openai-mixpanel-2025 · Disclosed 2025-11-26
Mixpanel: smishing and analytics-data export affecting OpenAI users
Mixpanel reported a smishing incident; OpenAI reported export of user analytics data from the supplier. OpenAI says passwords, API keys, and chat content were not involved.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
Mixpanel dates smishing detection to November 8; OpenAI reports export of a dataset containing analytics data from Mixpanel.
- Reported fact
Potentially affected data includes names, emails, and coarse locations; a December 19 clarification also includes some ChatGPT users, without API-key or chat-content exposure.
[s1]December 19 clarification / What this means for you
Timeline
Incident disclosed. [s1]
Reported response
- Reported fact
Mixpanel revoked sessions, rotated credentials, and reviewed logs; OpenAI ended production use of Mixpanel and expanded supplier reviews.
Evidence relevant to prevention
Operational controls to inspect
Inspect resistance to SMS-led fake logins and session revocation, plus analytics identifiers, export permissions, and retention.
Editorial assessment; not a determination of liability. [s1][s2]
Unknowns and AI involvement
The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.
Exact entry mechanics, initial access date, and victim count are unspecified. November 8 and 9 are provider-specific detection/awareness dates rather than assigned entry dates.
Sources
[s1] OpenAI · Primary source
What to know about a recent Mixpanel security incident ↗Published 2025-11-26 · Reviewed 2026-10-02
[s2] Mixpanel · Primary source
Our response to a recent security incident ↗Published 2025-11-27 · Reviewed 2026-10-02