OpenAI terminated its use of the analytics platform Mixpanel after a security incident at the vendor exposed identifying information tied to OpenAI accounts. Mixpanel detected unauthorized access to part of its systems on November 9, 2025, and determined that an attacker had exported a dataset containing customer identifiable information and analytics records. Mixpanel notified OpenAI and shared the affected dataset on November 25, 2025.
The exposed fields included names supplied on API accounts, email addresses, approximate location data, operating system and browser details, referring websites, and organization or user identifiers linked to API accounts.
OpenAI stated that its own systems were not breached. Chat content, API requests, API usage data, passwords, credentials, API keys, payment details, and government identification documents were not part of the exported dataset. Impact fell on some API users along with a limited group of ChatGPT users who had submitted help center tickets or were signed in to platform.openai.com.
OpenAI ended the Mixpanel relationship rather than continuing under revised terms, and opened broader security reviews across its third party vendors.
The incident falls into a category that has grown alongside AI platform adoption. Analytics, support, and telemetry vendors sit outside the primary system boundary while still holding account level identifiers, and a compromise at that layer produces exposure without any failure inside the AI provider itself.
Source: SecurityWeek - https://www.securityweek.com/openai-user-data-exposed-in-mixpanel-hack/
