← Incident database

openai-mixpanel-2025 · Disclosed 2025-11-26

Mixpanel: smishing and analytics-data export affecting OpenAI users

Mixpanel reported a smishing incident; OpenAI reported export of user analytics data from the supplier. OpenAI says passwords, API keys, and chat content were not involved.

CredentialsSupply chain / CI

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Mixpanel dates smishing detection to November 8; OpenAI reports export of a dataset containing analytics data from Mixpanel.

    [s1][s2]Mixpanel: introduction / OpenAI: What happened
  • Reported fact

    Potentially affected data includes names, emails, and coarse locations; a December 19 clarification also includes some ChatGPT users, without API-key or chat-content exposure.

    [s1]December 19 clarification / What this means for you

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    Mixpanel revoked sessions, rotated credentials, and reviewed logs; OpenAI ended production use of Mixpanel and expanded supplier reviews.

    [s1][s2]Mixpanel: What we did in response / OpenAI: Our response

Evidence relevant to prevention

Operational controls to inspect

Inspect resistance to SMS-led fake logins and session revocation, plus analytics identifiers, export permissions, and retention.

Editorial assessment; not a determination of liability. [s1][s2]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

Exact entry mechanics, initial access date, and victim count are unspecified. November 8 and 9 are provider-specific detection/awareness dates rather than assigned entry dates.

Sources

  1. [s1] OpenAI · Primary source

    What to know about a recent Mixpanel security incident ↗

    Published 2025-11-26 · Reviewed 2026-10-02

  2. [s2] Mixpanel · Primary source

    Our response to a recent security incident ↗

    Published 2025-11-27 · Reviewed 2026-10-02