← The Desk 2026-07-14 The Wire
The Perimeter Site

Eleven AI Chat Exporter Extensions Caught Stealing Data Despite No-Upload Claims

Gus Tavares
2026-07-14
# Eleven AI Chat Exporter Extensions Caught Stealing Data Despite No-Upload Claims The most dangerous tool in your office isn't the outdated server in the closet. It's the "productivity" extension your assistant installed last Tuesday to save ten minutes of formatting. Eleven Chrome extensions designed to export AI chat logs to PDF were just caught uploading full chat contents to external servers. The kicker? Their store listings explicitly claimed they didn't upload data to external servers. It's a clean, simple lie. For a ten-person shop, this is a nightmare because you probably don't have a policy on browser extensions. You just have people trying to be efficient. If you're an enterprise, you have a whitelist. You've paid a team of engineers to ensure only approved software hits the browser. A small firm doesn't have that luxury. You're relying on the honor system and a "No-Upload" badge that means nothing. The fix is free: tell your staff to stop using third-party "exporters." Use the native export tools provided by the AI vendor or the old-fashioned Ctrl+C and Ctrl+V. It's boring, it's manual, and it doesn't send your proprietary strategy documents to a random server in a jurisdiction where you can't sue. Some will argue that these tools are essential for documenting AI workflows at scale. They aren't. The productivity gain of a PDF export is negligible compared to the risk of a full session leak. Then we have the July Microsoft patch dump. This wasn't a routine update; it was a landslide. Microsoft patched a record 622 vulnerabilities. That includes two zero-days in Active Directory and SharePoint Server that were already being exploited. When a vendor drops 622 fixes in one go, the headline is usually about the "record number." For the small business owner, the headline is: "Your MSP is currently drowning." This is the second-order effect nobody prices in. A ten-person shop doesn't patch their own Active Directory; they pay a Managed Service Provider to do it. But when a patch cycle is this massive, the MSPs get overwhelmed. They might prioritize the "critical" ones and miss the "important" ones, or they might push the update and break your legacy accounting software, leading them to delay the patch for "stability" reasons. You think you're covered because you pay a monthly retainer, but you're actually just waiting in a queue behind fifty other clients. I suspect we're seeing the first real bill for the AI-assisted coding craze. Vendors are using LLMs to write code faster, but they're introducing bugs at a rate that human QA can't keep up with. We're trading stability for velocity, and the small business owner is the one who has to live with the resulting vulnerabilities. While we're talking about data leaving the building, ShinyHunters is claiming they've taken 10 million records from Match Group. They've also been linked to other massive leaks recently, like the 4.38 million records from Aflac Japan and nearly 7 million from AssuranceAmerica. The risk here isn't that someone is going to hack your office based on a dating app leak. The risk is credential stuffing. If your office manager uses the same password for their Tinder account as they do for your company's cloud storage or CRM, ShinyHunters just handed the keys to your kingdom to whoever is buying the logs. Enterprise firms use Single Sign-On (SSO) and conditional access to stop this. They can force a password change or block a login from an odd IP address instantly. For a small shop, you don't have an identity team. You have a prayer and a hope that your employees have basic password hygiene. You can't control what your staff does on their personal time, but you can control how they access your business. This is where a boring, free control like MFA (Multi-Factor Authentication) stops being a nuisance and starts being the only thing keeping you in business. If you aren't using a hardware key or a proper authenticator app on every single business account, you're just waiting for a leaked password to become a breach. The tech sector remains the primary target this week, ranking #1 of 15 sectors with 163 stories. Government is a close second at #2. If you're a small vendor selling into either of those sectors, you're in the splash zone. Your customers will start asking you about your patching cadence and your extension policies. Don't give them a fancy slide deck. Give them a date and a version number. One thing to check this week: Open your browser extensions on every work machine. If you see any "AI Assistant," "Chat Exporter," or "PDF Formatter" that you didn't specifically vet, delete it.
◼
← More from the Desk Live Wire →

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.