Skip to content
OpenAI Confirms Data Exposure After Mixpanel Breach; API Users Warned Of Phishing Risks

OpenAI Confirms Data Exposure After Mixpanel Breach; API Users Warned Of Phishing Risks

In.Mashable • November 27, 2025

OpenAI has revealed that a security incident at Mixpanel, one of its external analytics providers, led to limited information some API users being exposed. The company stressed that its own systems were not breached, and that ChatGPT users and their data remain completely unaffected. The issue occurred entirely within Mixpanel’s environment when an attacker gained access to its internal systems earlier this month and exported a dataset. OpenAI was informed of the breach and received the affected data on November 25.

The information involved was basic profile-level data connected to API accounts. This includes names associated with the accounts, email addresses, approximate geographic location, the type of device and browser used, and certain account identifiers. OpenAI made it clear that none of the exposed data included chat logs, prompts, passwords, API keys, payment details, or any sensitive information that could compromise an account directly. It was the kind of analytics metadata typically gathered to understand how customers use API products, but the company acknowledged that such details can still be exploited for phishing attempts.

⚠️ @OpenAI x @Mixpanel Data Breach: The Hidden Dangers of a Unified Ecosystem While they claim API Keys remained secure, User IDs, emails, and Org IDs were all exposed. For the vast majority of users, the API platform and ChatGPT a Unified Login system. This means… pic.twitter.com/1UOKY7LWXB — Under Construction42 (@Clo0oOoud) November 27, 2025

In response, OpenAI has removed Mixpanel from all production services and will no longer rely on the platform. The company is now reaching out directly to every impacted user, administrator and organisation. OpenAI described trust and privacy as core pillars of its mission, adding that it expects its partners to uphold the same level of security. Following this incident, the company has begun expanding its review of third-party vendors and plans to significantly raise security requirements for all external partners.

Even though the leaked data is limited, OpenAI is urging users to remain cautious. Emails paired with API-related identifiers could potentially be used to craft convincing phishing messages. Users have been advised to be skeptical of any unexpected communication that appears to come from OpenAI or that directs them to click links or download attachments. The company reiterated that it will never request passwords, API keys or verification codes through email, text or chat, and encouraged account owners to enable multi-factor authentication as an added layer of protection.

The Mixpanel incident serves as another reminder of how vulnerable technology ecosystems can be through third-party services, even when core systems remain secure. While no direct breach occurred within OpenAI’s infrastructure, the event underscores the growing need for tighter oversight of external analytics tools and data processors in an increasingly interconnected digital landscape.

SEE ALSO: AI-Generated Fake GTA 6 'Leaks' Go Viral On X, Misleads Millions Of Fans

Extracted Entities

Attack Types (2)

Companies (1)

MITRE ATT&CK (1)