OpenAI Mixpanel Security Incident Report
OpenAI has terminated its use of Mixpanel, a third-party web analytics provider, following a security incident where an unauthorized attacker gained access to Mixpanel's systems and exported a dataset containing limited user identifiable information. This incident was not a breach of OpenAI's own infrastructure, but rather a compromise of data stored within the vendor's environment.
Technical Scope of the Incident
The security incident occurred within Mixpanel's systems, not OpenAI's. An attacker gained unauthorized access to Mixpanel's environment and exported a dataset containing customer identifiable information and analytics data. Mixpanel notified OpenAI on November 9, 2025, and provided the affected dataset for review on November 25, 2025.
Impacted User Groups
While primarily affecting users of the OpenAI API product (platform.openai.com), the incident also impacted a limited number of ChatGPT users who:
- Submitted help center tickets.
- Were logged into platform.openai.com.
Compromised Data Categories
The data exported from Mixpanel was limited to user profile information and web analytics metadata. Specifically, the affected information included:
- Account names and associated email addresses.
- Approximate coarse location (city, state, country) based on the browser.
- Operating system and browser used to access the account.
- Operating system and browser used to access the account.
- Referring websites.
- Organization or User IDs associated with the account.
Data Not Affected
OpenAI has confirmed that the following sensitive information was not compromised or exposed during this incident:
- Chat content, prompts, and API responses/outputs.
- API requests and usage data.
- API keys, passwords, and account access credentials.
- Payment details and government IDs.
- Session tokens and authentication tokens.
OpenAI's Response and Mitigation
OpenAI has taken the following actions to secure its user base and user data:
- Vendor Termination: OpenAI has completely removed Mixpanel from its production services and terminated its use of the provider.
- Investigation: OpenAI obtained the affected datasets for independent review and is monitoring for signs of misuse.
- User Notification: All impacted organizations, administrators, and users are being notified directly via email.
- Vendor Ecosystem Review: OpenAI is conducting expanded security reviews across its entire vendor ecosystem and elevating security requirements for all partners.
Security Recommendations for Users
Because passwords and API keys were not compromised, OpenAI does not recommend password resets or API key rotation. However, the exposure of names, emails, and user IDs increases the risk of targeted phishing and social engineering attacks.
Users are encouraged to remain vigilant for credible-looking phishing attempts and verify that any message claiming to be from OpenAI is sent from an official OpenAI domain. As a best practice, OpenAI recommends that all users enable multi-factor authentication (MFA), with enterprises and organizations implementing MFA at the SSO layer.