Mixpanel Smishing Hack Leaks Data of OpenAI, CoinTracker Users

Smishing Attack on Mixpanel Leads to Data Leak Impacting OpenAI and CoinTracker Customers

  • A “smishing” attack on analytics firm Mixpanel led to a data leak affecting customers of CoinTracker and OpenAI.
  • The breach occurred on November 8, with Mixpanel reporting it publicly on November 21 and OpenAI notifying users on November 25.
  • Compromised data includes names, email addresses, approximate locations, device information, and transaction summaries, but no sensitive data like passwords or payment details.
  • OpenAI has stopped using Mixpanel services following the incident and assured ChatGPT users were not affected.
  • Mixpanel has responded by securing accounts, resetting passwords, and involving forensic and law enforcement teams.

On November 8, analytics provider Mixpanel was targeted by a “smishing” attack—a phishing scam sent via SMS messages—resulting in unauthorized access to customer data. This incident impacted users of crypto tax company CoinTracker and AI company OpenAI, both clients of Mixpanel’s analytics services.

- Advertisement -

Mixpanel disclosed the breach on November 21, informing that attackers exported customer data including names, email addresses, location data derived from IP addresses, device metadata, and summaries of user transactions. OpenAI followed with a user alert on November 25, confirming that some users’ names, email addresses, rough locations, and device information were accessed in the breach.

In statements, OpenAI emphasized that sensitive information such as chat content, API requests, passwords, credentials, payment details, government IDs, and API keys were not compromised. The company also clarified that the incident originated from Mixpanel’s systems and did not affect ChatGPT users. As a precaution, OpenAI has removed Mixpanel from its services and urged users to stay alert for scams that could use the leaked information.

CoinTracker warned that attackers accessed email addresses, location data based on IP addresses, device metadata, and brief summaries of users’ transactions through Mixpanel. Both companies advised caution regarding unexpected communications or requests related to password or personal information.

In response to the incident, Mixpanel secured the accounts impacted by the attack, reset employee passwords, blocked malicious IP addresses, engaged third-party forensic experts, and reached out to law enforcement and Cybersecurity advisors to investigate further.

- Advertisement -

Data breaches have become frequent in the crypto sector, with previous attacks hitting companies like crypto.com and Coinbase. Notably, last Christmas, the data of nearly 70,000 Coinbase users was leaked. Additionally, this year, customer service platform Zendesk suffered a breach leading to the exposure of millions of user IDs submitted by Discord users.

For more details on the attack, see Mixpanel’s official announcement at their blog and OpenAI‘s statement at their site. CoinTracker’s warning is available via their Twitter post.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Backpack Airdrops Equity to VIP Token Stakers

Backpack plans to offer equity to users who stake its upcoming token and join...

AI Demands Crypto to Keep Pace, Investor Says

Veteran investor Jordi Visser argues that AI "can’t survive without crypto," as the fiat...

Bitcoin Plunges as Israel Strikes Iran, Bounces Back Over $68K

Bitcoin plunged nearly 5% to near $60,000 following reports of U.S.-Israel strikes on Iran,...

XRP’s Future: $13.5 Trillion Hurdle to $150 Dream

Reaching $150 per XRP would require a $13.5 trillion market cap, a figure nearly...

BRICS Rising: Lula and Modi Boost India-Brazil Trade Amid Global Shift

Brazilian President Lula da Silva arrived in India with a 300-person delegation aiming to...

Must Read

How to Set Up a Simple Bitcoin Tip Jar for Your Site or Stream

QUICK LINKSWhat a tip jar is, in plain wordsWhat you needBuild a payment link that just worksAdd a QR code that actually scansWhere to...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!