OpenAI disclosed a data breach in November 2025, which occurred due to unauthorized access to the systems of its analytics partner, Mixpanel. The incident primarily impacted OpenAI API customers, specifically organizations utilizing OpenAI's API to integrate its services into their own software. OpenAI confirmed that its own systems were not compromised, and they subsequently removed Mixpanel from their production environment.
The exposed data included customer names, email addresses, approximate location information, and details about devices and browsers. Crucially, OpenAI confirmed that no sensitive data such as chat content, API keys, passwords, credentials, or payment information was exposed. The exact number of affected individuals has not been publicly disclosed.
While the scope of the exposed metadata was limited, OpenAI noted that this information could potentially be used for highly targeted phishing attempts against developers and administrators. Details regarding specific affected states or official notification procedures have not been provided in the available research.