Reporting described data brokers and “privacy” browser extensions harvesting and monetizing users’ chatbot conversations with services such as ChatGPT, Gemini, Claude, and DeepSeek. The technique cited involves extensions overriding browser fetch() and XMLHttpRequest() to capture prompts and responses, storing them in a vector database and exposing them via API; while IDs may be pseudonymized (e.g., SHA-256 hashes), the captured text can include highly sensitive data (names, dates of birth, medical record numbers, diagnosis codes), creating re-identification and privacy risks.
Separately, dark-web monitoring reported multiple alleged data leak/sale claims and a malware offering: an actor claimed to have exfiltrated an Eholo healthcare-related database (including large volumes of medical notes and PII) and demanded a ransom with a threat to sell the data, and another post advertised an OptimizerAI user database leak (emails, usernames, timestamps, and Discord-related identifiers). The same monitoring also noted additional alleged listings (e.g., PlayStation, Florajet, Coinbase) and promotion of a MalFactory “stealer builder,” but these claims were presented as underground advertisements rather than confirmed incidents.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
A report described a broader attack pattern dubbed 'prompt poaching,' in which malicious browser extensions intercept or scrape AI assistant prompts and responses and exfiltrate them to attacker-controlled servers. The article said responders had handled dozens of such incidents and cited examples including cloned AITOPIA-related extensions and Urban VPN Proxy allegedly adding prompt-harvesting behavior after gaining users.
One of the dark web posts cited by SOCRadar claimed exfiltration of an Eholo healthcare-related database containing 1,146,700 medical notes and 601,308 PII records. The post paired the claim with a $300,000 ransom demand and set a deadline of 2026-03-15.
SOCRadar reported new dark web forum posts offering or claiming leaks involving Eholo, OptimizerAI.xyz, PlayStation, Florajet, and Coinbase, alongside an advertisement for the MalFactory Stealer Builder malware service. The listings described large volumes of alleged user, healthcare, order, and login data, though authenticity was not confirmed.
The Register cited a report alleging that data brokers were selling access to verbatim conversations from AI services including ChatGPT, Gemini, Claude, and DeepSeek. The report said browser extensions overrode networking functions such as fetch() and XMLHttpRequest() to capture prompts and responses, raising concerns about healthcare and corporate data leakage.
Lee S Dryburgh reported querying a major VC-backed "generative engine optimization" platform and retrieving hundreds of unique chatbot prompts and responses containing sensitive personal, medical, legal, and corporate information. The report alleged the data had been harvested from browser extensions marketed as privacy tools and exposed through a commercial API.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesocradar.io
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.