Open AI recently sent ot a notification to users saying that they had become aware of a a recent security incident at Mixpanel, a data analytics provider that OpenAI used for web analytics on the frontend interface of their API product (platform.openai.com). The incident occurred within Mixpanel’s systems and involved limited analytics data related to your API account.
According to Open AI this was not a breach of OpenAI’s systems. No chat, API requests, API usage data, passwords, credentials, API keys, payment details, or government IDs were compromised or exposed.
Editor: Stand by for a rant! I find it incongruous that an Open AI company would take umbrance at a breach of their security allowing hackers to get in when, on the other hand, all AI companies have basically stolen all intellectual property ever released on the internet without compensation, acknowledgement or even accreditation. NOW we have the criminal complaining about the criminal.
But, back to today’s show:
Apparently on 9 November 2025, Mixpanel became aware that an attacker that gained unauthorized access to part of their systems and exported a dataset containing limited customer identifiable information and analytics information. Mixpanel notified OpenAI that they were investigating, and on November 25, 2025, they shared the affected dataset with us.
User profile information associated with use of platform.openai.com may have been included in data exported from Mixpanel.
The information that may have been affected was limited to:
- Name that was provided on the API account
- Email address associated with the API account
- Approximate coarse location based on API user browser (city, state, country)
- Operating system and browser used to access the API account
- Referring websites
- Organization or User IDs associated with the API account
Open Ai says that as part of their security investigation, we removed Mixpanel from their production services, reviewed the affected datasets, and are working closely with Mixpanel and other partners to fully understand the incident and its scope. We are in the process of notifying impacted organizations, admins, and users directly. While we have found no evidence of any effect on systems or data outside Mixpanel’s environment, we continue to monitor closely for any signs of misuse.
Trust, security, and privacy are foundational to our products, our organization, and our mission. We are committed to transparency, and are notifying all impacted customers and users. We also hold our partners and vendors accountable for the highest bar for security and privacy of their services. After reviewing this incident, OpenAI has terminated its use of Mixpanel.
Editor (again): Yup, you knew that I would not stay away! Don’t you find it funny that Mixpanel has been ‘fired’ for ‘allowing’ a breach BUT, if the shoe was on the other foot and Mixpanel had deployed a method to ‘steal’ more content that they would have been applauded?
But, here comes the legal disclaimer that puts the blame on YOU if you ever succumb to a phishing attempt that could be traced back to this breach:
The information that may have been affected here could be used as part of phishing or social engineering attacks against you or your organization.
Since names, email addresses, and OpenAI API metadata (e.g., user IDs) were included, we encourage you to remain vigilant for credible-looking phishing attempts or spam.
As a reminder:
- Treat unexpected emails or messages with caution, especially if they include links or attachments.
- Double-check that any message claiming to be from OpenAI is sent from an official OpenAI domain.
- OpenAI does not request passwords, API keys, or verification codes through email, text, or chat.
- Further protect your account by enabling multi-factor authentication.
Open Ai concluded saying; “The security and privacy of our products are paramount, and we remain resolute in protecting your information and communicating transparently when issues arise. Thank you for your continued trust in us.”
