HomeSecurityChatGPT data leak and new cyberattacks

ChatGPT data leak and new cyberattacks

ChatGPT has been at the center of a new data leak via Mixpanel, while serious cybersecurity incidents including an Android rootkit and a ransomware attack on water facilities have been reported. These incidents highlight the growing threats in the space of artificial intelligence and critical infrastructure, raising concerns about the security of the personal data of millions of users worldwide.

See also: OpenAI fixes data extraction vulnerability in ChatGPT

ChatGPT

The most recent security breach involving ChatGPT stemmed from a breach of Mixpanel, a third-party analytics company that OpenAI uses to track usage of its services. Attackers gained unauthorized access to Mixpanel’s systems on November 9, 2025, with the breach being publicly disclosed on November 26. The exposed data includes names, email addresses, approximate location, browser and operating system information, as well as OpenAI organization and API user identifiers. The scale of the breach affected thousands of users using OpenAI’s enterprise services.

Importantly, the breach did not affect ChatGPT user conversations, API requests, passwords, API keys, or payment information. However, the incident highlights the risks of using third-party services to process sensitive data, especially in an era where AI companies are collecting vast amounts of information to improve their algorithms. OpenAI immediately suspended its partnership with Mixpanel and initiated broader security audits across its supplier ecosystem, implementing stricter security criteria for future partnerships.

See also: NoVoice: New Android malware on Google Play

ChatGPT data leak and new cyberattacks

Android rootkits and attacks on critical infrastructure

In addition to threats to artificial intelligence, a new Android rootkit threatens the stability of mobile devices, exploiting vulnerabilities in the operating system to gain privileged access and remain hidden from detection systems. At the same time, a ransomware attack hit water facilities, highlighting the increasing targeting of critical infrastructure by cybercriminals seeking maximum impact and financial gain. These incidents demonstrate that cybersecurity threats are rapidly evolving and target both consumer and industrial applications, creating risks to public health and safety.

Additionally, a critical vulnerability was identified in Symantec that could allow attackers to bypass protection mechanisms, while Apple added an anti-ClickFix mechanism to macOS to protect against malicious attacks that exploit fake repair messages. The FBI categorized a recent breach as a significant incident, indicating the escalation of cyber threats at the government level and the need for a coordinated national response.

Advanced protection techniques and security recommendations

Security experts emphasize that companies should implement stricter data minimization policies and anonymize customer information before sending it to external vendors. Every piece of identifiable data sent externally creates an additional point of potential exposure. Organizations should conduct regular security audits of all third-party integrations, implement data encryption at all stages of processing, and create strict data-sharing agreements with clear liability and indemnification terms.

See also: ChatGPT available on Apple CarPlay with voice control

ChatGPT data leak and new cyberattacks

To protect users, it is recommended to enable multi-factor authentication on all AI service accounts, avoid entering sensitive or proprietary information into ChatGPT, and regularly monitor accounts for unauthorized access. Organizations should limit the use of ChatGPT for handling sensitive data until their security posture is improved, implement prompt injection detection and prevention mechanisms, and monitor for Firebase misconfigurations in mobile and web applications.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS