2025 OpenAI — Mixpanel third-party breach (API users)
Data compromised
Names, email addresses, approximate locations, OS/browser info, organization IDs
Technical writeup
Mixpanel, OpenAI's third-party analytics provider, suffered a smishing (SMS phishing) attack on November 8-9, 2025. An attacker gained unauthorized access and exported a dataset containing customer information. The breach affected OpenAI API platform users and limited ChatGPT users. Exposed data included names, email addresses, approximate locations, OS/browser info, and organization IDs. No chat content, API keys, passwords, or payment data was compromised. OpenAI terminated Mixpanel and elevated vendor security requirements.
Root cause
Third-party breach (Mixpanel); smishing attack