Sev0AI security incidents, tracked

All incidents / Supply chain and access

Analytics vendor breach exposed names and emails of OpenAI API users

OpenAI (via Mixpanel), disclosed 26 Nov 2025. Supply chain and access Data exposed Medium

An attacker broke into Mixpanel, an analytics provider OpenAI used on its API platform, and exported names, email addresses, approximate locations and browser details of some API users. OpenAI said no chats, API keys or payment data were involved and stopped using Mixpanel.

Disclosed
26 Nov 2025
Organization
OpenAI (via Mixpanel)
Vendor
OpenAI
Product
OpenAI API platform
Kind of AI
Model or package
AI's role
AI was the target
How it happened
Supply chain and access: Third-party leak
Harm
Data exposed
Data involved
Personal data
Reach
One organization
Severity
Medium
Model at fault
No
Status
Confirmed

Sources

  1. https://openai.com/index/mixpanel-incident/

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "Analytics vendor breach exposed names and emails of OpenAI API users", https://sev0.fyi/incidents/2025-11-26-openai-mixpanel-vendor-breach/