OpenAI confirmed that a security incident at Mixpanel, its third-party analytics provider, led to the exposure of limited identifiable information for some users of the OpenAI API product. The breach did not affect OpenAI's core infrastructure, ChatGPT, or other products, and no sensitive data such as passwords, API keys, payment details, or chat content was compromised. The exposed data included names, email addresses, approximate locations, operating system and browser details, referring websites, and organization or user IDs associated with API accounts. OpenAI responded by removing Mixpanel from its production environment and began notifying affected users and organizations directly.
Mixpanel attributed the breach to a smishing (SMS phishing) campaign detected on November 8, 2025, which allowed unauthorized access to a portion of its systems. The company took immediate action by securing affected accounts, revoking sessions, rotating credentials, blocking malicious IPs, and engaging external cybersecurity experts for remediation. Both OpenAI and Mixpanel emphasized that only a limited subset of customers was impacted, and users not directly contacted were unaffected. OpenAI continues to investigate the incident and has terminated its use of Mixpanel for analytics on its API frontend.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
On November 27, 2025, Mixpanel published a public response describing the recent security incident and its remediation efforts. The statement formalized the company's acknowledgement of the breach and the steps taken to contain it.
In response to the incident, OpenAI removed or suspended Mixpanel from its production environments, began directly notifying affected users and organizations, and launched a review of third-party vendors. The company warned customers to watch for phishing and social engineering attempts using the exposed metadata.
On November 26, 2025, OpenAI disclosed that a breach at third-party analytics provider Mixpanel exposed limited data for a subset of API users. OpenAI said its own systems and products such as ChatGPT were not compromised.
After detecting the intrusion, Mixpanel took containment actions including securing affected accounts, blocking malicious IP addresses, resetting employee passwords, and engaging external security experts. The company also began investigating the scope and impact of the breach.
Following the compromise of Mixpanel, an attacker accessed and exported limited analytics metadata tied to some OpenAI API accounts. Exposed fields included names, email addresses, approximate locations, browser and OS details, referring websites, and organization or user IDs, but not API keys, passwords, chat logs, or payment data.
Mixpanel detected a smishing (SMS phishing) campaign on November 8, 2025, which led to unauthorized access within its environment. The incident later proved to affect customer data held for third-party clients including OpenAI.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
16 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecio.com
Open sourcesecurityonline.info
Open sourcebankinfosecurity.com
Open sourcebleepingcomputer.com
Open sourcehackread.com
Open sourcemixpanel.com
Open sourcecsoonline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.