https://x.com/i/article/2108789427233587200
Fireworks October 2026 security incident
Fireworks identified a security incident involving unauthorized use of internal Fireworks credentials. An unauthorized third party accessed environment variables used in evaluation jobs in a limited number of customer accounts. To our knowledge, no customer data or inference traffic was accessed or impacted.
We began containment the same day and have directly notified every identified affected customer. Our investigation is ongoing. We recognize the concern and work this creates for affected customers, and we are providing account-specific information to help them respond.
We’re working with a cybersecurity expert firm to assist with the incident.
Who is affected? The incident affected a limited number of customer accounts. Affected customers received a direct email identifying the credentials requiring action.
If you have not received a notice, we have not identified your account as affected based on our investigation to date. If that changes, we will contact you directly.
What we know. Our investigation has established the following timeline (PDT):
Oct 6 9am, 2026: Fireworks identified the activity and began containment.
Oct 7 7am, 2026: Started notifying affected customers
Oct 9 4pm, 2026: Rotated all the Fireworks employee API keys
Oct 9 6pm, 2026: Notified all affected customers
Oct 9 10pm, 2026: Published bulletin
We have confirmed that environment variables, including API keys and tokens stored as secrets, were captured in affected accounts. Our review of other potential access remains ongoing:
- Models, datasets, and training data: We have not detected access. We are reviewing calls made with the exposed credentials to verify the scope.
- Live inference traffic (including prompts and outputs): We have found no evidence that any inference traffic was accessed. Additionally, note that Fireworks does not store prompts or outputs by default, as our platform is ZDR.
- Personal data: We have not identified personal data being accessed.
What we have done. We have revoked the internal credentials used in the incident, revoked exposed Fireworks API keys and keys created by the actor, and added access restrictions. We are continuing to monitor for further activity.
We are also reviewing how secrets are made available to evaluation jobs. We will share additional remediation measures as they are implemented and verified.
What affected customers should do.
1. Rotate the credentials identified in your notice. Rotate or revoke third-party credentials with the providers that issued them, then update the applications and Fireworks secrets that use them. Removing a stored secret alone does not invalidate the underlying credential. Fireworks has revoked the affected Fireworks API keys; third-party credentials require action with their issuing providers.
1. Check for unrecognized resources or activity. Review API keys, users, evaluators, training jobs, and datasets. Send us the names or IDs of anything you do not recognize so we can determine whether it is related and help you address it.
We can provide secret names and credential fingerprints through a secure channel to help you identify the exact credentials requiring rotation.
If you have not received an affected-customer notice, no incident-specific action is currently required. Contact us if you observe suspicious activity or need help confirming your account’s status.
Contact. Reply to your incident notification email or contact security@fireworks.ai.
