OpenAI says a security incident at its third-party analytics provider Mixpanel exposed a dataset containing limited identifying and analytics information associated with some OpenAI users. OpenAI’s notice says the incident was confined to Mixpanel’s systems—not a breach of OpenAI’s systems—and that chats, prompts, API data, passwords, and API keys were not exposed.
What happened in the Mixpanel incident?
According to OpenAI’s incident notice, Mixpanel became aware on November 9, 2025 that an attacker had gained unauthorized access to part of its systems and exported a dataset. Mixpanel told OpenAI it was investigating, then shared the affected dataset with OpenAI on November 25. OpenAI published its notice on November 26, 2025.
OpenAI described Mixpanel as a web analytics provider it had used on the frontend interface for its API product. The company said: “This was not a breach of OpenAI’s systems.” That is OpenAI’s characterization of the incident; the notice describes the access and data export as occurring within Mixpanel’s systems.
What information may have been exposed?
OpenAI said the dataset may have included these fields associated with use of platform.openai.com:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Account name and email address
- Approximate location inferred from browser data, such as city, state, and country
- Operating system and browser
- Referring websites
- Organization or user IDs
This is account-profile and analytics information. It is distinct from the content of conversations, prompts, outputs, or API activity.
Were ChatGPT conversations or API data affected?
OpenAI said chats, prompts, outputs, API requests, and API usage data were not compromised or exposed. It also said passwords, credentials, API keys, payment details, government IDs, session tokens, authentication tokens, and other sensitive parameters for OpenAI services were not affected.
OpenAI’s December 19, 2025 clarification said a limited number of ChatGPT users who had submitted help-center tickets or were logged into platform.openai.com were also affected. The company said those users had already been identified and notified in its original outreach, and that the clarification did not change its understanding of the data involved.
How many people were affected?
OpenAI’s notice does not state a count of affected users or records. It uses qualitative descriptions such as “limited” and “a limited number,” so there is no published figure in the notice from which to estimate the incident’s size.
Recommended Free Tools
What should affected users do?
Be alert to targeted phishing
OpenAI identifies phishing and social engineering as the practical risk: an attacker could use names, email addresses, and account metadata to make an unsolicited message seem credible. Treat unexpected messages, links, and attachments cautiously. If a message claims to come from OpenAI, check that it uses an official OpenAI domain; do not rely only on the display name or branding.
Never provide a password, API key, or verification code in response to an email, text, or chat. If you are unsure whether a message is genuine, go to OpenAI’s service directly rather than using a link in the message.
Use multifactor authentication
OpenAI recommends enabling multifactor authentication as a general security best practice. Its notice does not name a particular MFA method or specify compatibility for individual account types, so check the security settings available on your account.
Password resets and API-key rotation
OpenAI says it is not recommending password resets or API-key rotation in response to this incident because passwords and API keys were not affected. If you have a separate reason to believe a credential is compromised, respond to that situation independently.
Best Value
What did OpenAI do after learning about the incident?
OpenAI said it reviewed the affected datasets, contacted impacted organizations and users, and continued monitoring for signs of misuse. It also said it removed Mixpanel from production services and terminated its use of the provider.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

