Last seen January 29, 2026

ChatGPT Prompt Injection Vulnerability

OpenAI confirmed a data breach originating from unauthorized access to Mixpanel, a third-party web analytics provider it uses for its API product. This incident exposed names, email addresses, approximate locations, OS/browser data, and user IDs associated with OpenAI API accounts (platform.openai.com users), but did not compromise ChatGPT content, passwords, or payment details.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

OpenAI confirmed a data breach originating from unauthorized access to Mixpanel, a third-party web analytics provider it uses for its API product. This incident exposed names, email addresses, approximate locations, OS/browser data, and user IDs associated with OpenAI API accounts (platform.openai.com users), but did not compromise ChatGPT content, passwords, or payment details.

Why This Matters

Publisher reporting describes a security event affecting llm. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether llm is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Jan 29, 2026 05:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

OpenAIChatGPTOpenAI APIData LeakagePrompt InjectionCISA

Timeline

  • Incident first seen
    Nov 26, 2025 05:30

    BugSkan first recorded this incident.

  • OpenAI confirms major data breach, exposing names, emails and more - Windows Central
    Nov 26, 2025 05:30

    windowscentral.com · Data Leak

  • OpenAI confirms ChatGPT data breach. Here is everything we know - Euronews.com
    Nov 27, 2025 05:30

    euronews.com · Data Leak

  • Is ChatGPT a Home Security Risk? Why You Shouldn’t Get Too Comfy With AI - Family Handyman
    Dec 03, 2025 05:30

    familyhandyman.com · Data Leak

  • The OpenAI security breach: The information you share with ChatGPT may leak - CTech
    Dec 16, 2025 05:30

    calcalistech.com · Data Leak

  • What the Latest OpenAI Security Breach Reveals About the State of AI Protection - securityboulevard.com
    Dec 18, 2025 05:30

    securityboulevard.com · Data Leak

  • ChatGPT falls to new data-pilfering attack as a vicious cycle in AI continues - Ars Technica
    Jan 08, 2026 05:30

    arstechnica.com · Data Leak

  • Trump’s acting cyber chief uploaded sensitive files into a public version of ChatGPT - Politico
    Jan 27, 2026 05:30

    politico.com · Data Leak

  • CISA chief uploaded sensitive government files to public ChatGPT - csoonline.com
    Jan 29, 2026 05:30

    csoonline.com · Data Leak

  • Latest observed development
    Jan 29, 2026 05:30

    Most recent source or update associated with this incident.

Sources

OpenAI confirms major data breach, exposing names, emails and more - Windows Central

windowscentral.com · Nov 26, 2025 05:30

OpenAI confirmed a data breach originating from unauthorized access to Mixpanel, a third-party web analytics provider it uses for its API product. This incident exposed names, email addresses, approximate locations, OS/browser data, and user IDs associated with OpenAI API accounts (platform.openai.com users), but did not compromise ChatGPT content, passwords, or payment details.

Open publisher source
OpenAI confirms ChatGPT data breach. Here is everything we know - Euronews.com

euronews.com · Nov 27, 2025 05:30

OpenAI confirmed a security breach originating from its third-party analytics provider, Mixpanel, where an unauthorized actor gained access to and exfiltrated a dataset. This incident led to the exposure of limited user-identifiable information, specifically names, email addresses, and user identifiers, without impacting core OpenAI systems or sensitive data like API keys or payment details.

Open publisher source
Is ChatGPT a Home Security Risk? Why You Shouldn’t Get Too Comfy With AI - Family Handyman

familyhandyman.com · Dec 03, 2025 05:30

AI chatbots pose a home security risk by indefinitely storing sensitive user conversation data, which can include details about home layouts, addresses, and personal routines. This stored information is vulnerable to data leaks and can be leveraged by attackers for social engineering tactics, enabling impersonation or facilitating physical security breaches.

Open publisher source
The OpenAI security breach: The information you share with ChatGPT may leak - CTech

calcalistech.com · Dec 16, 2025 05:30

A security incident at OpenAI led to data exposure through a vulnerability in Mixpanel, a third-party analytics provider. This compromise resulted in the leakage of user metadata, including names, email addresses, browser information, and approximate locations for individuals interacting with OpenAI's API.

Open publisher source
What the Latest OpenAI Security Breach Reveals About the State of AI Protection - securityboulevard.com

securityboulevard.com · Dec 18, 2025 05:30

A security breach at OpenAI occurred through a vulnerability in its third-party data analytics provider, Mixpanel, rather than a direct compromise of OpenAI's servers. This incident exposed general information about OpenAI API users, including names, email addresses, user IDs, browser details, operating systems, and approximate locations.

Open publisher source
ChatGPT falls to new data-pilfering attack as a vicious cycle in AI continues - Ars Technica

arstechnica.com · Jan 08, 2026 05:30

The ZombieAgent attack, a bypass of the earlier ShadowLeak exploit, leverages an indirect prompt injection vulnerability in ChatGPT to achieve character-by-character data exfiltration from user sessions. This sophisticated exploit bypasses OpenAI's URL parameter restrictions by supplying pre-constructed URLs and establishes persistence by planting malicious instructions within the LLM's long-term memory.

Open publisher source
Trump’s acting cyber chief uploaded sensitive files into a public version of ChatGPT - Politico

politico.com · Jan 27, 2026 05:30

An acting CISA director uploaded "for official use only" government contracting documents into a public version of ChatGPT, triggering internal security warnings. This action resulted in the unintentional disclosure of sensitive data to OpenAI, with the inherent risk of its incorporation into the LLM's training data and potential broader exposure.

Open publisher source
CISA chief uploaded sensitive government files to public ChatGPT - csoonline.com

csoonline.com · Jan 29, 2026 05:30

A CISA director uploaded "for official use only" government contracting documents to OpenAI's public ChatGPT, bypassing approved federal AI tools and triggering automated cyber alerts. This action resulted in the loss of data control, potential incorporation of sensitive information into the model's training data, and exposed critical enterprise AI governance failures.

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

← Back to incident intelligence