Back to feed
News
Now (0-6 months)
January 6, 2026

Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users

January 6, 2026The Hacker News

Summary

Cybersecurity researchers have discovered two new malicious extensions on the Chrome Web Store that are designed to exfiltrate OpenAI ChatGPT and DeepSeek conversations alongside browsing data to servers under the attackers' control. The names of the extensions, which collectively have over 900,000 users, are below - Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI (ID:

Impact Areas

risk
strategic
cost

Sector Impact

For the Cybersecurity sector, this illustrates the need for advanced threat detection mechanisms specifically targeting AI application data theft. For Frontier Models, it emphasizes the crucial role of securing training data and user interaction data to maintain model integrity and user trust.

Analysis Perspective
Executive Perspective

Operational impact: Businesses need to implement stricter security protocols for employee use of AI tools, including vetting browser extensions and educating users on data security risks. AI platform providers must enhance their API security and implement monitoring systems to detect and prevent unauthorized data access, potentially increasing operational costs in the short term but improving data security posture and reducing long-term risk.

Related Articles
News
September 22, 2022
Building safer dialogue agents  Google DeepMind
News
December 22, 2025
Telegram users in Uzbekistan are being targeted with Android SMS-stealer malware, and what's worse, the attackers are improving their methods.
News
20 hours ago
Analysts say the deal is likely to be welcomed by consumers - but reflects Apple's failure to develop its own AI tools.
Companies Mentioned
Technologies
LLM