A Chrome browser extension called Urban VPN Proxy with over 6 million users was found to be harvesting complete AI conversations from major platforms like ChatGPT, Claude, and Gemini, selling this sensitive personal data to third-party data brokers for marketing purposes.
Urban VPN Proxy, a Chrome browser extension with over 6 million users and a 'Featured' badge from Google, was discovered to be secretly harvesting AI conversations from users. The extension, developed by Urban Cyber Security Inc., began collecting this data in July 2025 with version 5.5.0, which introduced AI conversation harvesting by default. The system targets ten major AI platforms including ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, DeepSeek, Grok, and Meta AI. The extension injects dedicated 'executor' scripts into these platforms that override browser functions to intercept all API traffic, capturing user prompts, AI responses, timestamps, and session metadata. This data is then transmitted to Urban VPN's servers and shared with affiliated data broker BiScience for commercial purposes. The harvesting operates continuously regardless of whether the VPN is active, and users have no way to disable it without completely uninstalling the extension. Security researchers at Koi discovered that seven additional extensions from the same publisher, affecting over 8 million total users across Chrome and Edge, contain identical harvesting functionality. The company's privacy policy admits to collecting 'AI Inputs and Outputs' and sharing them for 'marketing analytics purposes,' though the Chrome Web Store listing claims data is not sold to third parties.
Domain classification, causal taxonomy, severity scores, and national security assessments were LLM-classified and may contain errors.
AI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized sharing of data and information can compromise user expectation of privacy, assist identity theft, or cause loss of confidential intellectual property.
Human
Due to a decision or action made by humans
Intentional
Due to an expected outcome from pursuing a goal
Post-deployment
Occurring after the AI model has been trained and deployed