OpenAI Confirms Data Breach at Analytics Partner Mixpanel, API Users Affected

Reviewed byNidhi Govil

9 Sources

Share

OpenAI disclosed a security incident involving third-party analytics provider Mixpanel that exposed limited user data from its API platform. The breach affected only developers using OpenAI's API services, not regular ChatGPT users.

Breach Details and Timeline

OpenAI has confirmed a security incident involving third-party analytics provider Mixpanel that resulted in the exposure of limited user data from its API platform. The breach was discovered on November 9, 2024, when Mixpanel became aware that an unknown attacker had gained unauthorized access to part of its systems and exported a dataset containing customer-identifiable information

1

. Mixpanel notified OpenAI of the investigation and shared the affected dataset on November 25, with OpenAI beginning to notify customers the following day

2

.

Source: Digit

Source: Digit

The exposed data included names provided on API accounts, email addresses associated with those accounts, approximate location data derived from browser information, operating system and browser types, referring websites, and organization or user IDs

3

. Importantly, OpenAI emphasized that no chat conversations, API requests, passwords, credentials, API keys, payment details, or government IDs were compromised or exposed

4

.

Impact on Users

The breach specifically affected only users of platform.openai.com, OpenAI's API interface used by software developers to integrate AI functionality into their products. Regular ChatGPT users were not impacted by this incident

2

. OpenAI clarified that this was not a breach of its own systems, but rather a security incident at Mixpanel, which provided web analytics services for the API platform

1

.

Security experts warn that the combination of exposed data creates conditions for convincing social engineering attacks. Miguel Fornes from Surfshark explained that when seemingly simple details like email addresses and locations are combined with other publicly available information, they can "ripple through a person's entire digital life"

5

. OpenAI has advised affected users to remain vigilant against phishing attempts and emphasized that the company never requests passwords or API keys via email or chat

3

.

Company Response and Security Measures

Following the incident, OpenAI immediately terminated its relationship with Mixpanel and removed the analytics provider from its production services

4

. The company is conducting "additional and expanded security reviews across our vendor ecosystem" and elevating security requirements for all partners and vendors

1

.

Source: Decrypt

Source: Decrypt

Because passwords and API keys were not compromised, OpenAI is not recommending password resets or key rotation. However, the company has advised all users to enable multi-factor authentication as a best-practice security control

5

. Some OpenAI customers expressed frustration on social media about the revelation that a third-party service had access to their information, with one user questioning why their name and email address needed to be shared with Mixpanel [3](https://decrypt.co/350376/openai-confirms-data-breach-heres-whos-impacted].

Today's Top Stories

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo