Princeton researchers show some analytics firms are still accidentally collecting user passwords, including Mixpanel, which issued fixes after earlier findings
Lily Hay Newman / Wired :
Context & Ripple Effects
This story closes a loop on Mixpanel's earlier password-collection episode, when the analytics vendor was found to be accidentally capturing passwords in some clients' apps from March 2017 to January 2018 and was slow to notify clients and the public. The new Princeton work shows the failure mode was not one vendor's bug but a class of defect still present across analytics firms even after Mixpanel shipped its fixes.
It also fits a broader research pattern in the corpus: academics and independent researchers repeatedly surface data leakage that companies themselves miss, from an ad agency leaving a database with 150K+ personal records open to email addresses leaking to ads and analytics firms via URL query strings.
First-order effects
- Analytics vendors named in the findings, Mixpanel foremost, face renewed client scrutiny of their SDKs just as they were rebuilding trust after the earlier incident and its delayed disclosure.
- Sites embedding these analytics tools must audit what their third-party scripts actually transmit, since the collection happens inside client apps without the site operator's knowledge.
Second-order effects
- Buyers of product analytics gain leverage to demand contractual data-handling guarantees and faster breach notification, pressuring vendors whose slow disclosure in the earlier Mixpanel case became part of the story.
- The pattern echoes adjacent exposures — Spotify resetting user passwords after a bug exposed account data to business partners — pushing companies to treat every embedded third-party script as a potential credential leak vector.
Third-order effects
- If academic audits keep outpacing vendors' own detection, third-party analytics becomes a standing compliance liability, likely driving consolidation toward vendors that can prove data minimization rather than merely patch after publication.
- Repeated researcher-found leaks across analytics, ads, and cleartext storage point toward structural accountability for data flows between sites and their business partners, where responsibility today is diffuse enough that each party assumes another audited it.
The trend: Independent academic auditing is becoming the de facto inspection layer for third-party data collection, repeatedly catching credential and personal-data leakage that analytics vendors' internal processes miss.