{"id":5011,"date":"2026-03-29T10:36:49","date_gmt":"2026-03-29T10:36:49","guid":{"rendered":"https:\/\/ft365.org\/index.php\/2026\/03\/29\/experts-sound-alarm-over-prompt-poaching-browser-extensions\/"},"modified":"2026-03-29T10:36:49","modified_gmt":"2026-03-29T10:36:49","slug":"experts-sound-alarm-over-prompt-poaching-browser-extensions","status":"publish","type":"post","link":"http:\/\/ft365.org\/index.php\/2026\/03\/29\/experts-sound-alarm-over-prompt-poaching-browser-extensions\/","title":{"rendered":"Experts Sound Alarm Over \u201cPrompt Poaching\u201d Browser Extensions"},"content":{"rendered":"<div>\n<p><img decoding=\"async\" src=\"https:\/\/ft365.org\/wp-content\/uploads\/2025\/06\/localimages\/ea721ff9-8ba4-4d88-b386-57e9e1606077.jpg?width=64&#038;height=64&#038;mode=crop&#038;scale=both&#038;format=webp\" alt=\"Photo of Phil Muncaster\" loading=\"lazy\"><\/p>\n<\/div>\n<div id=\"cphContent_pnlArticleBody\" data-layout-id=\"2\" data-edit-folder-name=\"text\" data-index=\"0\">\n<p>Security experts have warned users to beware of malicious Chrome extensions designed to secretly monitor and exfiltrate users\u2019 AI conversations.<\/p>\n<p>Expel explained in a blog post, published on March 24, that it had observed \u201cseveral dozen\u201d incidents in the past month of so-called \u201cprompt poaching\u201d by legitimate-looking extensions.<\/p>\n<p>\u201cThe functionality is fairly straightforward \u2013 the browser extension monitors open tabs, and upon seeing an AI client loaded, will monitor for and collect questions and answers using API interception or DOM scraping,\u201d it said.<\/p>\n<p>\u201cThe extension will then package them up and send them to an external server run by the browser extension\u2019s developers.\u201d<\/p>\n<p><em>Read more on malicious browser extensions: Malicious Google Chrome Extensions Hijack Workday and Netsuite.<\/em><\/p>\n<p>There appear to be two main ways that scammers trick their victims.<\/p>\n<p>The first is to impersonate legitimate extensions, such as \u201cChat GPT for Chrome with GPT-5, Claude Sonnet &#038; DeepSeek AI\u201d and \u201cTalk to ChatGPT\u201d from developer AITOPIA. A report from December last year claimed that two of these malicious extensions had accrued as many as 900,000 unwitting users.<\/p>\n<p>A second tactic is to develop and market a legitimate extension, and then insert malicious functionality once the user base has grown large enough. This is the case with the \u201cUrban VPN Proxy\u201d tool spotted by Expel.<\/p>\n<h2><strong>How to Minimize Prompt Poaching Risks<\/strong><\/h2>\n<p>The security vendor urged businesses to prohibit the downloading of AI-related browser extensions and ensure employee use of extensions in general is centrally managed.<\/p>\n<p>\u201cIt almost goes without saying that these plugins open the doors to several risks, including identity theft, targeted phishing campaigns, and sensitive data being put up for sale on underground forums,\u201d Expel warned.<\/p>\n<p>\u201cIn the case of organizations where employees may have unwittingly installed these extensions, they may have exposed intellectual property, customer data, or other confidential information.\u201d<\/p>\n<p>Expel recommended the following:<\/p>\n<ul>\n<li>Suggest approved alternatives to reduce the likelihood of users installing potentially dangerous extensions<\/li>\n<li>Review extension permissions before installation and beware of any that request permissions beyond advertised functionality<\/li>\n<li>Manage extensions using group policy or browser management consoles, limiting use to those which have been reviewed and approved<\/li>\n<li>Run periodic audits to understand usage and monitor browser processes for any tools that connect to unknown domains<\/li>\n<\/ul><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Security experts have warned users to beware of malicious Chrome extensions designed to secretly monitor and exfiltrate users\u2019 AI conversations. Expel explained in a blog post, published on March 24, that it had observed \u201cseveral dozen\u201d incidents in the past month of so-called \u201cprompt poaching\u201d by legitimate-looking extensions. \u201cThe functionality is fairly straightforward \u2013 the<\/p>\n","protected":false},"author":2,"featured_media":5012,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-5011","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"featured_image_urls":{"full":["http:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/5011-fe917717-3539-4cfd-972a-8ee32590dc70.jpg",300,300,false],"thumbnail":["http:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/5011-fe917717-3539-4cfd-972a-8ee32590dc70-150x150.jpg",150,150,true],"medium":["http:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/5011-fe917717-3539-4cfd-972a-8ee32590dc70.jpg",300,300,false],"medium_large":["http:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/5011-fe917717-3539-4cfd-972a-8ee32590dc70.jpg",300,300,false],"large":["http:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/5011-fe917717-3539-4cfd-972a-8ee32590dc70.jpg",300,300,false],"1536x1536":["http:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/5011-fe917717-3539-4cfd-972a-8ee32590dc70.jpg",300,300,false],"2048x2048":["http:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/5011-fe917717-3539-4cfd-972a-8ee32590dc70.jpg",300,300,false],"morenews-featured":["http:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/5011-fe917717-3539-4cfd-972a-8ee32590dc70.jpg",300,300,false],"morenews-large":["http:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/5011-fe917717-3539-4cfd-972a-8ee32590dc70.jpg",300,300,false],"morenews-medium":["http:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/5011-fe917717-3539-4cfd-972a-8ee32590dc70.jpg",300,300,false],"crawlomatic_preview_image":["http:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/5011-fe917717-3539-4cfd-972a-8ee32590dc70-146x146.jpg",146,146,true]},"author_info":{"display_name":"henry","author_link":"http:\/\/ft365.org\/index.php\/author\/henry\/"},"category_info":"<a href=\"http:\/\/ft365.org\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","_links":{"self":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/5011","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/comments?post=5011"}],"version-history":[{"count":0,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/5011\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media\/5012"}],"wp:attachment":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media?parent=5011"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/categories?post=5011"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/tags?post=5011"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}