← Back to Risk Digest

Risk Digest record

Multiple OpenAI security incidents (2023-2026)

Four OpenAI security breaches pose distinct legal risks for law firms

United States · attorney

AI tool named
OpenAI ChatGPT
Hallucination type
fabricated citation
Sanction type
monetary-sanction
Ruling date
Source document
View the primary court order ↗
Last reviewed

A law firm cannot assess OpenAI security-breach legal risks by asking whether OpenAI has been “breached.” That question is too blunt for the work risk teams actually have to do. The useful question is narrower: what data was exposed, through whose system, and which duty does that activate for a firm that allowed lawyers, staff, or clients to use the tool?

The four documented incidents point in different directions. One reaches breach-notification and confidentiality analysis because billing data and chat metadata were exposed. One affects vendor diligence because a compromise of an internal employee forum reportedly was not disclosed to customers or the FBI at the time. One sits in the third-party analytics layer, where names, emails, and approximate geolocation can still reveal legal work patterns. One is a supply-chain event involving compromised employee devices, credential material, internal repositories, and certificate rotation. Treating them as one generic security story makes the legal analysis worse, not simpler.

IncidentReported exposure or breach pathPrimary legal risk for legal organizations
March 2023 Redis bugChat titles, names, email addresses, payment addresses, and last-four digits of credit cards were exposed during the incident window.Breach-notification analysis, personal-data analysis, and ABA Model Rule 1.6 confidentiality exposure if matter-identifying metadata appeared in prompts or chat titles. [1][2]
2023 employee-forum breach, reported July 2024A hacker reportedly stole secrets from an internal OpenAI employee forum; reporting said OpenAI did not disclose the incident to customers or the FBI at the time.Vendor diligence, contractual disclosure expectations, and competence/supervision questions under Rules 1.1 and 5.3. [3]
November 2025 Mixpanel exposureNames, email addresses, and approximate geolocation of ChatGPT and API users were exposed through a third-party analytics vendor; OpenAI said it terminated Mixpanel.Third-party metadata, privacy, cross-border, and client-confidentiality risk where usage data can identify legal work patterns. [4][5]
May 2026 TanStack supply-chain attackMalicious npm packages were published; two OpenAI employee devices were compromised; credential material was exfiltrated from internal code repositories; certificate rotation was required.Supplier oversight and inherited supply-chain risk for firms relying on OpenAI’s development and vendor ecosystem. [6]
Four breach pathways mapped to notification, due diligence, privacy, and supplier oversight obligations

The Redis bug is the cleanest notification problem

The March 2023 Redis incident is the one most likely to make a privacy lawyer reach for the notification chart. OpenAI said a bug in the Redis open-source library made it possible for some users to see other users’ chat titles. It also said payment-related information for a subset of ChatGPT Plus subscribers may have been visible, including first and last name, email address, payment address, the last four digits of a credit card number, and credit card expiration date. OpenAI described the affected payment window as a nine-hour period on March 20, 2023. [1]

For ordinary consumer use, a chat title may look like weak metadata. In a law-firm environment, it can be different. A title such as a client name plus “termination strategy,” “merger antitrust review,” or “settlement authority” may disclose more than a user intended, even if the underlying prompt text was not exposed. ABA Model Rule 1.6 is not limited to documents formally labeled confidential. It protects information relating to the representation of a client, which is why matter-identifying metadata deserves attention even when no memo, pleading, or contract was exposed.

ABA Formal Opinion 512, issued in July 2024, gives that analysis a practical baseline. The opinion says lawyers using generative AI must understand the relevant tool well enough to protect client information, including whether the tool is “self-learning” and whether information entered into it may be used in ways the client has not authorized. It also states that informed consent may be required before inputting client information into a generative AI tool. [2]

That does not mean every Redis-exposed chat title would automatically require client notice. It means a firm would need a defensible way to answer basic questions: which users had access, whether those users were permitted to enter client information, whether chat titles were generated from client-related prompts, whether any title identified a client or matter, and whether billing fields combined with other identifiers triggered statutory breach-notification duties. If the firm’s policy merely said “do not enter client data” but the product had no technical restriction, no logging review, and no sanctioned workspace boundary, the policy may not carry much weight when the firm reconstructs what happened.

The employee-forum breach is a diligence problem before it is a notice problem

The reported 2023 employee-forum breach sits in a different category. SecurityWeek, citing New York Times reporting, said a hacker obtained secrets from an internal OpenAI employee discussion forum and that OpenAI did not disclose the incident to customers or the FBI at the time. The reporting did not describe the event as an exposure of customer prompts or billing records. [3]

That distinction matters. If no firm data, client data, or personal data held for the firm was exposed, a law firm may not have a breach-notification event to analyze. But the non-disclosure detail still belongs in a vendor-risk file. A firm assessing an AI provider is not only buying a product feature set; it is relying on the provider’s internal escalation culture, security governance, and willingness to tell customers when an incident may affect their risk posture.

Rules 1.1 and 5.3 make that a professional-responsibility issue, not only a procurement preference. Competence now includes understanding the relevant benefits and risks of technology. Supervision of non-lawyer assistance includes taking reasonable steps to ensure outsourced services are compatible with the lawyer’s professional obligations. For an AI vendor, reasonable diligence may include asking what categories of incidents are contractually reportable, whether internal compromises that do not expose customer content are disclosed through security advisories, and whether the vendor will provide enough detail for the firm to decide whether client notice, regulator notice, or client-relations outreach is necessary.

A firm cannot ask in 2026 whether a vendor disclosed an incident that was not public in 2023. It can, however, update the intake questionnaire, the contract annex, and the renewal review once that fact pattern is known. The point is not to punish a vendor for every internal security event. The point is to avoid a contract in which the vendor alone decides that an incident is immaterial while the law firm remains responsible for explaining its own reliance to clients, insurers, and regulators.

The November 2025 Mixpanel exposure is the incident legal organizations should spend time on even if no prompt content was reported exposed. Euronews reported that OpenAI confirmed a ChatGPT data breach involving Mixpanel, a third-party analytics provider, and said the exposed information included names, email addresses, and approximate location data. [4] Windows Central also reported exposure of names, emails, and additional account-related details, while noting OpenAI’s statement that passwords, payment information, government IDs, and chat contents were not exposed. [5]

For a law firm, the legal issue is not limited to whether prompt text left OpenAI. Analytics metadata can describe a person’s relationship to a service, timing of use, location, and sometimes organizational role. If a partner, investigator, or client-facing legal operations employee uses an AI account tied to a firm email address, names and email domains may identify the institution. Approximate geolocation may add jurisdictional facts. Usage tied to API access may suggest that a legal workflow, not just casual experimentation, was connected to the platform.

OpenAI reportedly terminated Mixpanel as a vendor after the incident. [4] That is a meaningful remediation fact, but it does not answer the downstream questions for a firm. The firm still needs to know whether Mixpanel or similar analytics providers appeared in the relevant data-flow diagram, whether the firm’s contract restricted analytics use, whether personal data crossed borders, whether the vendor was a processor, subprocessor, or independent controller for the relevant processing, and whether client confidentiality commitments reached account metadata as well as prompt content.

The GDPR analysis also needs care. Names, email addresses, and approximate location data are personal data. Whether a notification obligation arises depends on the risk to individuals, the controller-processor relationship, contractual allocation, and the facts of the exposure. A law firm should not assume that “no chat content” means no privacy analysis. It also should not assume that every analytics incident requires client notice. The review turns on whose data appeared, where the affected individuals were located, what the vendor relationship required, and whether the exposed fields could connect legal work to identifiable people or organizations.

The Italy Garante fine belongs here only as context, not as a fifth security incident. Reuters reported in December 2024 that Italy’s data protection authority fined OpenAI €15 million over ChatGPT privacy-rule breaches; the proceeding concerned privacy compliance, not the Mixpanel exposure itself, and the fine was under appeal. [7] The useful lesson for legal teams is narrower: European privacy authorities have already treated ChatGPT-related data practices as regulatorily significant, so cross-border assumptions in AI intake should be written down rather than left to vendor marketing language.

TanStack is supplier risk, not a prompt-leak story

The May 2026 TanStack supply-chain attack should not be analyzed as though it were the Redis bug with different branding. TechCrunch reported that 84 malicious npm packages were published in six minutes, that two OpenAI employee devices were compromised, that credential material was exfiltrated from internal code repositories, and that certificate rotation was required. [6]

Those facts point to inherited supplier risk. A law firm using OpenAI tools is relying on more than the visible product interface. It is relying on the provider’s endpoint controls, developer access controls, package-publishing hygiene, repository segmentation, secrets management, and incident response. Most lawyers do not need a technical explanation of npm to understand the consequence: a compromised dependency or developer environment can create risk before any lawyer types a confidential prompt.

The certificate-rotation detail is particularly important. Rotation is not a public-relations flourish; it is the operational step taken when trust in credentials, signing material, or related access paths may have been affected. A firm reviewing this class of incident should ask whether the vendor can describe the containment boundary, the affected systems, the credential classes involved, the rotation timeline, and any customer-facing implications. If the vendor will not provide that information directly, the contract should at least specify what incident summaries, attestations, and audit materials the firm is entitled to receive.

There is a familiar legal-sector analogue. The available reporting identifies this as the same class of supply-chain compromise used by Clop against law firms through third-party file-transfer tools in 2023. That comparison should not be stretched into a claim that OpenAI’s event caused the same harm. It does show why firms cannot confine AI risk review to prompt retention and training use. Supplier compromise can arrive through software dependencies, developer systems, and credential material that the customer never sees.

Four distinct breach vectors approaching a law book and gavel

The same incident can implicate different duties inside the firm

A practical intake review should separate at least five internal owners. Privacy counsel decides whether personal-data or breach-notification obligations have been triggered. Conflicts or risk counsel decides whether matter-identifying information may have been exposed. Procurement and security review vendor commitments, subprocessors, audit rights, and incident-notice clauses. Practice leadership decides whether lawyers used the tool outside approved workflows. Client relationship partners decide whether a disclosure is legally required, contractually required, or strategically necessary to preserve trust.

QuestionWhy it matters
Did the exposed data include client names, matter names, adversary names, or transaction labels?This determines whether metadata may become Rule 1.6 information rather than ordinary account data.
Was the exposure inside OpenAI, inside a subprocessor, or inside an open-source supply chain?The answer changes contractual notice, vendor supervision, and remediation expectations.
Were names, email addresses, payment fields, or approximate geolocation exposed?These fields affect breach-notification and privacy analysis even when prompt content was not exposed.
Did the firm technically restrict client-data entry, or merely discourage it by policy?A written rule without enforcement, logging, or workspace controls may be difficult to defend after an incident.
What incident categories must the vendor disclose to the firm?Internal compromises, analytics-vendor exposures, and customer-content incidents should not be treated as one notice category.

The financial context is real but should not be misused. IBM’s 2025 Cost of a Data Breach materials, as summarized by CNIC Solutions, reported a U.S. average breach cost of $10.22 million, described as an all-time high, and reported that shadow AI added a $670,000 premium. The same summary stated that 63% of breached organizations lacked formal AI governance policies. [8] Those numbers do not prove what any OpenAI incident cost any law firm. They do support a narrower point: unmanaged AI use makes breach response more expensive because the firm first has to discover where the tool was used, by whom, and with what data.

Shadow use is where many firms lose the cleanest argument. If approved AI use happens only in a governed enterprise environment, the firm can review contracts, retention settings, logging, access controls, and vendor notices. If lawyers use personal accounts, browser extensions, trial API keys, or client-provided tools without review, the firm may not know whether Redis-type metadata, Mixpanel-type analytics data, or supply-chain exposure touched legal work until after the incident has already moved past the first response window.

A defensible posture separates the four risk classes

The right conclusion is not that law firms must avoid OpenAI tools, and it is not that the tools are safe because no single incident proves catastrophic exposure of client files. The defensible position is more administrative and less dramatic: approve use only inside defined data boundaries, and map each incident class to a different control.

  • For Redis-type exposures, require prompt and title controls, matter-name restrictions, user logging, and a plan for reviewing whether exposed metadata relates to client representations.
  • For employee-forum or internal-compromise events, require contract language explaining which security incidents must be disclosed even when the vendor believes customer content was not exposed.
  • For Mixpanel-type third-party exposures, review subprocessors, analytics data fields, cross-border transfers, retention, and whether account metadata can identify client or matter activity.
  • For TanStack-type supply-chain attacks, ask about secure development practices, secrets management, dependency controls, certificate rotation, and customer-facing incident attestations.
  • For all four, align the AI-use policy with ABA Formal Opinion 512 by deciding when informed client consent is required before client information enters the tool.

That posture is not glamorous, but it is the one a firm can explain. It does not depend on a single verdict about OpenAI’s trustworthiness. It depends on knowing which data the firm allowed into the tool, which vendors and subprocessors touched related metadata, what the contract requires after an incident, and who inside the firm is responsible for deciding whether a legal duty has been triggered.

References

  1. March 20 ChatGPT outage: Here’s what happened, OpenAI, March 24, 2023.
  2. ABA issues first ethics guidance on a lawyer's use of AI tools, American Bar Association, July 2024.
  3. Hacker Stole Secrets From OpenAI, SecurityWeek.
  4. OpenAI confirms ChatGPT data breach. Here is everything we know, Euronews, November 27, 2025.
  5. OpenAI confirms new data breach, exposing names, emails, more, Windows Central.
  6. OpenAI says hackers stole some data after latest code security issue, TechCrunch, May 14, 2026.
  7. Italy fines OpenAI over ChatGPT privacy rules breach, Reuters, December 20, 2024.
  8. Average Cost of a Data Breach 2026 | 46 Facts From IBM & Verizon, CNIC Solutions.

Connected records

Obligations in this jurisdiction

Spotted an error in this record?

Every entry is bound to a primary source. If a field is outdated, a citation is wrong, or you have a source for a newer ruling, send it our way so the record can be corrected or superseded.

Report a correction or send a new-case tip
Blogarama - Blog Directory