financetom
Business
financetom
/
Business
/
These two browser extensions leaked millions of users' data, including your tax returns
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
These two browser extensions leaked millions of users' data, including your tax returns
Jul 20, 2019 4:11 AM

Popular browser extensions like ad blockers have been caught harvesting personal data of millions of consumers who use Chrome and Firefox -- not only their browsing histories but also exposing tax returns, medical records, credit card information and other sensitive data in the public domain.

According to an independent cybersecurity researcher Sam Jadali, the data has been leaked to a fee-based company called Nacho Analytics that gives unlimited access to any websites analytics data.

The data could be purchased for as little as $10 to $50, said Jadali whose report was first described in Ars Technica late on Friday. "This non-stop flow of sensitive data over the past seven months has resulted in the publication of links to home and business surveillance videos hosted on Nest and other security services.

"Tax returns, billing invoices, business documents, and presentation slides posted to, or hosted on, Microsoft OneDrive, Intuit.com, and other online services" have been exposed, said the report.

The exposed data via eight browser extensions also include vehicle identification, numbers of recently bought automobiles, along with the names and addresses of the buyers. Patient details, travel itineraries, Facebook Messenger attachments and Facebook photos, even private, are now available in the public domain.

Browser extensions - also known as plug-ins or add-ons - are apps that consumers can install to run alongside their browser for additional functionality. The affected extensions were apps used by millions of people, including HoverZoom, SpeakIt!, and FairShare Unlock.

"The extensions have been remotely removed or disabled in consumers' browsers and are no longer available for download," said both Google and Firefox.

People who didn't download the extensions may also be affected. "Nobody is immune to this. Even if you don't have any harmful extensions, the other people you interact with may have an extension on their computers that could be leaking the data you share with them," Jadali was quoted as saying.

Nacho Analytics, for example, promises to let people "see anyone's analytics account" and to provide "real-time web analytics for any website".

The company charges $49 per month, per domain, to monitor any of the top 5,000 most widely-trafficked websites. The security expert has suggested users delete all browser extensions they have installed in the past.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Once a beacon of stability, Vietnam to name third president in a year
Once a beacon of stability, Vietnam to name third president in a year
Mar 22, 2024
HANOI, March 22 (Reuters) - Communist-ruled Vietnam is seeking its third president in little more than a year after the resignation of Vo Van Thuong, who was only elected last year after the sudden dismissal of his predecessor. With accumulated foreign direct investment higher than its gross domestic product, Vietnam's stability is crucial to multinationals with large operations in the...
Cathie Wood's ARK Invest scoops up nearly 10,000 Reddit shares in debut
Cathie Wood's ARK Invest scoops up nearly 10,000 Reddit shares in debut
Mar 22, 2024
(Reuters) - Popular investor Cathie Wood's ARK Invest bought nearly 10,000 shares of Reddit ( RDDT ) in the social media platform's strong market debut on Thursday, an email from the asset manager showed. A total of 9,982 shares of the loss-making company was added to ARK Next Generation Internet ETF ( ARKW ) and ARK Fintech Innovation ETF (...
Japan's union group Rengo announces biggest wage hikes on record
Japan's union group Rengo announces biggest wage hikes on record
Mar 22, 2024
TOKYO (Reuters) -Japanese firms have agreed to raise pay by 5.25% this year, the biggest rise under comparable data since 2013, the country's largest union group Rengo confirmed on Friday. The results of the closely-watched wage negotiations are announced in several stages, in which the blue-chip firms are first to wrap up their talks in mid-March. The second announcement on...
Hutchmed Begins Registration Stage for Phase 2/3 Trial of Investigational Autoimmune Disorder Drug
Hutchmed Begins Registration Stage for Phase 2/3 Trial of Investigational Autoimmune Disorder Drug
Mar 22, 2024
05:04 AM EDT, 03/22/2024 (MT Newswires) -- Hutchmed ( HCM ) said late Thursday it has started the registration stage for a phase 2/3 clinical trial of investigational drug sovleplenib for adult patients with warm antibody autoimmune hemolytic anemia in China. The move follows positive data from the proof-of-concept phase 2 stage of the trial and a consultation with the...
Copyright 2023-2026 - www.financetom.com All Rights Reserved