Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Entities

Claude users

Incidents Harmed By

Incident 13563 Report
Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

2025-07-09

Security researchers reported that the Urban VPN Proxy browser extension introduced AI conversation–harvesting functionality in version 5.5.0, released July 9, 2025. The extension allegedly intercepted and exfiltrated private conversations from AI platforms including ChatGPT, Claude, Gemini, Grok, and others without a user-facing opt-out. The data, including sensitive personal and financial information, was reportedly shared with affiliated data brokers for commercial analytics.

More

Incident 13951 Report
Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale

2026-02-23

Anthropic said it identified large-scale campaigns that used fraudulent accounts and proxy services to generate high volumes of Claude interactions to extract model capabilities for competitor training ("distillation"). Anthropic attributed the activity to DeepSeek, Moonshot, and MiniMax and said it involved millions of exchanges across thousands of accounts, violating its terms and access restrictions. Anthropic described detection measures, account controls, and indicator-sharing in response.

More

Related Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
 

Entity

Urban Cyber Security Inc.

Incidents involved as both Developer and Deployer
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

BiScience

Incidents involved as Developer
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

Urban VPN Proxy users

Incidents Harmed By
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

General public

Incidents Harmed By
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

Gemini users

Incidents Harmed By
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

Copilot users

Incidents Harmed By
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

ChatGPT users

Incidents Harmed By
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

Chatbot users

Incidents Harmed By
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

Browser extension users

Incidents Harmed By
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

Grok users

Incidents Harmed By
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

Meta AI users

Incidents Harmed By
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

DeepSeek users

Incidents Harmed By
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

Perplexity users

Incidents Harmed By
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

Perplexity

Incidents implicated systems
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

Meta AI

Incidents implicated systems
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

Grok

Incidents implicated systems
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

Gemini

Incidents implicated systems
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

DeepSeek

Incidents involved as Deployer
  • Incident 1395
    1 Report

    Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale

Incidents implicated systems
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

Copilot

Incidents implicated systems
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

Claude

Incidents implicated systems
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

  • Incident 1395
    1 Report

    Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale

More
Entity

ChatGPT

Incidents implicated systems
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

Urban VPN Proxy

Incidents implicated systems
  • Incident 1356
    3 Reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update

More
Entity

Moonshot AI

Incidents involved as Deployer
  • Incident 1395
    1 Report

    Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale

More
Entity

MiniMax

Incidents involved as Deployer
  • Incident 1395
    1 Report

    Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale

More
Entity

Proxy reseller services

Incidents involved as Deployer
  • Incident 1395
    1 Report

    Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale

More
Entity

Anthropic

Incidents Harmed By
  • Incident 1395
    1 Report

    Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale

Incidents involved as Developer
  • Incident 1395
    1 Report

    Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale

More
Entity

Anthropic customers

Incidents Harmed By
  • Incident 1395
    1 Report

    Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale

More
Entity

National security and intelligence stakeholders

Incidents Harmed By
  • Incident 1395
    1 Report

    Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale

More
Entity

Claude API

Incidents implicated systems
  • Incident 1395
    1 Report

    Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale

More
Entity

Distillation

Incidents implicated systems
  • Incident 1395
    1 Report

    Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale

More
Entity

Model extraction

Incidents implicated systems
  • Incident 1395
    1 Report

    Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale

More
Entity

Account farming

Incidents implicated systems
  • Incident 1395
    1 Report

    Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale

More
Entity

Proxy access infrastructure

Incidents implicated systems
  • Incident 1395
    1 Report

    Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale

More

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2024 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • e1b50cd