Back to feed
News
Now (0-6 months)
January 8, 2026

Fake AI Chrome Extensions Steal 900K Users' Data

5 days agoDark Reading

Summary

Threat actors ripped off a legitimate AI-powered Chrome extension in order to harvest ChatGPT and DeepSeek data before sending it to a C2 server.

Impact Areas

cost
risk
strategic

Sector Impact

Cybersecurity: The incident exposes a new vector of attack on AI applications which makes securing AI-based products a higher priority. It directly increases the scope of cybersecurity to include protecting LLM user data from malicious extensions. Frontier Models: The attractiveness of LLMs as targets for data theft increases as their user base grows. Model providers need to work with browser vendors to improve security within browser environments.

Analysis Perspective
Executive Perspective

Businesses using AI-powered extensions need to immediately assess their risk exposure by identifying vulnerable extensions and implementing stricter security protocols, including multi-factor authentication and endpoint protection. Robust employee training is also needed to educate users on identifying and avoiding malicious extensions, along with continuous monitoring of network traffic for suspicious activity related to data exfiltration.

Related Articles
News
September 22, 2022
Building safer dialogue agents  Google DeepMind
News
December 22, 2025
Telegram users in Uzbekistan are being targeted with Android SMS-stealer malware, and what's worse, the attackers are improving their methods.
News
20 hours ago
Analysts say the deal is likely to be welcomed by consumers - but reflects Apple's failure to develop its own AI tools.
Companies Mentioned
Technologies
LLM