OpenAI

OpenAI Discloses API User Data Exposure via Third-Party Mixpanel Breach


Executive Summary

OpenAI has announced a security incident originating from a breach at its third-party web analytics provider, Mixpanel. The incident was not a breach of OpenAI's own systems but resulted in the unauthorized export of limited analytics data for some users of its API product interface (platform.openai.com). The exposed information includes names, email addresses, and account metadata, but critically, does not include API keys, passwords, payment details, or any prompt/response data. In response, OpenAI has terminated its use of Mixpanel and is notifying all affected users.

Key Takeaways

* Incident Origin: The breach occurred within Mixpanel's systems, not OpenAI's infrastructure. An attacker gained unauthorized access and exported a dataset on November 9, 2025.

* Affected Audience: The incident impacted only users of the API product via `platform.openai.com`. Users of ChatGPT and other OpenAI products were not affected.

* Exposed Data: The compromised information was limited to user profile and analytics data, including:

* Name and email address associated with the API account.

* Approximate coarse location (city, state, country).

* Operating system, browser, and referring websites.

* Organization or User IDs.

* Data NOT Exposed: No sensitive data such as passwords, API keys, payment information, government IDs, chat content, or API usage data was compromised.

* Company Response: OpenAI has removed Mixpanel from its services, is directly notifying all impacted users and organizations, and is conducting expanded security reviews of its entire vendor ecosystem.

* User Recommendation: While password resets or API key rotations are not necessary, users are advised to be vigilant against potential phishing or social engineering attacks using the exposed information.

Strategic Importance

This incident highlights the significant supply-chain risk technology companies face from third-party vendors. OpenAI's transparent disclosure and swift action to terminate the vendor relationship are critical moves to maintain customer trust and underscore its commitment to security.

Original article