ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

OpenAI notifies API customers of data exposure linked to Mixpanel breach

OpenAI is notifying some ChatGPT API customers that limited identifying information was exposed after a security incident at Mixpanel, a third-party analytics provider used to track user interactions on the API’s frontend interface.


The breach occurred when Mixpanel detected a smishing attack on November 8 that targeted its systems. Mixpanel determined that a limited number of its customers were affected. OpenAI received details of the compromised dataset on November 25 as part of Mixpanel’s ongoing investigation.


OpenAI confirmed that the incident involved only analytics data related to certain API users and did not affect users of ChatGPT or its other products. The company stated that no chat content, API requests, usage data, passwords, credentials, API keys, payment information, or government IDs were exposed. OpenAI emphasized that the event did not involve unauthorized access to its own systems.


The exposed information may include the name provided on an API account, the associated email address, approximate coarse location based on user browser data, operating system and browser details, referring websites, and organization or user IDs tied to the account. OpenAI stated that passwords and API keys were not affected and do not need to be reset.


Some users have reported that CoinTracker, a cryptocurrency portfolio tracker and tax platform, was also impacted. In that case, the leaked dataset may include device metadata and limited transaction count information.


OpenAI has begun an investigation to determine the full scope of the incident. As a precaution, the company has removed Mixpanel from its production environment and is notifying organizations, administrators, and individual users. Although only API users were affected, OpenAI sent notices to all subscribers.


The company advised users to remain alert for phishing or social-engineering attempts that may leverage the exposed data. Messages containing links or attachments should be verified to ensure they originate from an official OpenAI domain. OpenAI also urged users to enable two-factor authentication and avoid sharing sensitive information such as passwords, API keys, or verification codes through email, text, or chat.


Mixpanel stated that all impacted customers have been contacted. The company secured affected accounts, revoked active sessions, rotated credentials, blocked the threat actor’s IP addresses, reset employee passwords, and introduced additional controls to prevent future incidents.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543