Data leak
OpenAI Mixpanel Product Analytics Data Exposure
Primary Source βIncident Details
In November 2025, OpenAI disclosed that customer data had been exposed via Mixpanel, its third-party product analytics platform. OpenAI had shared user behavioral data with Mixpanel for product improvement purposes, and the compromise of Mixpanel’s systems exposed this data. Affected information included user names, email addresses, approximate geographic location, operating system and browser information, and organizational/user identifiers. This was part of a broader Mixpanel breach that affected multiple technology companies including PornHub, Pinterest’s Shuffles app, CoinDCX, SoundCloud, SwissBorg, and CoinLedger in November-December 2025.
Technical Details
- Initial Attack Vector
- OpenAI's product analytics vendor Mixpanel was compromised, exposing behavioral and account data that OpenAI had shared with Mixpanel for product analytics purposes
- Vendor / Product
- Mixpanel (product analytics SaaS)
Timeline
- 2025-10-01 Breach occurred
- 2025-11-10 Publicly disclosed
- 2025-11-10 Customers notified