Safety & Security

Mixpanel breach exposed OpenAI API user names, emails and location data

An attacker exported OpenAI API user names, emails and coarse location data from Mixpanel on November 9, 2025. No chats, API keys or credentials were exposed, and OpenAI has dropped Mixpanel.

Mixpanel security incident: what OpenAI users need to know
Mixpanel security incident: what OpenAI users need to knowseanrnicholson / Openverse
By Sophie Lindqvist5 min read

Updated

Why it matters

  • On November 9, 2025, an attacker gained unauthorized access to part of Mixpanel's systems and exported a dataset with limited identifiable information on OpenAI API platform users, plus some ChatGPT help center users.
  • Exposed data was limited to names, emails, coarse browser-based location, OS and browser details, referring websites, and organization or user IDs — no chats, prompts, API keys, passwords, payment details or tokens were compromised.
  • OpenAI has terminated its use of Mixpanel, is notifying all impacted users directly, recommends enabling multi-factor authentication, and does not advise password resets or API key rotation.

An attacker gained unauthorized access to part of Mixpanel's systems on November 9, 2025, and exported a dataset containing limited customer identifiable information and analytics data related to users of OpenAI's API platform. OpenAI disclosed the incident publicly and confirmed it has terminated its use of Mixpanel entirely.

The breach occurred entirely within Mixpanel's environment, according to OpenAI. Mixpanel served as a third-party web analytics provider for the frontend interface of OpenAI's API product, platform.openai.com. OpenAI stressed that the incident was not a breach of its own systems. "This was not a breach of OpenAI's systems," the company stated. "No chat, API requests, API usage data, passwords, credentials, API keys, payment details, or government IDs were compromised or exposed."

What happened, and when

The timeline matters here. Mixpanel became aware of the attacker on November 9, 2025, and notified OpenAI that it was investigating. On November 25, 2025, Mixpanel shared the affected dataset with OpenAI. OpenAI then reviewed the data, removed Mixpanel from its production services, and began notifying impacted organizations, admins, and users directly.

On December 19, 2025, OpenAI updated its disclosure to clarify who was affected. The original blog post said only "API users" were impacted. The corrected version adds: "It also affected a limited number of ChatGPT users who submitted help center tickets or were logged into platform.openai.com." OpenAI says all impacted users were identified and notified at the same time as part of the original outreach, and that nothing else about its understanding of the incident — including the type of information involved — has changed.

What data was exposed

The exposed information was limited to user profile information associated with the use of platform.openai.com. Specifically, the dataset may have included:

  • The name provided on the account
  • The email address associated with the account
  • Approximate coarse location based on the user's browser (city, state, country)
  • Operating system and browser used to access the account
  • Referring websites
  • Organization or User IDs associated with the account

That is identifying metadata, not content. OpenAI confirmed that chat content, prompts, responses, and API usage data were not affected. It also confirmed that session tokens, authentication tokens, and other sensitive parameters for OpenAI services were not impacted. Passwords, API keys, payment information, government IDs, and account access credentials were all excluded from the breach.

Because of that, OpenAI is not recommending password resets or API key rotation in response to this incident.

Why this matters

The incident is a reminder that third-party vendors remain one of the most common paths for data exposure at large AI companies, even when the company's own infrastructure holds firm. OpenAI positioned the event as evidence of that principle. "We also hold our partners and vendors accountable for the highest bar for security and privacy of their services," the company wrote. "After reviewing this incident, OpenAI has terminated its use of Mixpanel."

The company is going beyond the single vendor. OpenAI says it is conducting additional and expanded security reviews across its entire vendor ecosystem and elevating security requirements for all partners and vendors.

While OpenAI found no evidence of any effect on systems or data outside Mixpanel's environment, it continues to monitor for signs of misuse. It has obtained the impacted datasets for independent review and remains in contact with Mixpanel on further response actions.

The phishing risk is the real takeaway

For affected users, the practical danger is not the data itself but what attackers can do with it. OpenAI was blunt about this: "The information that may have been affected here could be used as part of phishing or social engineering attacks against you or your organization."

Because names, email addresses, and OpenAI API metadata such as user IDs were included, attackers could craft convincing, personalized phishing messages that appear to come from OpenAI and reference legitimate account details. OpenAI's guidance is specific:

  • Treat unexpected emails or messages with caution, especially if they include links or attachments.
  • Double-check that any message claiming to be from OpenAI is sent from an official OpenAI domain.
  • Remember that OpenAI does not request passwords, API keys, or verification codes through email, text, or chat.
  • Enable multi-factor authentication as an additional layer of protection.

On the MFA point, OpenAI goes further for organizations: it recommends that enterprises enable MFA at the single sign-on layer, even though account credentials and tokens were not compromised in this incident.

How users will know if they were affected

OpenAI is notifying impacted individuals and organizations directly via email, either to the user or to the organization admin. Users with questions, concerns, or security issues can reach OpenAI's support team at [email protected]. The company has committed to updating its FAQ and keeping affected users informed if it identifies new information that materially changes the picture.

For developers and enterprises building on the OpenAI API, the incident settles the most urgent questions: no API keys, no prompts, no outputs, and no credentials were exposed. The residual risk is operational rather than technical — attackers now hold verified names, emails, and account metadata for a slice of OpenAI's developer base, which makes targeted phishing the most likely follow-on threat. OpenAI's decision to cut Mixpanel and raise the bar across its vendor base signals that the company expects its partners' security to match its own, and future vendor disclosures from OpenAI will be measured against that standard.

Original: platform.openai.com

Share this article:

More from Sophie Lindqvist

Sophie Lindqvist

Show full bio

Staff writer covering marketplaces and e-commerce at AI In Context.

115 articles

Related articles

  1. OpenAI drops Mixpanel after vendor breach exposed user data
  2. OpenAI models broke out of isolation and breached Hugging Face

« Previous articleNext article »