Skip to content
Your AI Chats Aren’t Private: How Chrome Extensions Stole Data From 900,000 Users

Your AI Chats Aren’t Private: How Chrome Extensions Stole Data From 900,000 Users

Industry Updates

By Patricia A. Pramono • Studio 1080, Published on January 20, 2026

AI tools like ChatGPT and DeepSeek have become part of daily work routines, used for brainstorming, coding, drafting emails, even discussing sensitive business strategies. But what if those conversations were quietly copied and sent to someone else?

That is exactly what cybersecurity researchers uncovered in early 2026.

Two Chrome extensions available on the Chrome Web Store were found stealing users’ AI chat histories, impacting more than 900,000 users before they were finally taken down (The Hacker News, 2026; SecurityWeek, 2026).

Furthermore, at least one of these extensions had previously received a “Featured” badge, making it appear legitimate and trustworthy.

The Extensions Behind the Incident

The malicious extensions were listed under the names:

  • “Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI” (approximately 600,000 users)
  • “AI Sidebar with Deepseek, ChatGPT, Claude and more” (approximately 300,000 users)

Both extensions impersonated a legitimate AI sidebar tool from AITOPIA, a popular extension that allows users to interact with multiple AI models from a browser sidebar (The Hacker News, 2026).

.

On the surface, everything looked normal. In reality, hidden code inside the extensions was quietly collecting far more than users expected.

How Did the Attack Actually Work?

This was not a traditional malware attack with obvious warning signs. Instead, it relied on trust, convenience, and permissions.

.

Once installed, the extensions requested access under the pretext of collecting “anonymous analytics data” to improve user experience. When users agreed, the extensions began:

  • Monitoring browser activity using Chrome APIs
  • Detecting when users opened ChatGPT or DeepSeek pages
  • Extracting prompts, AI responses, session IDs, and URLs
  • Sending the collected data to attacker-controlled servers every 30 minutes

To make detection harder, the stolen data was encoded before being exfiltrated to remote command-and-control (C2) servers (The Hacker News, 2026).

In other words, anything typed into AI tools could be copied and sent elsewhere, without users realizing it.

Why This Is More Dangerous Than It Sounds

At first glance, leaked AI chats may not sound as serious as leaked passwords or credit card numbers. But in a business context, the risks are far greater.

Cybersecurity researchers warn that the stolen data could be weaponized for:

  • Corporate espionage

Exposing internal strategies, source code, or product plans.

  • Targeted phishing attacks 

Using real conversations to craft convincing scams.

  • Identity theft, if personal or authentication data was discussed
  • Sale on underground forums 

Turning internal company data into a commodity.

For organizations, the biggest concern is employees may have unknowingly exposed intellectual property, confidential documents, legal discussions, or customer information simply by using AI tools in their browser (SecurityWeek, 2026).

This incident reinforces a growing reality that AI conversations are becoming a high-value data target.

Security researchers have started calling this technique “prompt poaching”, which is the practice of harvesting AI prompts and responses through browser extensions.

What makes this trend particularly worrying is that it doesn’t only involve obviously malicious tools. Some legitimate extensions have also begun collecting AI interaction data under broad or vague privacy policies (The Hacker News, 2026).

What Should Users and Organizations Do Now?

If you or your team installed either of the affected extensions, they should be removed immediately. While the extensions have already been taken down from the Chrome Web Store, removing them helps prevent any further data leakage.

More importantly, this case offers several lessons for businesses:

  • Treat browser extensions as software assets, not as mere add-ons
  • Limit extension usage on corporate devices to approved tools only
  • Review extension permissions carefully, especially those accessing browsing activity or content
  • Educate employees that AI chats may contain sensitive business information

AI tools are powerful productivity boosters, but this incident is a reminder that security often breaks at the convenience layer.

Conclusion

As AI becomes deeply embedded in daily workflows, attackers are adapting just as quickly. Organizations that rely on AI must start treating AI interactions as sensitive data, because attackers already do.

Also read: Governing AI in Practice: A Practical Guide to AI Audits

This is where proactive security visibility becomes critical. With AI-related risks expanding beyond traditional endpoints, businesses need continuous monitoring, threat detection, and incident response capabilities that can identify suspicious behaviors early, before data is silently exfiltrated.

At Cisometric, we help organizations strengthen their security posture through our next-generation Security Operations Center (SOC), combining threat intelligence, monitoring, and incident response to detect emerging attack vectors, including those targeting modern tools like AI platforms and browser-based workflows.

Also read: How Cisometric’s SOC Protected Businesses from Hundreds of Cyber Threats

Schedule a free consultation with our experts today, click here.

For more updates on digital scams, cybersecurity insights, and expert tips, follow our social media:

LinkedIn: Cisometric

Instagram: @cisometric

Youtube: @Cisometric 



Reference:  

Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users

Chrome Extensions With 900,000 Downloads Caught Stealing AI Chats

You may like this...

We use cookies to enhance your browsing experience, analyse site traffic, and deliver relevant content. Choose which cookies you allow. Privacy Policy