OpenAI recently informed the public about a security incident related to third-party analytics provider Mixpanel , which was previously used to monitor activity on platform.openai.com , the frontend to the OpenAI API. The company emphasized transparency in its announcement, assuring that the breach did not affect OpenAI’s systems , nor did it affect users’ chat content , API keys, passwords, credentials, or payment information.

On November 9, 2025, Mixpanel detected unauthorized access to part of its systems, resulting in the export of an analytics dataset containing information from certain OpenAI API users.
See also: New prompt injection attack against AI browsers and browser assistants
Who was affected by the breach?
The investigation revealed that the incident only affected users of the OpenAI API, while users of ChatGPT and other OpenAI products were not affected. The data that may have been exposed includes:
- Full name as it appears on your OpenAI API account
- Email address
- Identified location (city, state, country) based on browser
- Operating system and browser
- Referral websites
- Organization or user identifiers
There was no disclosure of chat content, API keys, passwords, payment information, or government IDs.
OpenAI's reactions and measures
Immediately after being notified by Mixpanel, OpenAI removed the provider from production and began a thorough review of the data that may have been exposed. The company is also immediately notifying all organizations, administrators, and users who may have been affected.
See also: Shai-Hulud v2 campaign expands from npm to Maven
OpenAI reiterated that there is no evidence of further breaches in other systems and is actively monitoring for any potential misuse of data. In addition, the partnership with Mixpanel has been terminated, while the company is conducting enhanced security reviews with all partner suppliers, increasing protection standards at every level.

Phishing and social engineering risks
The breach highlights the need for increased user vigilance. OpenAI warns that exposed data, such as names and email addresses, could be used for phishing attempts or social engineering attacks.
Some basic guidelines include:
- Be careful of unexpected emails or messages containing links or attachments.
- Verify that all communications from OpenAI originate from official domains
- OpenAI will never ask for a password, API key, or verification code via email or chat.
- Enable multi-factor authentication (MFA) for added protection
The company emphasizes that privacy, security, and transparency remain top priorities, while continuing to openly report such incidents.

Importance of transparency in data security
The incident highlights the importance of transparency and timely notification when it comes to data breaches, especially on platforms with millions of users and critical API applications. It also highlights the challenges posed by using third-party service providers, which can be a weak link in the security chain.
See also: Malicious Prettier extension in VSCode Marketplace distributes Anivia Stealer
OpenAI is reviewing and strengthening security procedures, demonstrating that user protection is not limited to its internal systems, but also extends to partner suppliers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
With this approach, OpenAI attempts to build trust and ensure that users remain informed and protected, reducing the risk of phishing attacks and leaks of sensitive information.
