- What: Over 6.5 million users' data sold by browser extensions
- Impact: User privacy at risk due to lack of transparency
Data Security Report: Over 6.5M users’ data peddled by browser extensions April 29, 2026 Share By SC Staff More than 80 browser extensions with over 6.5 million users have been legally selling procured information for profit, reports Cybernews . Meanwhile, 71% of all Chrome Web Store extensions had no privacy policies, according to a LayerX Security report, which noted that the real figures may even be higher. Among those observed to have peddled user data were 24 streaming service extensions released by an undisclosed publisher targeting users of Hulu, Netflix, Disney+, and other platforms, which have a combined reach of almost 800,000 users. Its policies describe selling analytical reports to streaming services, marketing groups, media research firms, studios, content creators, and other individuals who purchase anonymized viewing data. Moreover, analysts discovered at least 12 ad-blocking extensions that were reserving rights to sell user information, such as Stands AdBlocker and Poper Blocker. There were also 30 extensions that sell data to corporate B2B sales intelligence tools, exposing employee browsing behavior. Organizations have been urged to deploy automated systems that can block or limit suspicious extensions, as well as establish policies on browser extension governance. SC Staff Related Data Security Vimeo confirms customer data accessed following Anodot breach SC Staff April 29, 2026 The breach was claimed by the ShinyHunters extortion group, which threatened to leak the data by April 30 if a ransom was not paid. Data Security Exposed Checkmarx data tied to March supply chain hack SC Staff April 29, 2026 Checkmarx has disclosed that its source code, API keys, MongoDB and MySQL credentials, and other sensitive information exposed by the Lapsus$ hacking operation were obtained from a GitHub repository that was breached as part of a supply chain attack by the TeamPCP threat group last month, according to The Register. Ransomware TeamPCP-linked VECT 2.0 ransomware unintentionally destroys files larger than 128 KB Laura French April 29, 2026 Researchers revealed several “amateur” mistakes made in Windows, Linux and ESXi variants. Related Events Cybercast Beyond the Hype: The Cybersecurity Trends CISOs are Keeping an Eye on in 2026 On-Demand Event Cybercast Beyond the data perimeter: Why next-generation DSPM is the foundation for modern data security On-Demand Event Virtual Conference Securing the Future of Finance: Strategies to Counter Modern Cyber Threats On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Block Cipher Ciphertext Cyclic Redundancy Check (CRC) Data Encryption Standard (DES) Data Loss Prevention (DLP) Data Warehousing Decryption Digital Envelope Digital Signature Digital Signature Algorithm (DSA) You can skip this ad in 5 seconds