OpenAI Admits Data-Breach After Analytics Partner Hit By Phishing Attack
OpenAI has suffered a significant data breach after hackers broke into the systems of its analytics partner Mixpanel and successfully stole customer profile information for its API portal, the companies have said in coordinated statements.
According to a post by Mixpanel CEO Jen Taylor, the incident took place on November 8 when the company “detected a smishing campaign and promptly executed our incident response processes.”
Smishing is a form of phishing-by-SMS against targeted employees, popular with hackers because text messages bypass normal enterprise controls. This gave the attackers access to Mixpanel’s system, allowing them to steal a range of metadata relating to platform.openai.com account profiles:
Name provided to OpenAI on the API account
Email address associated with the API account
Approximate location based on API user browser (city, state, country)
Operating system and browser used to access the API account
Referring websites
Organization or User IDs associated with the API account
“We proactively communicated with all impacted customers. If you have not heard from us directly, you were not impacted,” said Taylor.
According to a separate OpenAI post, Mixpanel shared the affected customer dataset with it on November 25. After review, OpenAI had terminated its use of Mixpanel, it said, implying that this might be permanent.
The incident affects some customers with platform.openai.com accounts, but not users of ChatGPT or other OpenAI products, OpenAI said.
“We are in the process of notifying impacted organizations, admins, and users directly. While we have found no evidence of any effect on systems or data outside Mixpanel’s environment, we continue to monitor closely for any signs of misuse,” OpenAI said.
“This was not a breach of OpenAI’s systems. No chat, API requests, API usage data, passwords, credentials, API keys, payment details, or government IDs were compromised or exposed.”
https://www.infoworld.com/article/4097479/openai-admits-data-breach-after-analytics-partner-hit-by-phishing-attack.html