OpenAI drops Mixpanel after vendor breach exposed user data
OpenAI cut ties with analytics vendor Mixpanel after an attacker exported user names, emails and account metadata tied to platform.openai.com. No passwords, API keys or chat data were exposed.
Updated
Why it matters
- On November 9, 2025, an attacker gained unauthorized access to part of Mixpanel's systems and exported a dataset containing limited customer identifiable information and analytics data tied to OpenAI users.
- OpenAI terminated its use of Mixpanel, removed it from production services, and is elevating security requirements across its vendor ecosystem.
- No passwords, API keys, payment details, chat content, prompts, responses or API usage data were exposed; OpenAI is not recommending password resets or key rotation.
OpenAI has terminated its contract with analytics vendor Mixpanel after an attacker exported a dataset containing limited customer identifiable information and analytics data tied to users of platform.openai.com, the company disclosed in a security notice.
The incident affected some users of OpenAI's API platform and a limited number of ChatGPT users who submitted help center tickets or were logged into platform.openai.com. It was not a breach of OpenAI's own systems. No chat content, prompts, responses, API usage data, passwords, credentials, API keys, payment details, or government IDs were compromised or exposed, OpenAI said.
The stakes are significant for enterprise customers: the exposed data — names, email addresses and OpenAI API metadata such as user IDs — is exactly the raw material attackers use for targeted phishing and social engineering campaigns against developers and organizations.
What happened
On November 9, 2025, Mixpanel became aware of an attacker who had gained unauthorized access to part of its systems and exported a dataset containing limited customer identifiable information and analytics information. Mixpanel notified OpenAI that it was investigating, and on November 25, 2025, it shared the affected dataset with OpenAI.
Mixpanel served as a third-party web analytics provider for the frontend interface of OpenAI's API product, platform.openai.com, helping the company understand product usage.
What data was exposed
User profile information associated with the use of platform.openai.com may have been included in the exported data. OpenAI says the affected information was limited to:
- The name provided on the account
- The email address associated with the account
- Approximate coarse location based on the user's browser (city, state, country)
- Operating system and browser used to access the account
- Referring websites
- Organization or User IDs associated with the account
A clarification dated December 19, 2025 updated the original disclosure, which had described only "API users" as impacted, to add that "It also affected a limited number of ChatGPT users who submitted help center tickets or were logged into platform.openai.com." OpenAI said all impacted users were identified and notified at the same time as part of the original outreach, and that nothing else about its understanding of the incident, including the type of information involved, has changed.
OpenAI's response
As part of its security investigation, OpenAI removed Mixpanel from its production services, reviewed the affected datasets, and is working with Mixpanel and other partners to fully understand the incident and its scope. The company is notifying impacted organizations, admins, and users directly by email.
OpenAI has found no evidence of any effect on systems or data outside Mixpanel's environment but continues to monitor for signs of misuse. Beyond Mixpanel, the company is conducting additional and expanded security reviews across its vendor ecosystem and is elevating security requirements for all partners and vendors.
The vendor-ecosystem angle matters. This is a case where a company with some of the most scrutinized security practices in AI still inherited a data exposure through a routine analytics integration — a reminder that third-party risk now sits at the center of enterprise AI supply chains.
Why the phishing risk is the real concern
OpenAI explicitly warns that the exposed information could be weaponized. Because names, email addresses, and OpenAI API metadata such as user IDs were included, the company encourages users to remain vigilant for credible-looking phishing attempts or spam. Its guidance:
- Treat unexpected emails or messages with caution, especially if they include links or attachments
- Double-check that any message claiming to be from OpenAI comes from an official OpenAI domain
- Remember that OpenAI does not request passwords, API keys, or verification codes through email, text, or chat
- Enable multi-factor authentication to further protect the account
FAQ highlights from OpenAI's disclosure
Was this caused by a vulnerability in OpenAI's systems? No. The incident was limited to Mixpanel's systems and did not involve unauthorized access to OpenAI's infrastructure.
Was any API data, prompts, or outputs affected? No. Chat content, prompts, responses, or API usage data were not impacted.
Were passwords, API keys, or payment information exposed? No. Passwords, API keys, payment information, government IDs, and account access credentials were not impacted. OpenAI also confirmed that session tokens, authentication tokens, and other sensitive parameters for its services were not affected.
Do users need to reset passwords or rotate API keys? No. Because passwords and API keys were not affected, OpenAI is not recommending resets or key rotation in response to this incident.
Has Mixpanel been removed from OpenAI products? Yes.
Should users enable multi-factor authentication? Yes. While credentials and tokens were not impacted, OpenAI recommends all users enable MFA as a best-practice security control. For enterprises and organizations, it recommends enabling MFA at the single sign-on layer.
Users with questions or security concerns can reach OpenAI's support team at [email protected]. OpenAI says it will update its FAQ and notify users if it identifies new information that materially affects impacted users.
With Mixpanel cut from its production stack and vendor security requirements being raised across the board, the practical takeaway for developers is narrower: expect convincing phishing that already knows your name, email and OpenAI account metadata — and treat MFA as the baseline defense.
Original: platform.openai.com
More from Elena Vasquez
Show full bio
Market editor covering media and advertising at AI In Context.
122 articles