Close Menu
    X (Twitter) LinkedIn
    CapitalAI DailyCapitalAI Daily
    X (Twitter) LinkedIn
    • Markets & Investments
    • Big Tech & AI
    • AI & Cybercrime
    • Jobs & AI
    • Banks
    • Crypto
    Monday, April 27
    CapitalAI DailyCapitalAI Daily
    Home»AI & Cybercrime»Microsoft Warns Fake AI Tools Installed by 900,000 Chrome and Edge Users Are Stealing ChatGPT Conversations, Browsing Data and More

    Microsoft Warns Fake AI Tools Installed by 900,000 Chrome and Edge Users Are Stealing ChatGPT Conversations, Browsing Data and More

    By Henry KanapiMarch 12, 20262 Mins Read
    Share
    Twitter LinkedIn

    Microsoft security researchers say malicious browser extensions impersonating AI assistant tools have spread to roughly 900,000 installs, quietly harvesting chat data and browsing activity from users.

    Microsoft Defender investigators say the extensions specifically target the rapidly growing ecosystem of AI productivity tools embedded inside Chromium-based browsers such as Google Chrome and Microsoft Edge.

    The campaign is designed to exploit the surge in AI-assisted workflows, where employees regularly interact with platforms like ChatGPT and DeepSeek directly inside their browser.

    Microsoft says the malicious tools are distributed through the Chrome Web Store and present themselves as legitimate AI productivity extensions, using familiar branding and interface patterns modeled after real tools. According to Microsoft Defender telemetry, the activity has been observed across more than 20,000 enterprise tenants, where employees frequently use AI assistants while working with sensitive corporate information.

    “The extensions collected full URLs and AI chat content from platforms such as ChatGPT and DeepSeek, exposing organizations to potential leakage of proprietary code, internal workflows, strategic discussions and other confidential data.”

    The campaign also relied heavily on social engineering and user trust.

    Researchers found that the criminals studied legitimate AI extensions, such as AITOPIA, and copied their branding, permissions prompts, and interaction patterns to make the tools appear authentic.

    In some cases, Microsoft says automated agentic browsers even installed the extensions automatically because the descriptions appeared legitimate.

    “User familiarity with installing AI sidebar tools, combined with permissive enterprise extension policies, allowed the extension to reach a broad audience.”

    Once installed, the extension could continue collecting data indefinitely. The malicious tools collected information locally before transmitting it periodically to an external infrastructure, creating a persistent data pipeline from infected browsers.

    “The extension was designed to passively observe user activity, collecting visited URLs and segments of AI-assisted chat content generated during normal browser use.”

    By quietly gathering prompts, responses, and browsing activity tied to AI platforms, the attackers could gain long-term visibility into corporate workflows and internal systems.

    Microsoft warns that the campaign demonstrates how browser extensions tied to AI tools are emerging as a new attack surface for enterprise data theft.

    Disclaimer: Opinions expressed at CapitalAI Daily are not investment advice. Investors should do their own due diligence before making any decisions involving securities, cryptocurrencies, or digital assets. Your transfers and trades are at your own risk, and any losses you may incur are your responsibility. CapitalAI Daily does not recommend the buying or selling of any assets, nor is CapitalAI Daily an investment advisor. See our Editorial Standards and Terms of Use.

    AI Chrome Edge Malware Microsoft
    Previous ArticleGrammarly Sued for Allegedly Using AI To Sell Writing Feedback From Stephen King and Other Authors
    Next Article ChatGPT Accused of Posing as Lawyer After Citing Fake Legal Case and Costing Insurance Firm $300,000: Report

    Read More

    ‘Please Assure Me This Is Not a Scam’ – AI-Powered Scammers Drain 73-Year-Old’s Entire $300,000 Life Savings: Report

    April 27, 2026

    Meta Cutting 8,000 Jobs and Microsoft Offers Employee Buyouts As Big Tech Trades Headcount for AI Dominance: Report

    April 23, 2026

    Citi Teams Up With Google DeepMind to Launch ‘Citi Sky,’ an Always-On AI Wealth Manager That Works Alongside Human Advisors

    April 22, 2026

    Wall Street Veteran Says Bitcoin About To Enter Its Most Bullish Macro Setup Since Inception – Here’s What He’s Watching

    April 22, 2026

    NYSE-Listed Food Firm Holding $182,000,000 in Bitcoin Builds AI Operating System for BTC Corporate Treasury

    April 21, 2026

    Anthropic’s Most Powerful and Dangerous AI Model Mythos Accessed by Hackers on Day One: Report

    April 21, 2026
    X (Twitter) LinkedIn
    • About
    • Author
    • Editorial Standards
    • Contact Us
    • Privacy Policy
    • Terms of Service
    • Cookie Policy
    © 2025 CapitalAI Daily. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.