Sev0AI security incidents, tracked

All incidents / Supply chain and access

Browser extensions harvested private AI chats into a commercial database

AI chatbot users, disclosed 3 Mar 2026. Supply chain and access Data exposed High

A researcher found private chatbot conversations captured by browser extensions, stored in a vector database and sold through an API. The data included healthcare workers pasting patient details and people asking about their immigration status.

Disclosed
3 Mar 2026
Organization
AI chatbot users
Vendor
Multiple models
Product
Browser extensions
Kind of AI
Chatbot
AI's role
AI was the target
How it happened
Supply chain and access: Third-party leak
Harm
Data exposed
Data involved
Chat logs, Personal data, Health
Reach
Many organizations
Severity
High
Model at fault
No
Status
Reported

Sources

  1. https://www.theregister.com/software/2026/03/03/chatbot-data-harvesting-yields-sensitive-personal-info/4166233

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "Browser extensions harvested private AI chats into a commercial database", https://sev0.fyi/incidents/2026-03-03-browser-extensions-harvest-ai-chats/