Charts
DataOn-chain
VIP
Market Cap
API
Rankings
CoinOSNew
CoinClaw🦞
Language
  • 简体中文
  • 繁体中文
  • English
Leader in global market data applications, committed to providing valuable information more efficiently.

Features

  • Real-time Data
  • Special Features
  • AI Grid

Services

  • News
  • Open Data(API)
  • Institutional Services

Downloads

  • Desktop
  • Android
  • iOS

Contact Us

  • Chat Room
  • Business Email
  • Official Email
  • Official Verification

Join Community

  • Telegram
  • Twitter
  • Discord

© Copyright 2013-2026. All rights reserved.

简体繁體English
|Legacy

OpenAI Confirms Data Breach—Here's Who Is Impacted

CN
Decrypt
Follow
4 months ago
AI summarizes in 5 seconds.

A breach at analytics provider Mixpanel earlier this month exposed account names, email addresses, and browser locations for some users of OpenAI's API, the AI giant confirmed Wednesday, raising concerns that cybercriminals could use the stolen metadata in targeted phishing attempts.


According to Mixpanel, on November 8, an unknown attacker gained access to part of its systems and exported a dataset containing customer-identifiable metadata and analytics information. The stolen data included usernames, email addresses, approximate browser-based location, operating system, and browser details.


OpenAI said the breach did not include users’ prompts, API keys, payment information, or authentication tokens.


Only data from users who accessed OpenAI's tech via the API—aka, via external apps powered by GPT—was leaked, the company said. In other words, if you access the ChatGPT chatbot directly from OpenAI's website, then you won't be impacted here.





“As part of our security investigation, we removed Mixpanel from our production services, reviewed the affected datasets, and are working closely with Mixpanel and other partners to fully understand the incident and its scope,” OpenAI said in a statement.


Founded in 2009, the San Francisco-based Mixpanel is a product analytics platform used to track user behavior across web and mobile applications. The company said it detected the "smishing" campaign, and after an initial investigation and response, alerted OpenAI the next day.


“We are committed to transparency, and are notifying all impacted customers and users,” OpenAI said. “We also hold our partners and vendors accountable for the highest bar for security and privacy of their services.”


Smishing is a type of phishing attack conducted through SMS messages. According to an October report by infrastructure management company Spacelift, smishing accounted for 39% of all mobile threats in 2024.


Mixpanel said it secured affected accounts, revoked active sessions, rotated compromised credentials, and blocked malicious IP addresses. The company also reset employee passwords, hired external cybersecurity firms, and reviewed authentication, session, and export logs.


After the breach, Mixpanel said it began notifying impacted customers about the incident.


“If you have not heard from us directly, you were not impacted,” Mixpanel CEO Jen Taylor said in a statement. “We continue to prioritize security as a core tenet of our company, products, and services. We are committed to supporting our customers and communicating transparently about this incident.”


Despite Mixpanel’s reporting of the incident to OpenAI, the ChatGPT developer said it was cutting ties with the analytics firm. “After reviewing this incident, OpenAI has terminated its use of Mixpanel,” they wrote.


Some OpenAI customers took to social media to express frustration with the revelation that a third-party service had access to their information.


“I'm not very happy about this. [...] Why did they have to pass on my name and email address to Mixpanel?” one user wrote on X. “I’m just a hobbyist trying to make small experiments.”


“OpenAI sending names and emails to a third party analytics platform (Mixpanel) feels wildly irresponsible,” another wrote.


OpenAI and Mixpanel did not immediately respond to requests for comment by Decrypt.


免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

极度恐慌别慌!注册币安领600 USDT,10%低费抄底!
广告
|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Selected Articles by Decrypt

2 hours ago
These Three Altcoins Just Got Leveraged Crypto ETFs
3 hours ago
Solana DeFi Exchange Drift Protocol Exploited, Upwards of $285 Million Stolen
3 hours ago
Google\\\'s Veo 3.1 Lite Cuts API Costs in Half as OpenAI\\\'s Sora Exits the Market
View More

Table of Contents

|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Related Articles

avatar
avatarbitcoin.com
51 minutes ago
Charles Schwab-Backed EDX Markets Applies for National Trust Bank Charter With OCC
avatar
avatarbitcoin.com
1 hour ago
World Unveils New Toolkit, Expands Developer Program With World Build 3
avatar
avatarDecrypt
2 hours ago
These Three Altcoins Just Got Leveraged Crypto ETFs
avatar
avatarbitcoin.com
2 hours ago
Cango Secures $75M in Fresh Capital to Expand Ecohash AI Computing Platform
avatar
avatarDecrypt
3 hours ago
Solana DeFi Exchange Drift Protocol Exploited, Upwards of $285 Million Stolen
APP
Windows
Mac

X

Telegram

Facebook

Reddit

CopyLink