Other β›“ Supply Chain

TechCrunch

πŸ“… 2025-11-26 🏒 Mixpanel analytics platform (used by OpenAI)
Primary Source β†—

Incident Details

Hackers breached Mixpanel, a third-party analytics vendor used by OpenAI to track user behavior on its API platform, on November 26, 2025. The breach exposed data belonging to OpenAI API platform business customers including names, email addresses, geographic locations, and technical details about customer systems. Standard ChatGPT consumer app users were not affected. No chat content, API keys, passwords, credentials, payment details, or government IDs were compromised. OpenAI confirmed the incident was at the vendor level, not within OpenAI’s own systems. The incident highlighted that AI platform providers β€” holding sensitive data on enterprises integrating AI into products β€” are attractive targets for attackers seeking business intelligence.

Technical Details

Initial Attack Vector
CWE-284: Improper Access Control (third-party analytics vendor breach)
Vendor / Product
Mixpanel analytics platform (used by OpenAI)
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2025-11-26 Breach occurred
  2. 2025-11-27 Publicly disclosed
  3. 2025-11-27 Customers notified