OpenAI announced that a third-party supplier data breach may have exposed some information of users of its API, ranging from personal emails to analytics data.
Mixpanel, a data analytics supplier, suffered a data breach when a threat actor gained unauthorised access to some of its systems, exposing a set of data which contained some amount of analytics information and customer data.
The incident and the investigation that followed resulted in OpenAI terminating its use of Mixpanel.
OpenAI uses Mixpanel for web analytics on the frontend interface for its API product to help the firm understand product usage and improve its API, and the incident affecting the third-party supplier occurred on the 9th of November.
Mixpanel shared the affected dataset with OpenAI on 25 November after informing the AI titan that they were investigating the incident.
OpenAI says that user profile information associated with use of its API may have been included in the data that was stolen from Mixpanel.
Breached information may have included names, email addresses, approximate coarse location data such as city, states, and countries, and any user IDs or organisations associated with an API account.
The operating system and browser used to access the API account, as well as referring websites, may also have been included in the dataset that was accessed in the incident.
Other OpenAI products, like ChatGPT, as well as related content and API usage data were not impacted by the third-party incident. The incident did not involve any unauthorised access to OpenAI’s infrastructure.
“This was not a breach of OpenAI’s systems. No chat, API requests, API usage data, passwords, credentials, API keys, payment details, or government IDs were compromised or exposed,” the company said in a blog post detailing the incident.
Recommended reading
- New Bill Targets Cyber Threats to UK Infrastructure
- Synnovis Updates On Data Breach From 2024 Ransomware Attack
- NHS Scotland Invests £3M in AI Anti-ransomware Software
- UK Facing 4 Major Cyber-Attacks Each Week, Warns NCSC
OpenAI said that as part f its security investigation, it removed Mixpanel from its production services, reviewed the datasets that had been affected, and are working with the firm to fully understand the incident.
“We are in the process of notifying impacted organizations, admins, and users directly,” the firm wrote. “While we have found no evidence of any effect on systems or data outside Mixpanel’s environment, we continue to monitor closely for any signs of misuse.”
The firm terminated its use of Mixpanel, saying that “Trust, security, and privacy are foundational to our products, our organization, and our mission.”
OpenAI also informed its API users to be wary of potential phishing or social engineering attacks that could arise against them as a result of the breached data.





