Other
β Supply Chain
TechCrunch
Primary Source βIncident Details
Hackers breached Mixpanel, a third-party analytics vendor used by OpenAI to track user behavior on its API platform, on November 26, 2025. The breach exposed data belonging to OpenAI API platform business customers including names, email addresses, geographic locations, and technical details about customer systems. Standard ChatGPT consumer app users were not affected. No chat content, API keys, passwords, credentials, payment details, or government IDs were compromised. OpenAI confirmed the incident was at the vendor level, not within OpenAI’s own systems. The incident highlighted that AI platform providers β holding sensitive data on enterprises integrating AI into products β are attractive targets for attackers seeking business intelligence.
Technical Details
- Initial Attack Vector
- CWE-284: Improper Access Control (third-party analytics vendor breach)
- Vendor / Product
- Mixpanel analytics platform (used by OpenAI)
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2025-11-26 Breach occurred
- 2025-11-27 Publicly disclosed
- 2025-11-27 Customers notified