PSA: OpenAI is notifying all users of a data breach, but you probably aren't affected
If you receive a notification from ChatGPT provider OpenAI that one of its partners has suffered a data breach , it’s likely that your own data is safe. Only those who have an API account may have been affected
The company shared the information on its website .
Transparency is important to us, so we want to inform you a recent security incident at Mixpanel, a data analytics provider OpenAI used for web analytics on the frontend interface for our API product (platform.openai.com).
Bleeping Computer reports that OpenAI is notifying all users despite the fact that most will not be impacted.
OpenAI has started an investigation to determine the full scope of the incident. As a precaution, it has removed Mixpanel from its production services and is notifying organizations, administrators, and individual users directly.
The company stresses that its own systems were not accessed and that no ordinary user data was exposed.
This was not a breach of OpenAI’s systems. No chat, API requests, API usage data, passwords, credentials, API keys, payment details, or government IDs were compromised or exposed.
Even for API account holders, limited data was compromised.
User profile information associated with the use of platform.openai.com may have been included in data exported from Mixpanel. The information that may have been affected was limited to:
Apple may have been included in the breach, but no customer data will have been exposed.
If you’re not sure whether you could be affected by this, then you’re not: API account holders will know who they are. It is, however, heartening to see a company being so completely transparent a data breach.
Photo by Solen Feyissa on Unsplash
Check out 9to5Mac on YouTube for more Apple news:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
