frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Tell HN: OpenAI Security Incident with PII

3•vintagedave•1h ago
Today I got the following email from OpenAI:

Subject: Third-party security incident

From: OpenAI <noreply@email.openai.com>

Transparency is important to us, so we want to inform you about a recent security incident at Mixpanel, a data analytics provider that OpenAI used for web analytics on the frontend interface for our API product (platform.openai.com). The incident occurred within Mixpanel’s systems and involved limited analytics data related to your API account.

This was not a breach of OpenAI’s systems. No chat, API requests, API usage data, passwords, credentials, API keys, payment details, or government IDs were compromised or exposed.

What happened

On November 9, 2025, Mixpanel became aware of an attacker that gained unauthorized access to part of their systems and exported a dataset containing limited customer identifiable information and analytics information. Mixpanel notified OpenAI that they were investigating, and on November 25, 2025, they shared the affected dataset with us.

What this means for you

User profile information associated with use of platform.openai.com may have been included in data exported from Mixpanel. The information that may have been affected was limited to:

* Name that was provided to us on the API account

* Email address associated with the API account

* Approximate coarse location based on API user browser (city, state, country)

* Operating system and browser used to access the API account

* Referring websites

* Organization or User IDs associated with the API account

Our response

As part of our security investigation, we removed Mixpanel from our production services, reviewed the affected datasets, and are working closely with Mixpanel and other partners to fully understand the incident and its scope. We are in the process of notifying impacted organizations, admins, and users directly. While we have found no evidence of any effect on systems or data outside Mixpanel’s environment, we continue to monitor closely for any signs of misuse.

Trust, security, and privacy are foundational to our products, our organization, and our mission. We are committed to transparency, and are notifying all impacted customers and users. We also hold our partners and vendors accountable for the highest bar for security and privacy of their services. After reviewing this incident, OpenAI has terminated its use of Mixpanel.

Beyond Mixpanel, we are conducting additional and expanded security reviews across our vendor ecosystem and are elevating security requirements for all partners and vendors.

What you should keep in mind

The information that may have been affected here could be used as part of phishing or social engineering attacks against you or your organization.

Since names, email addresses, and OpenAI API metadata (e.g., user IDs) were included, we encourage you to remain vigilant for credible-looking phishing attempts or spam. As a reminder:

* Treat unexpected emails or messages with caution, especially if they include links or attachments.

* Double-check that any message claiming to be from OpenAI is sent from an official OpenAI domain.

* OpenAI does not request passwords, API keys, or verification codes through email, text, or chat.

* Further protect your account by enabling multi-factor authentication.

The security and privacy of our products are paramount, and we remain resolute in protecting your information and communicating transparently when issues arise. Thank you for your continued trust in us.

For more information about this incident and what it means for impacted users, please see our blog post here. [ https://openai.com/index/mixpanel-incident/ ]

Please contact your account team or mixpanelincident@openai.com if you have any questions or need our support.

OpenAI

Comments

vintagedave•1h ago
What is unclear to me is since organization and user IDs are included, what security risk this poses to my account. I know the API includes sending the organization.

While I'm sure my name, email and location are out there already, I am also disappointed to see leaks of (what I view as) PII.

Show HN: Henry Perigal's Visual Proof of the Pythagoras Theorem

https://do-say-go.github.io/insights/others/interactive_perigals_pythagorean.html
1•keepamovin•3m ago•0 comments

Tell HN: Happy Thanksgiving – Grateful

1•emreb•5m ago•0 comments

Show HN: Auto-Unpublish NPM Packages Published Outside CI

https://github.com/telophasehq/tangent-plugins/tree/main/detections/sha1hulud/npmcicorrelation
2•ethanblackburn•5m ago•0 comments

Show HN: SyncKit – Offline-first sync engine (Rust/WASM and TypeScript)

https://github.com/Dancode-188/synckit
4•danbitengo•11m ago•0 comments

Toll in Hong Kong fire rises to 65, police cite 'grossly negligent' firm

https://www.reuters.com/world/china/hong-kong-tower-fire-toll-rises-44-police-arrest-three-2025-1...
2•Inocez•11m ago•0 comments

Use Minimal APIs over Controllers for new apps

https://www.roundthecode.com/dotnet-blog/why-you-must-use-minimal-apis-over-controllers-new-apps
1•PretzelFisch•11m ago•0 comments

Does anyone run ads successfully?

1•XCSme•12m ago•2 comments

GNU C Library Sees Up to 12.9x Improvement with New Generic FMA Implementation

https://www.phoronix.com/news/Glibc-New-Generic-FMA
1•Bender•13m ago•0 comments

I was left hospitalized and coughing up blood after using a glass straw

https://www.dailymail.co.uk/health/article-15325379/glass-straws-accident-TikTok-blood-stomach.html
2•Bender•14m ago•0 comments

Show HN: Runprompt – run .prompt files from the command line

https://github.com/chr15m/runprompt
2•chr15m•16m ago•0 comments

Show HN: Alt – A local AI lecture/meeting notetaker

https://www.altalt.io/en
2•predict-woo•19m ago•1 comments

Show HN: SceenYou.art-Your Personal AI Visual Studio

https://sceneyou.art/
1•zy5a59•20m ago•0 comments

Neuracore raises $3M to power next-gen robots and open robotics research

https://earlybird.com/perspectives/backing-neuracore-reinventing-data-infrastructure-for-robotics
1•felixneuraco•20m ago•0 comments

Equal things that don't look equal

https://www.johndcook.com/blog/2025/11/27/hyperbolic-metric-formulas/
2•ibobev•20m ago•0 comments

Launch: Rivellium – AI-powered multi-asset investing with real SMB cashflow

1•rivellium•21m ago•1 comments

Four-inch worm hatches in woman's forehead, wriggles to her eyelid

https://arstechnica.com/health/2025/11/doctors-pull-4-inch-worm-out-of-womans-eyelid-after-monthl...
3•Bender•21m ago•0 comments

AI Just Took My Product Photographer's Job

https://theautomatedoperator.substack.com/p/ai-just-took-my-product-photographers
2•idopmstuff•25m ago•0 comments

Haskell Jupyter kernels (IHaskell, xeus-Haskell) comparison

https://www.datahaskell.org/blog/2025/11/25/a-tale-of-two-kernels.html
1•yehoshuapw•29m ago•0 comments

Constraint-Engineered Development

https://rootcx.com/blog/constraint-engineered-development
1•seyz•32m ago•0 comments

Article on Medium

https://medium.com/@benoitlebison/what-would-a-world-with-legal-therapeutic-psilocybin-look-like-...
1•magictruffle•33m ago•0 comments

Crypto investors face tax crackdown as 70% non-compliant

https://www.thepost.co.nz/business/360897298/crypto-investors-face-tax-crackdown-70-non-compliant
22•gochuks•33m ago•7 comments

OpenAI confirms major breach, exposing user's names, email addresses, and more

https://www.windowscentral.com/artificial-intelligence/openai-chatgpt/openai-confirms-major-data-...
2•choult•34m ago•0 comments

Show HN: Omnom v0.8.0 with Fediverse feed integration

https://github.com/asciimoo/omnom/releases/tag/v0.8.0
4•asciimoo•36m ago•0 comments

A terminal emulator that runs in your terminal. Powered by Turbo Vision

https://github.com/magiblot/tvterm
1•mariuz•39m ago•0 comments

Got burned by an Apple ICLR paper – it was withdrawn after my Public Comment

https://twitter.com/diyerxx/status/1994042370376032701
3•diyer22•40m ago•2 comments

Boarding School Syndrome

https://www.theguardian.com/books/2015/jun/08/boarding-school-syndrome-joy-schaverien-review
2•niemandhier•40m ago•1 comments

Free Flux 2 to Try

https://flux-2-ai.com
1•jeyzolo•40m ago•1 comments

Ask HN: Do AIs replay with numerous em dashes save money somehow?

2•amichail•42m ago•1 comments

What Great Means to Us

https://twinlabs.notion.site/great
1•bkolobara•44m ago•0 comments

European parliament calls for social media ban on under-16s

https://www.theguardian.com/technology/2025/nov/26/social-media-ban-under-16s-european-parliament...
5•2OEH8eoCRo0•48m ago•2 comments