Sev0

AI security incidents, tracked

All incidents / Supply chain and access

Fake AI sidebar Chrome extensions stole ChatGPT and DeepSeek chats from 900,000 users

Chrome extension users, disclosed 7 Jan 2026 Supply chain and access Data exposed High

What happened

Two Chrome extensions posing as a legitimate AI sidebar tool secretly sent users' complete ChatGPT and DeepSeek conversations, along with their browsing history, to attacker servers every 30 minutes. One carried a Google Featured badge.

OX Security found two extensions, one with more than 600,000 users and the other with more than 300,000, that copied the look and features of a legitimate AI sidebar extension from AITOPIA, which lets people chat with popular AI models from any web page. On installation they asked for consent to collect anonymous analytics, but instead watched for visits to ChatGPT and DeepSeek, read the full conversations straight from the page, and sent them, together with the address of every open browser tab, to the attackers every 30 minutes. Conversations people have with chatbots at work can include source code, business plans and customer details, so OX warned the data could be used for corporate espionage, targeted phishing or sold on.

How it happened

Supply chain and access: Poisoned package. A malicious or tampered AI package, extension, plugin or MCP server was published and installed by users.

Models from several AI vendors were involved. The product was Fake AI sidebar extensions, a type of chatbot.

Impact

Data was exposed. Data involved: chat logs, personal data and source code. Many organizations were affected. Sources give a figure of 900,000.

Severity is rated High, calculated from how far the incident reached and how sensitive the data was.

Was the AI at fault?

No. The failure was in the systems, settings or people around the AI, not in the model's behaviour.

Status and timeline

Confirmed by the affected organization, the AI vendor, a regulator or a named security research firm.

It became public on 7 Jan 2026.

OX Security reported both extensions to Google on 29 December 2025. At the time of publication they were still available in the Chrome Web Store, though one had lost its Featured badge.

Sources

  1. https://www.ox.security/blog/malicious-chrome-extensions-steal-chatgpt-deepseek-conversations
  2. https://thehackernews.com/2026/01/two-chrome-extensions-caught-stealing.html
  3. https://www.techrepublic.com/article/news-900k-users-chrome-extensions-steal-chatgpt-deepseek-chats/

Related incidents

Cite as: Sev0, "Fake AI sidebar Chrome extensions stole ChatGPT and DeepSeek chats from 900,000 users", https://sev0.fyi/incidents/2026-01-07-fake-ai-sidebar-extensions-stole-chats/. Data for this record: incidents.json.