Researchers disclosed two malicious Chrome extensions impersonating the legitimate AITOPIA AI assistant, together downloaded by roughly 900,000 users. The extensions requested consent for “anonymous analytics” but actually exfiltrated complete ChatGPT and DeepSeek conversation content plus all open Chrome tab URLs to an attacker-controlled server every 30 minutes. The stolen data could expose corporate trade secrets, customer information, and personal details entered into AI chat sessions, and researchers warned it could be used for corporate espionage, identity theft, or targeted phishing. The extensions were disclosed on January 6, 2026.