Fireworks AI, a platform that runs AI models for developers, says an unauthorized third party “accessed environment variables used in evaluation jobs in a limited number of customer accounts” [1]. It says it identified the incident on 6 October and that it involved “unauthorized use of internal Fireworks credentials” [1].
Confirmed: Fireworks’ own bulletin. Scope and what it has not found are company statements; the review continues.
What Fireworks says
- What was taken. “We believe that environment variables, including API keys and tokens stored as secrets, were captured in certain affected accounts” [1].
- What it has not found. Fireworks says it has “not detected evidence of unauthorized access to customer models, datasets, training data, inference traffic (including prompts and outputs), or personal information within the Fireworks security perimeter or control” [1].
- Timeline (bulletin times are Pacific; London is 8 hours ahead). Containment began 6 October, 9am (5pm London). Customer notices began 7 October. The bulletin went up 9 October, 10pm (6am London on 10 October). On 10 October Fireworks revoked more user API keys and rotated service-account tokens; rotation is continuing. Last updated 10 October, 11:16am Pacific; status “Active monitoring”; working with “a cybersecurity expert firm” [1].
In plain words
An API key is a password-like string that lets software use a service as you. Environment variables are settings kept outside the code; “secrets” hold keys or tokens. Evaluation jobs, in TSN’s gloss, are test runs that score an AI model. Keys stored there for other services can work outside Fireworks.
What customers should do
Only affected customers got an email; for everyone else “no incident-specific action is currently required” [1]. If you got one: replace revoked Fireworks keys and rotate listed third-party credentials with their issuers. Fireworks warns: “Removing a stored secret alone does not invalidate the underlying credential” [1]. Check those providers’ logs and look for unrecognised keys, users or datasets [1]. TSN’s general advice, not Fireworks’: give each key the least access it needs.
What is not known
- How many accounts. “A limited number” is all it says.
- How the credentials were obtained. The bulletin gives no cause and names no one.
- What the keys could reach. That depends on each customer’s setup.
- Whether customer data was touched. Fireworks is still reviewing “calls made with the exposed credentials” [1], and its not-detected finding covers only what is “within the Fireworks security perimeter or control”.
- Independent confirmation. TSN found no outside reporting, only copies of the bulletin.
Sources
- Fireworks AI, “Fireworks October 2026 security incident”, security bulletin, published 9 October 2026 (10pm Pacific), last updated 10 October 2026, 11:16 PDT. https://fireworks.ai/security/bulletins/october-2026-security-incident
Related stories
- White House Super Intelligence Force Says AI Companies Must Report Security Incidents and Remedy Harm; Axios Says Enforcement Is Not Spelled Out
- Anthropic Says Claude Acted on Real Websites During Tests, and Has Cut Live Internet From Its Internal Evaluations
- AI Agent Security: A Hijacked SDK Goes After Agent Keys as Copilot, Bitdefender and Citadel Add Guardrails
- Japan’s Commune Confirms About 307,000 Community Members’ Data Leaked; Sansan and Panasonic Say Their Forums Were Hit
- Cyber Breaches, 9 October 2026: A Biotech’s Old Cloud, a Turkish University and a Louisiana Clinic






