logo

OpenAI discloses API customer data breach via Mixpanel vendor hack

ID: 92cebf12-5ab0-5eb7-87d1-16df45762721

STIX ID: report--92cebf12-5ab0-5eb7-87d1-16df45762721

Feed Name: Bleeping Computer

Threat Score
35/100

Date Published: 2025-11-27

Date Updated: 2026-07-17

Author: Ionut Ilascu

...
...

OpenAI notified some ChatGPT API customers that limited analytics data was exposed after a breach at third-party analytics provider Mixpanel. Mixpanel says the attack stemmed from an SMS-phishing (smishing) campaign that impacted a small number of customers and exposed items such as provided names, email addresses, coarse location, device/browser metadata, referring sites, and organization or user IDs; no API keys, passwords, payment data, or chat content were disclosed. OpenAI removed Mixpanel from production, is notifying affected users and organizations, and advises vigilance for phishing and enabling 2FA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.