logoalt Hacker News

cobertostoday at 8:48 AM10 repliesview on HN

I _hate_ how this is written. At no point does it disclose explicitly:

* What systems were accessed

* What information was potentially exposed

* Just how "proactively" they've been about this (no timeline)

* Numbers... The scale of any of it

---

Some comments from quoted portions of article

> Mixpanel detected a smishing campaign ...

Doesn't give any details on who the companion targeted, or how, or how widespread.

> We took comprehensive steps to contain and eradicate unauthorized access and secure impacted user accounts.

So there was definitely _some_ sort of unauthorized access, but doesn't say to which accounts or in what systems

> Performed global password resets for all Mixpanel employees

So... definitely sounds like they expected compromise of Mixpanel employee credentials


Replies

gorgoilertoday at 2:49 PM

Yes, if you accidentally push grandma and her wheelchair over a cliff you probably wouldn’t refer to it as “a recent family incident”. In particular the fourth word, a single letter ‘a’, immediately got my back up. The vagueness and defensiveness of the whole post feels very dismissive and inhuman.

”Out of transparency and our desire to share with our community…” also reminds me when I get a refund that is prefixed with ”as a one-time gesture of goodwill…” instead of ”sorry, we made a mistake”.

show 2 replies
sytsetoday at 3:06 PM

Yes, the OpenAI disclosure about the same incident is much better https://openai.com/index/mixpanel-incident/

show 2 replies
jacquesmtoday at 9:31 AM

It makes you wonder if Mixpanel would have disclosed this if not for OpenAI more or less forcing them to.

nolroztoday at 2:39 PM

I got a much more informative disclosure the day before from Open AI.

show 1 reply
jbochitoday at 1:50 PM

Announcing the breach on Thanksgiving day was also certainty calculated.

show 1 reply
reddalotoday at 9:38 AM

Also, I had never heard the word "smishing" before. I don't get what's different from "normal" phishing.

show 3 replies
breppptoday at 8:57 AM

but they registered the IOCs in their SIEM platform, so no way this will happen again

show 1 reply
SilverElfintoday at 5:17 PM

Related, Gainsight - some other customer analytics thing - was also breached. See here:

https://news.ycombinator.com/item?id=46071239

And it looks like many companies got affected because their data was stolen via gainsight. The hackers said they plan to ask the companies for ransoms.

tedgghtoday at 4:38 PM

Expect the worst.