
Brain Trust AI Platform Suffers Data Breach Exposing Customer API Keys
An AI evaluation and observability platform called Brain Trust detected a data breach on May 4, 2024, after identifying suspicious activity in an internal AWS account, prompting the company to notify customers on May 5 to rotate potentially compromised API keys. The breach likely exposed API keys stored for AI-forward companies such as Box, Cloudflare, Dropbox, Notion, Ramp, and Stripe, with at least one customer confirmed affected and three others reporting unusual spikes in AI provider usage. Brain Trust responded by locking down the compromised account, auditing related systems, restricting access, and rotating internal secrets while providing indicators of compromise (IoCs) and remediation steps to customers. The incident highlights emerging supply chain risks, as AI tools increasingly act as "credential warehouses" targeted by attackers, according to security expert Jamie Blasco. The video also recommends implementing low-cost security measures like honey tokens—fake accounts or data designed to trigger alerts if accessed—to detect unauthorized activity early. Companies using AI systems are urged to evaluate vendor security practices and enforce policies on data input to mitigate risks of sensitive information exposure.