Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

July 9, 2025

Security researchers uncovered that the Urban VPN Proxy browser extension, updated on July 9, 2025 to version 5.5.0, incorporated AI conversation-harvesting functionality without user consent. The extension is accused of secretly gathering private conversations from AI platforms such as ChatGPT, Claude, Gemini, and others, including sensitive personal and financial information. This data was allegedly sold to affiliated data brokers for commercial analytics.

Learn more about the HISPI Project Cerebellum TAIM (Govern) initiative to promote trustworthy AI and prevent such incidents. JOIN US

Matched TAIM controls

Suggested mapping from embedding similarity (not a formal assessment). Browse all TAIM controls

Alleged deployer
urban-cyber-security-inc.
Alleged developer
urban-cyber-security-inc., biscience
Alleged harmed parties
urban-vpn-proxy-users, general-public, gemini-users, copilot-users, claude-users, chatgpt-users, chatbot-users, browser-extension-users, grok-users, meta-ai-users, deepseek-users, perplexity-users

Source

Data from the AI Incident Database (AIID). Cite this incident: https://incidentdatabase.ai/cite/1356

Data source

Incident data is from the AI Incident Database (AIID).

When citing the database as a whole, please use:

McGregor, S. (2021) Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database. In Proceedings of the Thirty-Third Annual Conference on Innovative Applications of Artificial Intelligence (IAAI-21). Virtual Conference.

Pre-print on arXiv · Database snapshots & citation guide

We use weekly snapshots of the AIID for stable reference. For the official suggested citation of a specific incident, use the “Cite this incident” link on each incident page.