Copy article

When Your Free VPN Privacy Tool Is Your Biggest Privacy Threat

ended 17. December 2025

Security researchers at Koi have exposed what might be the most intimate data breach yet: browser extensions promising privacy protection have been harvesting and selling complete AI conversations from 8 million users: medical questions, financial details, proprietary code, personal dilemmas. All sold for "marketing analytics purposes."

Urban VPN Proxy, a Chrome extension with 6 million users, a 4.7-star rating, and Google's coveted "Featured" badge, silently updated in July 2025 to capture every conversation users had with ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, and four other AI platforms. The harvesting ran continuously in the background, whether the VPN was connected or not, with no way to disable it except to complete uninstall the 'malware'.

The betrayal is surgical. The extensions warn users about sharing sensitive data with AI companies whilst simultaneously syphoning off those exact conversations to data broker BiScience, which packages and sells the content to advertisers, along with personal identifiers. 

Users installing an Urban ad blocker or VPN for protection woke up one day with code silently mining their most candid thoughts: the kind of things people don't tell anyone else.

Seven other extensions from the same publisher carried identical harvesting code, spanning Chrome and Edge. All but one carried "Featured" badges from Google or Microsoft, signalling they'd passed manual human review and met "high standards of user experience and design." The platforms designed to protect users instead gave these extensions their stamp of approval whilst they harvested what researchers call "the most personal data users generate online."

Extensions the security experts found were:

Chrome Web Store:

  • Urban VPN Proxy - 6,000,000 users
  • 1ClickVPN Proxy - 600,000 users
  • Urban Browser Guard - 40,000 users
  • Urban Ad Blocker - 10,000 users

Microsoft Edge Add-ons:

  • Urban VPN Proxy - 1,323,622 users
  • 1ClickVPN Proxy - 36,459 users
  • Urban Browser Guard - 12,624 users
  • Urban Ad Blocker - 6,476 users

The tool is still available on the Chrome store. Its terms say:

AI Inputs and Outputs. As part of the Browsing Data, we will collect the prompts and outputs quired by the End-User or generated by the AI chat provider, as applicable. Meaning, we are only interested in the AI prompt and the results of your interaction with the chat AI. Due to the nature of the data involved in AI prompts, some sensitive personal information may be processed.

Koi cofounder, Idan Dardikman warns: “If you have any of these extensions installed, uninstall them now. Assume any AI conversations you've had since July 2025 have been captured and shared with third parties.”

We'd like your views:

  • Do you actually know what all your browser extensions do? How do you feel about this deliberate bait-and-switch misuse.
  • How should we feel about Google and Microsoft's "Featured" badges when they legitimise malware? A human reviewer waved this through, either they didn't look, or they looked and didn't care. Is that good enough?
  • When your "privacy protection" becomes your biggest privacy threat, how do you ever trust a browser tool again? 
  • What's the corporate accountability when platform gatekeepers profit from extension stores whilst failing basic oversight? These weren't obscure extensions—6 million users trusted Google's stamp of approval.
  • Is there ever informed consent when policies are full of legalese and have the right to change once initially accepted, and morph into something a typical user would be horrified by?

4 responses from the Newspage community

Copy all

Star Quote
Copy

When things are free, you are the product. For the sake of £3 a month with a reputable VPN provider, people are risking not only their own privacy, but everyone else's info they uploaded. So no matter how careful you might have been, the rug can still get pulled from under you and your privacy lost for good. This isn't just about your medical questions or financial worries ending up in an advertiser's database. It's about the proprietary code debugged, the client strategies workshopped, the sensitive documents analysed. Every conversation they had with their AI assistant whilst that extension was running? Sold.

What makes this particularly grotesque? Google's 'Featured' badge told users it was safe, bringing their QA methods into question. How much more of this productisation and snooping will the public have the stomach for before fighting back. Hard. The Wild West of AI has managed to get a little bit wilder, just when you could be forgiven for thinking that wasn't possible.
Copy

If Google’s ‘Featured’ badge can sit on spyware, it’s not a badge. It’s a trap. Most small business owners do not really know what their browser extensions do. You see “VPN” or “ad blocker”, you think safe. Then it quietly starts copying your team’s most private AI chats. That is medical stuff, pay questions, client pricing, drafts of grievances, settlement wording, bits of code. Now imagine that leaving your business. You are trying to stop leaks in a sieve. Those Featured badges from Google and Microsoft should mean someone actually checked. If a human waved this through, they either did not look or did not care. Neither is good enough when millions are affected and the platforms make money from the store. And consent? If it is buried in legal waffle and can be changed later, it is not informed. It is a gotcha. Keep work browsers boring. Fewer extensions. Only what you truly need. Have a robust IT and comms policy, review it often, train staff on it, and keep bringing it up at
Copy

The 'Featured' badge on browser stores has become a seal of approval for surveillance, not safety. Stop blaming users. Six million people trusted a system Google and Microsoft explicitly stamped as meeting 'high standards'.

Let’s call the verification process what it is: security theatre. We’re told extensions undergo 'manual human review', yet code explicitly written to harvest intimate AI data was waved through. That’s not a review; that’s a rubber stamp.

If a human reviewer misses a script syphoning off 8 million conversation logs, the methodology isn't just lacklustre, it's obsolete. It implies the platforms care more about a slick user interface than actual code security.

The 'Verified' tick is dead. Relying on a platform's badge is like leaving your front door open because a burglar promised to guard it. Until these tech giants face real accountability, the 'Featured' badge is just a marketing gimmick on top of malware.
Copy

People installed these extensions to protect themselves, and instead had their most private thoughts sold off in the background. Medical fears, money worries and confidential work were quietly harvested while users were being warned not to share sensitive data elsewhere. That is not informed consent, it is a bait and switch hiding in legal small print. The platform badges make this worse. Google and Microsoft signalled trust and safety, yet these tools were allowed to run for months at scale. Either no one properly checked, or they did and accepted it. Both should worry consumers. When privacy tools become the biggest privacy threat, trust collapses. Platform gatekeepers profit from these stores and should carry real accountability when oversight fails. If a typical user would be horrified by the reality, consent was never meaningful in the first place.