Nascode Blogs

Important Security Alert from Nascode: The Mixpanel Incident and Your OpenAI API Security

By 

nascode

28 November, 2025

Important Security Alert from Nascode: The Mixpanel Incident and Your OpenAI API Security

Important Security Alert from Nascode: The Mixpanel Incident and Your OpenAI API Security

At Nascode, we believe in proactive security and full transparency. As a company heavily invested in cutting-edge AI technologies, we received a vital notification from OpenAI regarding a recent security incident involving their third-party analytics provider, Mixpanel.

While OpenAI's core infrastructure was confirmed to be secure—meaning no sensitive data like passwords, API keys, or chat logs were compromised—we want to ensure our clients and partners understand the details and, more importantly, know how to protect themselves from related risks.

Key Facts: What Happened at Mixpanel

The incident occurred entirely within Mixpanel

Media1
Media2
’s systems, a vendor OpenAI used for web analytics on the frontend API platform (platform.openai.com).
  • Timeline: Unauthorized access was detected by Mixpanel on November 9, 2025. OpenAI was notified and received the affected data on November 25, 2025.

  • No Breach of OpenAI Systems: Crucially, no API requests, API usage data, passwords, credentials, API keys, payment details, or chat data were compromised.

  • The Impacted Data: The exported dataset was limited to analytics information related to user profiles on the API platform:

    • Name and Email Address associated with the API account.

    • Organization or User IDs associated with the API account.

    • Limited technical metadata (approximate location, OS, browser, and referring websites).



Nascode's Perspective: Supply Chain Risk Management


OpenAI's response, which included the immediate removal of Mixpanel from production and the subsequent termination of their use of Mixpanel, underscores a critical lesson for all businesses: the security of your entire vendor ecosystem is paramount.

This incident highlights the growing challenge of Supply Chain Risk Management . Every external partner or vendor introduces a potential security vulnerability, and they must be held to the highest standards of security and privacy—the same high standards we uphold at Nascode.



Actionable Security Tips: How to Remain Vigilant

The risk associated with the exposed data (Name, Email, User ID) is primarily Social Engineering and Phishing attacks. Attackers can use this specific information to craft highly convincing, personalized emails (Spear Phishing).

We urge our clients and team members to be extremely vigilant and take the following immediate steps:

  1. Enable Multi-Factor Authentication (MFA): This is your strongest defense against compromised credentials. Enable MFA on your OpenAI API account and all other critical services.

  2. Verify the Source of Emails: Be skeptical of unexpected messages. Always double-check the sender's domain to ensure it's an official OpenAI address before clicking links or downloading attachments.

  3. Recognize Phishing Tactics: Remember: OpenAI will never request your password, API keys, or verification codes via email, text, or chat.

  4. Isolate API Keys: If your security policy permits, consider isolating your high-privilege API keys and generating new ones regularly as a best practice.

At Nascode, we continue to monitor the situation and strengthen our internal security protocols. The security and privacy of the digital services we build and manage are non-negotiable.

Link copied to clipboard!