Mixpanel disclosed a security incident involving a smishing campaign that occurred on November 2025. The attack resulted in unauthorized access to a limited number of customer accounts. In response, Mixpanel revoked affected sessions and credentials, blocked malicious IPs, performed password resets, and engaged third-party forensic support. The company stated that customers who did not receive direct communication were not impacted.
IONIX can detect the use of Mixpanel in internet-facing web assets. This IONIX threat center post can help security teams of impacted organizations find potentially affected assets that use Mixpanel, helping them assess the potential impact.
Note: there could be additional assets using Mixpanel that are not listed in this post (e.g. if Mixpanel is used by web apps post-authentication).
References:

