ChatGPT Prompt Injection Vulnerability
OpenAI confirmed a data breach originating from unauthorized access to Mixpanel, a third-party web analytics provider it uses for its API product. This incident exposed names, email addresses, approximate locations, OS/browser data, and user IDs associated with OpenAI API accounts (platform.openai.com users), but did not compromise ChatGPT content, passwords, or payment details.
STABLE
What Happened
OpenAI confirmed a data breach originating from unauthorized access to Mixpanel, a third-party web analytics provider it uses for its API product. This incident exposed names, email addresses, approximate locations, OS/browser data, and user IDs associated with OpenAI API accounts (platform.openai.com users), but did not compromise ChatGPT content, passwords, or payment details.
Why This Matters
Publisher reporting describes a security event affecting llm. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether llm is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.
Exposure
Exposure unknown
Jan 29, 2026 05:30
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Timeline
-
Incident first seen
Nov 26, 2025 05:30BugSkan first recorded this incident.
-
OpenAI confirms major data breach, exposing names, emails and more - Windows Central
Nov 26, 2025 05:30windowscentral.com · Data Leak
-
OpenAI confirms ChatGPT data breach. Here is everything we know - Euronews.com
Nov 27, 2025 05:30euronews.com · Data Leak
-
Is ChatGPT a Home Security Risk? Why You Shouldn’t Get Too Comfy With AI - Family Handyman
Dec 03, 2025 05:30familyhandyman.com · Data Leak
-
The OpenAI security breach: The information you share with ChatGPT may leak - CTech
Dec 16, 2025 05:30calcalistech.com · Data Leak
-
What the Latest OpenAI Security Breach Reveals About the State of AI Protection - securityboulevard.com
Dec 18, 2025 05:30securityboulevard.com · Data Leak
-
ChatGPT falls to new data-pilfering attack as a vicious cycle in AI continues - Ars Technica
Jan 08, 2026 05:30arstechnica.com · Data Leak
-
Trump’s acting cyber chief uploaded sensitive files into a public version of ChatGPT - Politico
Jan 27, 2026 05:30politico.com · Data Leak
-
CISA chief uploaded sensitive government files to public ChatGPT - csoonline.com
Jan 29, 2026 05:30csoonline.com · Data Leak
-
Latest observed development
Jan 29, 2026 05:30Most recent source or update associated with this incident.
Sources
windowscentral.com · Nov 26, 2025 05:30
OpenAI confirmed a data breach originating from unauthorized access to Mixpanel, a third-party web analytics provider it uses for its API product. This incident exposed names, email addresses, approximate locations, OS/browser data, and user IDs associated with OpenAI API accounts (platform.openai.com users), but did not compromise ChatGPT content, passwords, or payment details.
Open publisher sourceeuronews.com · Nov 27, 2025 05:30
OpenAI confirmed a security breach originating from its third-party analytics provider, Mixpanel, where an unauthorized actor gained access to and exfiltrated a dataset. This incident led to the exposure of limited user-identifiable information, specifically names, email addresses, and user identifiers, without impacting core OpenAI systems or sensitive data like API keys or payment details.
Open publisher sourcefamilyhandyman.com · Dec 03, 2025 05:30
AI chatbots pose a home security risk by indefinitely storing sensitive user conversation data, which can include details about home layouts, addresses, and personal routines. This stored information is vulnerable to data leaks and can be leveraged by attackers for social engineering tactics, enabling impersonation or facilitating physical security breaches.
Open publisher sourcecalcalistech.com · Dec 16, 2025 05:30
A security incident at OpenAI led to data exposure through a vulnerability in Mixpanel, a third-party analytics provider. This compromise resulted in the leakage of user metadata, including names, email addresses, browser information, and approximate locations for individuals interacting with OpenAI's API.
Open publisher sourcesecurityboulevard.com · Dec 18, 2025 05:30
A security breach at OpenAI occurred through a vulnerability in its third-party data analytics provider, Mixpanel, rather than a direct compromise of OpenAI's servers. This incident exposed general information about OpenAI API users, including names, email addresses, user IDs, browser details, operating systems, and approximate locations.
Open publisher sourcearstechnica.com · Jan 08, 2026 05:30
The ZombieAgent attack, a bypass of the earlier ShadowLeak exploit, leverages an indirect prompt injection vulnerability in ChatGPT to achieve character-by-character data exfiltration from user sessions. This sophisticated exploit bypasses OpenAI's URL parameter restrictions by supplying pre-constructed URLs and establishes persistence by planting malicious instructions within the LLM's long-term memory.
Open publisher sourcepolitico.com · Jan 27, 2026 05:30
An acting CISA director uploaded "for official use only" government contracting documents into a public version of ChatGPT, triggering internal security warnings. This action resulted in the unintentional disclosure of sensitive data to OpenAI, with the inherent risk of its incorporation into the LLM's training data and potential broader exposure.
Open publisher sourcecsoonline.com · Jan 29, 2026 05:30
A CISA director uploaded "for official use only" government contracting documents to OpenAI's public ChatGPT, bypassing approved federal AI tools and triggering automated cyber alerts. This action resulted in the loss of data control, potential incorporation of sensitive information into the model's training data, and exposed critical enterprise AI governance failures.
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.