Particle.news

OpenAI Says Third-Party Breach Exposed API User Metadata, Removes Mixpanel From Production

OpenAI is notifying developer accounts following Mixpanel's late disclosure of a November 9 intrusion.

Overview

  • The incident involved unauthorized access to Mixpanel used on platform.openai.com, affecting a subset of OpenAI API users.
  • Exfiltrated data consisted of profile and technical metadata such as names, emails, approximate locations, OS and browser details, referrer sites, and organization or user IDs.
  • OpenAI reports no breach of its own systems and says chats, API requests or usage data, passwords, API keys, payment information, and government IDs were not exposed.
  • The company removed Mixpanel from its production environment, began direct notifications to potentially affected accounts, and initiated a broader vendor security review.
  • OpenAI warns the metadata could enable targeted phishing and advises enabling multi-factor authentication and verifying the origin of unexpected messages.