Sev0

AI security incidents, tracked

All incidents / Supply chain and access

Urban VPN and related extensions harvested AI chats from 8 million users

Urban VPN extension users, disclosed 15 Dec 2025 Supply chain and access Data exposed High

What happened

Koi Security found that Urban VPN Proxy and seven related Chrome and Edge extensions had been capturing users' full conversations with ChatGPT, Claude, Gemini, Copilot and other AI assistants since July 2025 and sending them to the publisher, which shares browsing data with an affiliated data broker.

Urban VPN Proxy is a free VPN extension with more than 6 million Chrome users, a 4.7-star rating and a Google Featured badge. Koi found that version 5.5.0, released on 9 July 2025 and pushed to users through automatic updates, added scripts for ten AI platforms, including ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, DeepSeek, Grok and Meta AI. The scripts intercepted the page's network traffic to capture every prompt and response, conversation IDs, timestamps and the model used, then compressed the data and sent it to the publisher's servers. The collection was switched on by default, ran whether or not the VPN was connected and could not be turned off. The same code was in seven more extensions from the same publisher, including 1ClickVPN Proxy, Urban Browser Guard and Urban Ad Blocker, bringing the total past 8 million users. The publisher's privacy policy says browsing data is shared with its affiliate BiScience, a company researchers have previously documented collecting and selling re-identifiable clickstream data.

How it happened

Supply chain and access: Third-party leak. Data leaked through a vendor or tool connected to the AI service rather than the AI service itself.

Models from several AI vendors were involved. The product was Urban VPN Proxy and related extensions, a type of chatbot.

Impact

Data was exposed. Data involved: chat logs and personal data. The impact spread across a wide ecosystem of developers, users and organizations. Sources give a figure of 8,000,000.

Severity is rated High, calculated from how far the incident reached and how sensitive the data was.

Was the AI at fault?

No. The failure was in the systems, settings or people around the AI, not in the model's behaviour.

Status and timeline

Confirmed by the affected organization, the AI vendor, a regulator or a named security research firm.

It happened or began on 9 Jul 2025. It became public on 15 Dec 2025, 159 days later.

Koi advised users to uninstall the extensions, since uninstalling was the only way to stop the collection. Anyone who used the targeted AI tools with them installed after 9 July 2025 was told to assume those conversations had been captured.

Sources

  1. https://www.koi.ai/blog/urban-vpn-browser-extension-ai-conversations-data-collection
  2. https://www.theregister.com/2025/12/16/chrome_edge_privacy_extensions_quietly/
  3. https://www.csoonline.com/article/4106949/featured-urban-vpn-caught-stealing-private-ai-chats.html

Related incidents

Cite as: Sev0, "Urban VPN and related extensions harvested AI chats from 8 million users", https://sev0.fyi/incidents/2025-12-15-urban-vpn-extensions-harvested-ai-chats/. Data for this record: incidents.json.