By peter.
OpenAI disclosed on Thursday, November 27, 2025, that a security breach at third-party analytics provider Mixpanel exposed limited profile data for some users of its developer platform (platform.openai.com). ChatGPT users and core OpenAI systems remain unaffected, with no compromise of passwords, API keys, payment details, chat content, or prompts.
What Happened
On November 9, 2025, Mixpanel detected unauthorized access to part of its systems via a smishing attack (phishing via SMS). An attacker exported a dataset containing customer identifiable information and analytics records. Mixpanel notified OpenAI immediately and shared the affected data on November 25 for review.
The breach was isolated to Mixpanel’s environment—used for web analytics on OpenAI’s API frontend. OpenAI has since terminated the partnership and is notifying impacted organizations, admins, and users via email.
Exposed Data
The incident affected a subset of API accounts with:
- Names and email addresses.
- Approximate (coarse) location.
- Device/OS details (e.g., browser, operating system).
- Account identifiers (e.g., organization or user IDs).
- Limited analytics (e.g., websites visited).
No sensitive data was leaked: API requests/usage, prompts, outputs, credentials, government IDs, or financial info.
Risks and Recommendations
Experts like ESET’s Jake Moore note the “low sensitivity” data could fuel phishing or social engineering attacks. OpenAI warns users to treat unexpected emails/messages with caution.
- For API Users: Monitor for suspicious activity; change passwords if reused elsewhere.
- Broader Impact: Highlights third-party risks in AI ecosystems—OpenAI emphasizes vendor accountability.
Company Responses
- OpenAI: “Transparency is important… We’re notifying all affected parties directly at [email protected].” No number of impacted users disclosed.
- Mixpanel CEO Jen Taylor: Confirmed engagement with law enforcement; communicating with all customers. The San Francisco-based firm serves 11,000+ clients.
This follows OpenAI’s 2024 internal hack (stolen AI tech data) and a fired researcher’s espionage concerns. As AI firms scale, supply-chain security remains a vulnerability.
For support, contact OpenAI at [email protected]. Stay vigilant against phishing.
#OpenAIDatabreach #MixpanelIncident #APISecurity #AIPrivacy






