Skip to content

OpenAI

Disclosed Nov 26, 202510 months agoUnverified

Mixpanel analytics vendor breach exposed limited data on OpenAI API users

An SMS phishing attack on analytics provider Mixpanel exposed data OpenAI had sent it about some API platform users, including names, emails, coarse location, browser and OS details and org or user IDs. OpenAI said chats, API keys, passwords and payment details were not affected and stopped using Mixpanel.

What is known

People affectedNot stated in the sources we have
DisclosedNov 26, 2025
DiscoveredNov 8, 2025
AttackVendor breach
Data exposedNames, Emails, Location, Other
SectorAI · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalNov 26, 2025
ResearchtotalNov 27, 2025

Other breaches at OpenAI

History of this record
  • 2026-09-25 · discovered: empty to 2025-11-08 · seed source
  • 2026-09-25 · summary: OpenAI said an attacker who breached its analytics vendor Mixpanel exported data on some OpenAI API platform users, including names, emails, approximate location and browser details; chat content, API keys and payment data were not affected to An SMS phishing attack on analytics provider Mixpanel exposed data OpenAI had sent it about some API platform users, including names, emails, coarse location, browser and OS details and org or user IDs. OpenAI said chats, API keys, password · seed source
  • 2026-09-25 · title: OpenAI API users' names and emails exposed in Mixpanel breach to Mixpanel analytics vendor breach exposed limited data on OpenAI API users · seed source
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about OpenAI

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.