In an alarming cybersecurity breach, hackers compromised Chrome extensions of multiple companies, including Cyberhaven, to access sensitive data. The attack, ongoing since December, highlights vulnerabilities in browser extensions.
Hackers Target Chrome Extensions in December Campaign
According to Investing.com, an expert who has studied the campaign and one of the victims reported that hackers have been compromising the Chrome browser extensions of multiple companies since the middle of December.
The data protection business Cyberhaven, located in California, was one of the victims. Cyberhaven acknowledged the hack to Reuters on Friday.
"Cyberhaven can confirm that a malicious cyberattack occurred on Christmas Eve, affecting our Chrome extension," according to the announcement. Public remarks made by cybersecurity professionals were referenced. An investigation by Cyberhaven revealed that these remarks hinted at an assault that was "part of a wider campaign to target Chrome extension developers across a wide range of companies."
Cyberhaven Responds to Federal Investigations
According to Cyberhaven, "We are actively cooperating with federal law enforcement."
It was unclear at the moment how widespread the hacks were.
A common use case for browser extensions is the ability to automate the application of coupons to online shopping sites, among other customization options. For Cyberhaven, the Chrome plugin meant easier data monitoring and security across all of their clients' online apps.
Experts Link Hacks to Sensitive Data Theft
One of Nudge Security's cofounders, Jaime Blasco of Austin, Texas, claimed to have uncovered multiple more Chrome extensions compromised in a similar fashion to Cyberhaven's. In the middle of December, it seemed like at least one had been struck.
According to Blasco, extensions associated with virtual private networks and artificial intelligence were among the others that were impacted. According to him, that pointed to a malicious attempt to steal sensitive information by exploiting as many vulnerable extensions as feasible.
"I'm almost certain this is not targeted to Cyberhaven," added Blasco. "If I had to guess, this was just random."
Questions were directed to the companies implicated by the U.S. cyber watchdog CISA. Alphabet, the maker of the Chrome browser, did not immediately respond to a message requesting comment.


Nvidia Nears $20 Billion OpenAI Investment as AI Funding Race Intensifies
Silver Prices Plunge in Asian Trade as Dollar Strength Triggers Fresh Precious Metals Sell-Off
Elon Musk’s Empire: SpaceX, Tesla, and xAI Merger Talks Spark Investor Debate
Oil Prices Slide on US-Iran Talks, Dollar Strength and Profit-Taking Pressure
Bank of Japan Signals Readiness for Near-Term Rate Hike as Inflation Nears Target
Oracle Plans $45–$50 Billion Funding Push in 2026 to Expand Cloud and AI Infrastructure
Amazon Stock Rebounds After Earnings as $200B Capex Plan Sparks AI Spending Debate
Global PC Makers Eye Chinese Memory Chip Suppliers Amid Ongoing Supply Crunch
Singapore Budget 2026 Set for Fiscal Prudence as Growth Remains Resilient
Nvidia, ByteDance, and the U.S.-China AI Chip Standoff Over H200 Exports
SpaceX Reports $8 Billion Profit as IPO Plans and Starlink Growth Fuel Valuation Buzz
Vietnam’s Trade Surplus With US Jumps as Exports Surge and China Imports Hit Record
Gold Prices Slide Below $5,000 as Strong Dollar and Central Bank Outlook Weigh on Metals
Anthropic Eyes $350 Billion Valuation as AI Funding and Share Sale Accelerate
Nintendo Shares Slide After Earnings Miss Raises Switch 2 Margin Concerns
Jensen Huang Urges Taiwan Suppliers to Boost AI Chip Production Amid Surging Demand
Tencent Shares Slide After WeChat Restricts YuanBao AI Promotional Links 



