Braintrust, an AI evaluation startup, confirmed unauthorized access to one of its Amazon Web Services accounts that stored customer secrets and urged all customers to revoke and rotate organization-level AI provider API keys kept on the platform. The company said it detected suspicious activity on May 4, locked down the affected account, restricted access across related systems, rotated internal secrets, and brought in incident response specialists while the root cause remains under investigation.
Braintrust said one customer has been confirmed affected, while three others reported suspicious spikes in AI provider usage that are still being investigated. The company shared indicators of compromise and remediation guidance with customers and said it plans to add controls such as timestamps and user attribution for API key changes. The incident highlights the downstream risk of stolen AI service credentials, which can let attackers consume cloud-based AI models as apparently legitimate users and deepen concerns about AI supply-chain and SaaS exposure.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
Braintrust said it had confirmed one affected customer following the breach. It also noted that three additional customers had reported suspicious spikes in AI provider usage that were still under investigation.
Dragos publicly analyzed the January 2026 Monterrey water utility intrusion, concluding that generative AI accelerated reconnaissance and targeting but did not provide novel offensive capability. The report highlighted that segmentation and password hygiene appeared to prevent compromise of the OT interface.
Braintrust disclosed the security incident to customers and advised them to revoke and rotate any organization-level AI provider API keys stored with the platform. The company also shared indicators of compromise and remediation guidance.
After detecting the intrusion, Braintrust locked down the affected AWS account, audited and restricted access across related systems, rotated internal secrets, and engaged incident response experts. The root cause remained under investigation.
Braintrust detected suspicious activity in one of its Amazon Web Services accounts on May 4, 2026. The affected account stored customer secrets, including organization-level AI provider API keys.
During the January 2026 intrusion, the attacker used Claude and ChatGPT to analyze the environment and identify a vNode industrial gateway as a high-value OT-related target. The subsequent password-spraying attempt failed, and the campaign resulted in data theft rather than operational disruption.
In January 2026, an unidentified attacker compromised the enterprise IT environment of Servicios de Agua y Drenaje de Monterrey in Mexico. The intrusion preceded attempts to identify and reach OT-adjacent assets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcegovinfosecurity.com
Open sourcetechcrunch.com
Open source5943619.hs-sites.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.