Briefly
Mixpanel mentioned an attacker accessed a part of its programs and exported customer-identifiable metadata.
OpenAI mentioned no prompts, API keys, fee info, or authentication tokens had been concerned.
Each corporations reviewed the incident, notified affected customers, and outlined new safety steps.
A breach at analytics supplier Mixpanel earlier this month uncovered account names, electronic mail addresses, and browser places for some customers of OpenAI’s API, the AI large confirmed Wednesday, elevating issues that cybercriminals may use the stolen metadata in focused phishing makes an attempt.
In keeping with Mixpanel, on November 8, an unknown attacker gained entry to a part of its programs and exported a dataset containing customer-identifiable metadata and analytics info. The stolen information included usernames, electronic mail addresses, approximate browser-based location, working system, and browser particulars.
OpenAI mentioned the breach didn’t embody customers’ prompts, API keys, fee info, or authentication tokens.
Solely information from customers who accessed OpenAI’s tech by way of the API—aka, by way of exterior apps powered by GPT—was leaked, the corporate mentioned. In different phrases, if you happen to entry the ChatGPT chatbot instantly from OpenAI’s web site, you then will not be impacted right here.
“As a part of our safety investigation, we eliminated Mixpanel from our manufacturing providers, reviewed the affected datasets, and are working carefully with Mixpanel and different companions to completely perceive the incident and its scope,” OpenAI mentioned in a press release.
Based in 2009, the San Francisco-based Mixpanel is a product analytics platform used to trace person habits throughout internet and cellular purposes. The corporate mentioned it detected the “smishing” marketing campaign, and after an preliminary investigation and response, alerted OpenAI the following day.
“We’re dedicated to transparency, and are notifying all impacted clients and customers,” OpenAI mentioned. “We additionally maintain our companions and distributors accountable for the very best bar for safety and privateness of their providers.”
Smishing is a sort of phishing assault performed via SMS messages. In keeping with an October report by infrastructure administration firm Spacelift, smishing accounted for 39% of all cellular threats in 2024.
Mixpanel mentioned it secured affected accounts, revoked energetic classes, rotated compromised credentials, and blocked malicious IP addresses. The corporate additionally reset worker passwords, employed exterior cybersecurity corporations, and reviewed authentication, session, and export logs.
After the breach, Mixpanel mentioned it started notifying impacted clients in regards to the incident.
“When you have not heard from us instantly, you weren’t impacted,” Mixpanel CEO Jen Taylor mentioned in a press release. “We proceed to prioritize safety as a core tenet of our firm, merchandise, and providers. We’re dedicated to supporting our clients and speaking transparently about this incident.”
Regardless of Mixpanel’s reporting of the incident to OpenAI, the ChatGPT developer mentioned it was chopping ties with the analytics agency. “After reviewing this incident, OpenAI has terminated its use of Mixpanel,” they wrote.
Some OpenAI clients took to social media to precise frustration with the revelation {that a} third-party service had entry to their info.
“I am not very glad about this. […] Why did they should move on my identify and electronic mail handle to Mixpanel?” one person wrote on X. “I’m only a hobbyist attempting to make small experiments.”
“OpenAI sending names and emails to a 3rd social gathering analytics platform (Mixpanel) feels wildly irresponsible,” one other wrote.
OpenAI and Mixpanel didn’t instantly reply to requests for remark by Decrypt.
Typically Clever Publication
A weekly AI journey narrated by Gen, a generative AI mannequin.

