Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124

[ad_1]
AI analytics startup Braintrust has urged customers to return and replace their API keys following a breach of customer privacy.
According to an email sent to customers on Monday and seen by TechCrunch, the startup confirmed “unauthorized access” in one of its Amazon Web Services (AWS) cloud accounts, which contained API keys used by customers to access cloud-based AI models.
“We have contacted one customer who was affected and so far have not found any visible evidence,” the email read.
The email asked “every customer to rotate” any API keys they store with Braintrust.
Braintrust to be revealed security incident on its website on Tuesday. “This incident occurred, and in the meantime, we have closed the compromised account, monitored and restricted access to all other systems, and updated internal privacy.”
The company said the cause of the breach is under investigation.
Braintrust spokesman Martin Bergman told TechCrunch that the company sent the email to customers “out of an abundance of caution” and that it had “confirmed security measures, but there is no evidence of a breach at this time.”
Techcrunch event
San Francisco, CA
| |
October 13-15, 2026
Braintrust provides a platform designed for companies to explore AI models and products. Founder and CEO Ankur Goyal previously told TechCrunch that Braintrust is like “a platform for AI software engineers.” Introduction earned $80 million in Series B funding around February, which cost the company at $800 million.
Jaime Blasco, co-founder of the cybersecurity startup Nudge Security who received an email warning of the breach from Braintrust, told TechCrunch that the incident could have “downstream consequences for affected customers,” such as the AI companies that rely on Braintrust.
Do you have information about breaking the law? Or another data breach? From a non-working device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.
Hackers often target corporate accounts cloud services or third-party platforms as a good way to steal confidential information, such as API keys. Once hackers get their hands on API keys, they can gain access to company or customer systems pretending to be legitimate users, without needing to log into the company they want.
CircleCI, a company that provides professional development for software developers, was hit by the same data breach in 2023, and also asked its customers to change “any secrets” they keep with the company.
Recently, the EU cybersecurity agency said hackers were able to steal 92 gigabytes of data from an AWS account used by the European Commission. The breach affected 29 other EU agencies and the data of many internal customers of the European Commission.
When you purchase through links in our articles, we can get a little work. This does not affect our authorship.
[ad_2]
Source link