Close Menu
    X (Twitter) LinkedIn
    CapitalAI DailyCapitalAI Daily
    X (Twitter) LinkedIn
    • Markets & Investments
    • Big Tech & AI
    • AI & Cybercrime
    • Jobs & AI
    • Banks
    • Crypto
    Thursday, March 12
    CapitalAI DailyCapitalAI Daily
    Home»AI & Cybercrime»Microsoft Warns Fake AI Tools Installed by 900,000 Chrome and Edge Users Are Stealing ChatGPT Conversations, Browsing Data and More

    Microsoft Warns Fake AI Tools Installed by 900,000 Chrome and Edge Users Are Stealing ChatGPT Conversations, Browsing Data and More

    By Henry KanapiMarch 12, 20262 Mins Read
    Share
    Twitter LinkedIn

    Microsoft security researchers say malicious browser extensions impersonating AI assistant tools have spread to roughly 900,000 installs, quietly harvesting chat data and browsing activity from users.

    Microsoft Defender investigators say the extensions specifically target the rapidly growing ecosystem of AI productivity tools embedded inside Chromium-based browsers such as Google Chrome and Microsoft Edge.

    The campaign is designed to exploit the surge in AI-assisted workflows, where employees regularly interact with platforms like ChatGPT and DeepSeek directly inside their browser.

    Microsoft says the malicious tools are distributed through the Chrome Web Store and present themselves as legitimate AI productivity extensions, using familiar branding and interface patterns modeled after real tools. According to Microsoft Defender telemetry, the activity has been observed across more than 20,000 enterprise tenants, where employees frequently use AI assistants while working with sensitive corporate information.

    “The extensions collected full URLs and AI chat content from platforms such as ChatGPT and DeepSeek, exposing organizations to potential leakage of proprietary code, internal workflows, strategic discussions and other confidential data.”

    The campaign also relied heavily on social engineering and user trust.

    Researchers found that the criminals studied legitimate AI extensions, such as AITOPIA, and copied their branding, permissions prompts, and interaction patterns to make the tools appear authentic.

    In some cases, Microsoft says automated agentic browsers even installed the extensions automatically because the descriptions appeared legitimate.

    “User familiarity with installing AI sidebar tools, combined with permissive enterprise extension policies, allowed the extension to reach a broad audience.”

    Once installed, the extension could continue collecting data indefinitely. The malicious tools collected information locally before transmitting it periodically to an external infrastructure, creating a persistent data pipeline from infected browsers.

    “The extension was designed to passively observe user activity, collecting visited URLs and segments of AI-assisted chat content generated during normal browser use.”

    By quietly gathering prompts, responses, and browsing activity tied to AI platforms, the attackers could gain long-term visibility into corporate workflows and internal systems.

    Microsoft warns that the campaign demonstrates how browser extensions tied to AI tools are emerging as a new attack surface for enterprise data theft.

    Disclaimer: Opinions expressed at CapitalAI Daily are not investment advice. Investors should do their own due diligence before making any decisions involving securities, cryptocurrencies, or digital assets. Your transfers and trades are at your own risk, and any losses you may incur are your responsibility. CapitalAI Daily does not recommend the buying or selling of any assets, nor is CapitalAI Daily an investment advisor. See our Editorial Standards and Terms of Use.

    AI Chrome Edge Malware Microsoft
    Previous ArticleGrammarly Sued for Allegedly Using AI To Sell Writing Feedback From Stephen King and Other Authors

    Read More

    Grammarly Sued for Allegedly Using AI To Sell Writing Feedback From Stephen King and Other Authors

    March 12, 2026

    OpenAI Board Chair Says Most Companies Are Not Ready To Capture AI Productivity Gains – Here’s Why

    March 11, 2026

    Amazon Wins Court Order Blocking Perplexity AI From Accessing User Accounts

    March 11, 2026

    Microsoft AI CEO Says Health Is the Top Topic for Copilot Mobile Users – And People Ask More Questions at Night

    March 11, 2026

    Oracle Shrinks Teams As AI Code Generation Builds More Software With Fewer Workers

    March 11, 2026

    OpenAI Acquires AI Security Firm Used by 25% of Fortune 500 As Enterprises Deploy ‘AI Coworkers’

    March 10, 2026
    X (Twitter) LinkedIn
    • About
    • Author
    • Editorial Standards
    • Contact Us
    • Privacy Policy
    • Terms of Service
    • Cookie Policy
    © 2025 CapitalAI Daily. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.