OpenAI Confirms Data Breach—Here's Who Is Impacted
## OpenAI Confirms Mixpanel Data Breach Earlier this month, a security problem at Mixpanel, a product analytics service, led to exposure of certain OpenAI API user metadata. OpenAI has confirmed this breach and advised users to stay alert for phishing threats. ### Details of the Incident - On November 8, an unauthorized party accessed parts of Mixpanel's systems. - The attackers exported a dataset with user profile information tied to OpenAI's API, such as the following: - Names used in API accounts. - Email addresses linked to API accounts. - Approximate location data from IP and browser info. - Browser and operating system details. - Referring websites and organizations/user IDs. > "Transparency is important to us, so we want to inform you about a recent security incident at Mixpanel, a data analytics provider that OpenAI used for web analytics on the frontend interface for our API product (platform.openai.com). The incident occurred within Mixpanel's systems and involved limited analytics data related to your API account." ### What Was Not Compromised OpenAI has specified that the following sensitive information was **not** exposed: - Chat content and API usage data. - Passwords or API keys. - Payment details or government identification. ### OpenAI's Response - OpenAI stopped using Mixpanel in their production systems while investigating. - The company is collaborating with Mixpanel and carrying out additional security reviews with all partners. - OpenAI emphasized that only API accounts on platform.openai.com were impacted, not standard ChatGPT users. ### Risks and Recommendations - The leaked metadata increases risk for phishing and social engineering attacks. - OpenAI urges affected users to be extra cautious and monitor communications for suspicious activity. ## Author's Summary OpenAI confirmed a third-party breach at Mixpanel exposed API user metadata but not sensitive content or credentials, warning customers to stay vigilant against phishing attacks.

more

Decrypt Decrypt — 2025-11-29

More News