Supply chain β›“ Supply Chain

Mixpanel Product Analytics Platform Breach (Multiple Companies)

πŸ“… 2025-10-15 🏒 Mixpanel (product analytics SaaS)
Primary Source β†—

Incident Details

In late 2025, Mixpanel, a widely-used product analytics SaaS platform, suffered a breach that exposed user behavioral data from dozens of customer companies. Confirmed affected organizations include OpenAI, PornHub, Pinterest (Shuffles app), CoinDCX, SoundCloud, SwissBorg, and CoinLedger. Exposed data categories varied by company but typically included user names, email addresses, device information, browser/OS metadata, geographic location data, and in some cases sensitive behavioral data such as video viewing histories, search terms, and financial transaction types. The breach highlighted the risk of sensitive behavioral and usage data flowing to third-party analytics vendors without adequate data minimization or contractual security controls. Multiple European DPAs opened investigations into the incident.

Technical Details

Initial Attack Vector
Threat actors compromised Mixpanel's product analytics platform infrastructure, gaining access to customer behavioral and analytics data that dozens of companies had shared with Mixpanel for product improvement and user analytics purposes
Vendor / Product
Mixpanel (product analytics SaaS)
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2025-10-15 Breach occurred
  2. 2025-11-10 Publicly disclosed
  3. 2025-11-10 Customers notified