frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Mixpanel Security Breach

https://mixpanel.com/blog/sms-security-incident/
38•jaredwiener•1h ago

Comments

kevcampb•1h ago
The title here is misleading. The original article does not state breach and at no point have Mixpanel used that term.
willsmith72•48m ago
Well OpenAI say users' names, emails and locations have been divulged, one of them is going to accept there was a "breach"
red_Seashell_32•40m ago
OpenAI was sending that data to MixPanel. If anything, OpenAI is culprit for sensitive data leak. There’s absolutely no reason to send that data.
jacquesm•3m ago
Companies use sub-processors all the time, OpenAI is no different. Unless you want to have everybody get a major case of NIH tomorrow (I wouldn't mind, then we can get rid of third party cookies and all advertising as well while we're at it).

Every time a google tag is included on a page a ton of sensitive data gets sent to another party than the one whose website you are visiting.

aberoham•23m ago
For context: https://news.ycombinator.com/item?id=46065585 OpenAI's announcement and https://news.ycombinator.com/item?id=46065208 CoinTracker’s
red_Seashell_32•56m ago
It was SMS Phishing, a.k.a. Social Engineering.

It anything, it’s opposite of breach.

autoexec•27m ago
> It was SMS Phishing, a.k.a. Social Engineering... it’s opposite of breach.

A social engineering attack that enables an attacker to gain unauthorized access to Mixpanel's systems and export a dataset containing names, user IDs, location data, and email addresses sounds exactly like a breach to me.

jacquesm•21m ago
That is not how it works.

A breach is unauthorized disclosure, the mechanism through which it is achieved is not relevant to that classification.

An employee that walks out with a file would also be classified as a breach, even if no systems got compromised from the outside.

denuoweb•38m ago
Email from OpenAI: Transparency is important to us, so we want to inform you about a recent security incident at Mixpanel, a data analytics provider that OpenAI used for web analytics on the frontend interface for our API product (platform.openai.com). The incident occurred within Mixpanel’s systems and involved limited analytics data related to your API account.

This was not a breach of OpenAI’s systems. No chat, API requests, API usage data, passwords, credentials, API keys, payment details, or government IDs were compromised or exposed.

What happened On November 9, 2025, Mixpanel became aware of an attacker that gained unauthorized access to part of their systems and exported a dataset containing limited customer identifiable information and analytics information. Mixpanel notified OpenAI that they were investigating, and on November 25, 2025, they shared the affected dataset with us.

What this means for you User profile information associated with use of platform.openai.com may have been included in data exported from Mixpanel. The information that may have been affected was limited to: Name that was provided to us on the API account Email address associated with the API account Approximate coarse location based on API user browser (city, state, country) Operating system and browser used to access the API account Referring websites Organization or User IDs associated with the API account

jvandenbroeck•36m ago
It's a suspicious post, why would you make a post if attackers are performing a sms phishing, that happens all the time.
kevcampb•29m ago
Possibly because OpenAI have just made a post stating there has been a breach https://openai.com/index/mixpanel-incident/ and implicating Mixpanel as the cause
LostMyLogin•17m ago
I also just received an email from OpenAI regarding the incident.
ares623•21m ago
Does that mean Mixpanel stock/valuation goes up because OpenAI uses them? That's how it works now is it?
weird-eye-issue•11m ago
In the email they sent to users it's clear they don't use them anymore
gotosun•18m ago
So did an Mixpanel employee get phished or were Mixpanel customer accounts targeted, thus an OpenAI employee fell for it?
anonymous908213•13m ago
I don't understand. I was assured that ChatGPT is AGI by Sam Altman. Why are security breaches still happening? Surely with several hundred billion dollars investment and access to AGI, they could use ChatGPT agents to create their own product analytics platform that is robust and resilient against such a trivial attack rather than selling off users' personal data to a third party.
weird-eye-issue•11m ago
> selling off users' personal data to a third party.

You do realize that you pay for Mixpanel right?

autoexec•13m ago
Considering they were aware of this on the 8th (who knows how long that was after it actually happened) it's a little disappointing that they'd wait until the day of such a major holiday to post about it. Unsurprising sure, but still disappointing.
thinkindie•10m ago
I'm extremely confused by Mixpanel announcement, according to their blog post if you received an email from them it implies you were affected, yet I closed my account with them few months ago and I still received their email, which I can't understand if my account was impacted or no

> As a valued customer, we wanted to inform you about a recent security incident that affected a limited number of Mixpanel user accounts. We have proactively communicated with all impacted customers. If we did not previously contact you, your Mixpanel accounts were not impacted. We continue to prioritize security as a core tenant of our company, products and services. We are committed to supporting our customers and communicating transparently about this incident.

Mixpanel Security Breach

https://mixpanel.com/blog/sms-security-incident/
39•jaredwiener•1h ago•19 comments

Penpot: The Open-Source Figma

https://github.com/penpot/penpot
224•selvan•6h ago•26 comments

DIY NAS: 2026 Edition

https://blog.briancmoses.com/2025/11/diy-nas-2026-edition.html
149•sashk•5h ago•59 comments

Voyager 1 is about to reach one light-day from Earth

https://scienceclock.com/voyager-1-is-about-to-reach-one-light-day-from-earth/
893•ashishgupta2209•18h ago•308 comments

Music eases surgery and speeds recovery, study finds

https://www.bbc.com/news/articles/c231dv9zpz3o
48•1659447091•3h ago•5 comments

Linux Kernel Explorer

https://reverser.dev/linux-kernel-explorer
23•tanelpoder•2h ago•1 comments

Willis Whitfield: A simple man with a simple solution that changed the world

https://www.sandia.gov/labnews/2024/04/04/willis-whitfield-a-simple-man-with-a-simple-solution-th...
47•rbanffy•2d ago•8 comments

Interactive λ-Reduction

https://deltanets.org/
8•jy14898•2d ago•0 comments

G0-G3 corners, visualised: learn what "Apple corners" are

https://www.printables.com/model/1490911-g0-g3-corners-visualised-learn-what-apple-corners
16•dgroshev•3d ago•1 comments

Coq: The World's Best Macro Assembler? [pdf] [2013]

https://nickbenton.name/coqasm.pdf
63•addaon•4h ago•23 comments

Principles of Vasocomputation

https://opentheory.net/2023/07/principles-of-vasocomputation-a-unification-of-buddhist-phenomenol...
13•eatitraw•2h ago•1 comments

Ray Marching Soft Shadows in 2D

https://www.rykap.com/2020/09/23/distance-fields/
11•memalign•1h ago•0 comments

Migrating the main Zig repository from GitHub to Codeberg

https://ziglang.org/news/migrating-from-github-to-codeberg/
557•todsacerdoti•6h ago•443 comments

S&box is now an open source game engine

https://sbox.game/news/update-25-11-26
297•MaximilianEmel•12h ago•96 comments

Running Unsupported iOS on Deprecated Devices

https://nyansatan.github.io/run-unsupported-ios/
141•OuterVale•9h ago•48 comments

Gemini CLI Tips and Tricks for Agentic Coding

https://github.com/addyosmani/gemini-cli-tips
264•ayoisaiah•14h ago•90 comments

DNS Firewalling with MISP and Technitium DNS Server

https://zaferbalkan.com/technitium-misp/
4•feldrim•1h ago•2 comments

Functional Data Structures and Algorithms: a Proof Assistant Approach

https://fdsa-book.net/
47•SchwKatze•6h ago•6 comments

Show HN: Era – Open-source local sandbox for AI agents

https://github.com/BinSquare/ERA
13•gregTurri•3h ago•3 comments

Last Issue of "ECMAScript News"

https://ecmascript.news/archive/es-next-news-2025-11-26.html
7•Klaster_1•2h ago•0 comments

A Fast 64-Bit Date Algorithm (30–40% faster by counting dates backwards)

https://www.benjoffe.com/fast-date-64
322•benjoffe•4d ago•70 comments

Fara-7B: An efficient agentic model for computer use

https://github.com/microsoft/fara
122•maxloh•13h ago•37 comments

C100 Developer Terminal

https://caligra.com/
70•matthewsinclair•9h ago•67 comments

The EU made Apple adopt new Wi-Fi standards, and now Android can support AirDrop

https://arstechnica.com/gadgets/2025/11/the-eu-made-apple-adopt-new-wi-fi-standards-and-now-andro...
433•cyclecount•11h ago•197 comments

Bring bathroom doors back to hotels

https://bringbackdoors.com/
626•bariumbitmap•10h ago•477 comments

Evaluating Uniform Memory Access Mode on AMD's Turin

https://chipsandcheese.com/p/evaluating-uniform-memory-access
8•zdw•3h ago•0 comments

A woman on a mission to photograph every species of hummingbird

https://www.audubon.org/magazine/meet-woman-mission-photograph-every-species-of-hummingbird-world
124•zeech•4d ago•25 comments

Ruby Was Ready from the Start

https://obie.medium.com/ruby-was-ready-from-the-start-4b089b17babb
49•thunderbong•3d ago•14 comments

DSP 101 Part 1: An Introductory Course in DSP System Design

https://www.analog.com/en/resources/analog-dialogue/articles/dsp-101-part-1.html
36•teleforce•7h ago•5 comments

A cell so minimal that it challenges definitions of life

https://www.quantamagazine.org/a-cell-so-minimal-that-it-challenges-definitions-of-life-20251124/
274•ibobev•22h ago•119 comments