthorized access had been detected in one of its Amazon Web Services (AWS) accounts. This account contained sensitive API keys used by customers to access cloud-based AI services. The startup reassured its clients that they are working closely with only one customer impacted by the breach and have not identified any signs of wider exposure. In the communication, Braintrust emphasized the necessity for all customers to revoke and replace any API keys stored with them. On Tuesday, Braintrust updated its website to reflect the security incident, stating that they had contained the breach. They have locked the affected account, conducted an audit, restricted access across related systems, and rotated internal security measures. The investigation into the breach's cause is still ongoing. Spokesperson Martin Bergman noted that the precautionary measures taken were in response to the confirmed security incident, although he stated that there is no current evidence of a breach affecting more than the one customer. Braintrust's platform is designed to assist companies in monitoring AI models and products. Ankur Goyal, the founder and CEO, has previously described Braintrust as an “operating system for engineers developing AI software.” Earlier this year, the company secured $80 million in Series B funding, reaching a valuation of $800 million. Jaime Blasco, co-founder of cybersecurity firm Nudge Security, highlighted that this incident could have significant implications for AI companies relying on Braintrust’s services. He received the breach notification and emphasized the potential downstream effects on customers. Cybersecurity experts point out that hackers often target corporate accounts on cloud services to steal sensitive information like API keys. Once acquired, these keys allow unauthorized users to access company systems as if they were legitimate users. This breach comes in the wake of similar incidents, including a 2023 breach at CircleCI, which also prompted customers to rotate their stored secrets. Additionally, a recent report from a EU cybersecurity agency indicated that hackers stole 92 gigabytes of data from a compromised AWS account used by the European Commission, affecting multiple EU entities and numerous internal clients.
In recent years, the AI sector has been intensely focused on identifying the most advanced models. While this pursuit re...
Business Insider | Jul 25, 2026, 13:10This past week has been challenging for the stock market, driven by several significant forces that have created turbule...
CNBC | Jul 25, 2026, 20:05
In a groundbreaking move to address the critical issue of renewable energy intermittency, a small town in southern Finla...
CNBC | Jul 25, 2026, 05:35
Nvidia has successfully forged a significant partnership with South Korea's SK Hynix to secure memory supplies essential...
CNBC | Jul 25, 2026, 05:15
As the demand for expertise in artificial intelligence surges, many are seeking ways to break into this dynamic field. H...
Business Insider | Jul 26, 2026, 10:10