{"id":412666,"date":"2025-11-29T15:15:39","date_gmt":"2025-11-29T09:45:39","guid":{"rendered":"https:\/\/dripp.zone\/news\/openai-confirms-data-breach-heres-who-is-impacted-crypto-news\/"},"modified":"2025-11-29T15:34:04","modified_gmt":"2025-11-29T10:04:04","slug":"openai-confirms-data-breach-heres-who-is-impacted-crypto-news","status":"publish","type":"post","link":"https:\/\/dripp.zone\/news\/openai-confirms-data-breach-heres-who-is-impacted-crypto-news\/","title":{"rendered":"OpenAI Confirms Data Breach\u2014Here&#8217;s Who Is Impacted &#8211; Crypto News"},"content":{"rendered":"<div style=\"position:relative;overflow:visible;font-size:1.2em;line-height:1.58\">\n<div class=\"pt-8 pb-10 border-t border-b border-decryptGridline \">\n<h4 class=\"sc-b2a202e4-4 bNRGqr gg-dark:text-white\" color=\"#333\">In brief<\/h4>\n<ul>\n<li class=\"font-meta-serif-pro font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Mixpanel said an attacker accessed part of its systems and exported customer-identifiable metadata.<\/li>\n<li class=\"font-meta-serif-pro font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">OpenAI said no prompts, API keys, payment information, or authentication tokens were involved.<\/li>\n<li class=\"font-meta-serif-pro font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Both companies reviewed the incident, notified affected users, and outlined new security steps.<\/li>\n<\/ul>\n<\/div>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">A breach at analytics provider Mixpanel earlier this month exposed account names, email addresses, and browser locations for some users of OpenAI&#8217;s API, the AI giant confirmed Wednesday, raising concerns that cybercriminals could use the stolen metadata in targeted phishing attempts.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">According to Mixpanel, on November 8, an unknown attacker gained access to part of its systems and exported a dataset containing customer-identifiable metadata and analytics information. The stolen data included usernames, email addresses, approximate browser-based location, operating system, and browser details.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">OpenAI said the breach did not include users\u2019 prompts, API keys, payment information, or authentication tokens.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Only data from users who accessed OpenAI&#8217;s tech via the API\u2014aka, via external apps powered by GPT\u2014was leaked, the company said. In other words, if you access the ChatGPT chatbot directly from OpenAI&#8217;s website, then you won&#8217;t be impacted here.<\/p>\n<p><iframe loading=\"lazy\" style=\"border:0\" src=\"https:\/\/myriad.markets\/embed\/market\/time-person-of-the-year-2025-will-it-be-a-human\" width=\"100%\" height=\"415px\"><span data-mce-type=\"bookmark\" style=\"display:inline-block;width:0px;overflow:hidden;line-height:0\" class=\"mce_SELRES_start\">\ufeff<\/span><\/iframe><\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">\u201cAs part of our security investigation, we removed Mixpanel from our production services, reviewed the affected datasets, and are working closely with Mixpanel and other partners to fully understand the incident and its scope,\u201d OpenAI <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/openai.com\/index\/mixpanel-incident\/\" target=\"_blank\" rel=\"noopener nofollow external\" class=\"sc-adb616fe-0 bJsyml\">said<\/a> in a statement.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Founded in 2009, the San Francisco-based Mixpanel is a product analytics platform used to track user behavior across web and mobile applications. The company said it detected the &#8220;smishing&#8221; campaign, and after an initial investigation and response, alerted OpenAI the next day.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">\u201cWe are committed to transparency, and are notifying all impacted customers and users,\u201d OpenAI said. \u201cWe also hold our partners and vendors accountable for the highest bar for security and privacy of their services.\u201d<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Smishing is a type of <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/decrypt.co\/resources\/cybersecurity-in-web3-protecting-yourself-and-your-ape-jpeg\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">phishing<\/a> attack conducted through SMS messages. According to an October <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/spacelift.io\/blog\/social-engineering-statistics\" target=\"_blank\" rel=\"noopener nofollow external\" class=\"sc-adb616fe-0 bJsyml\">report<\/a> by infrastructure management company Spacelift, smishing accounted for 39% of all mobile threats in 2024.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Mixpanel said it secured affected accounts, revoked active sessions, rotated compromised credentials, and blocked malicious IP addresses. The company also reset employee passwords, hired external cybersecurity firms, and reviewed authentication, session, and export logs.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">After the breach, Mixpanel said it began notifying impacted customers about the incident.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">\u201cIf you have not heard from us directly, you were not impacted,\u201d Mixpanel CEO Jen Taylor said in a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/mixpanel.com\/blog\/sms-security-incident\/\" target=\"_blank\" rel=\"noopener nofollow external\" class=\"sc-adb616fe-0 bJsyml\">statement<\/a>. \u201cWe continue to prioritize security as a core tenet of our company, products, and services. We are committed to supporting our customers and communicating transparently about this incident.\u201d<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Despite Mixpanel\u2019s reporting of the incident to OpenAI, the ChatGPT developer said it was cutting ties with the analytics firm. \u201cAfter reviewing this incident, OpenAI has terminated its use of Mixpanel,\u201d they wrote.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Some OpenAI customers took to social media to express frustration with the revelation that a third-party service had access to their information.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">\u201cI&#8217;m not very happy about this. [&#8230;] Why did they have to pass on my name and email address to Mixpanel?\u201d one user <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/NCResq\/status\/1993929360286601390?s=20\" target=\"_blank\" rel=\"noopener nofollow external\" class=\"sc-adb616fe-0 bJsyml\">wrote<\/a> on X. \u201cI\u2019m just a hobbyist trying to make small experiments.\u201d<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">\u201cOpenAI sending names and emails to a third party analytics platform (Mixpanel) feels wildly irresponsible,\u201d another <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/ZackKorman\/status\/1994065737972109412?s=20\" target=\"_blank\" rel=\"noopener nofollow external\" class=\"sc-adb616fe-0 bJsyml\">wrote<\/a>.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">OpenAI and Mixpanel did not immediately respond to requests for comment by <i>Decrypt.<\/i><\/p>\n<div class=\"my-4 border-b border-decryptGridline\">\n<div class=\"text-start p-8 md:py-12 md:px-12 max-w-prose relative\"><span class=\"border-t-4 border-l-4 w-4 h-4 md:border-t-[6px] md:border-l-[6px] md:w-6 md:h-6 border-decryptPurple dark:border-decryptNeon gg-dark:border-cc-pink-2 absolute top-4 left-4 md:top-6 md:left-6\"\/><span class=\"border-t-4 border-l-4 w-4 h-4 md:border-t-[6px] md:border-l-[6px] md:w-6 md:h-6 border-decryptPurple dark:border-decryptNeon gg-dark:border-cc-pink-2 absolute rotate-180 bottom-4 right-4 md:bottom-6 md:right-6\"\/><\/p>\n<h3 class=\"font-akzidenz-grotesk font-bold text-xl md:text-3xl md:text-center gg-dark:text-white\">Generally Intelligent<!-- --> Newsletter<\/h3>\n<p>A weekly AI journey narrated by Gen, a generative AI model.<\/p>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>In brief Mixpanel said an attacker accessed part of its systems and exported customer-identifiable metadata. OpenAI said no prompts, API keys, payment information, or authentication tokens were involved. Both companies reviewed the incident, notified affected users, and outlined new security steps. A breach at analytics provider Mixpanel earlier this month exposed account names, email addresses, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":412667,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[230,225,221,227,226,228,229,60,223,224,222],"class_list":["post-412666","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency","tag-brave","tag-coinbase","tag-crypto","tag-decentralised","tag-decentralized","tag-decentralized-exchange","tag-erc-20","tag-featured","tag-meme-coin","tag-robinhood","tag-solana"],"_links":{"self":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/412666","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/comments?post=412666"}],"version-history":[{"count":1,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/412666\/revisions"}],"predecessor-version":[{"id":412668,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/412666\/revisions\/412668"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media\/412667"}],"wp:attachment":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media?parent=412666"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/categories?post=412666"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/tags?post=412666"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}