Analysis
What Is In-Browser Data Exfiltration? Definition & Examples
Publication date unknown · Discovered nhimg.org
Page published
Publication date unknown · First observed: 10 Oct 2026
Coverage timeline
Single-source analysis — one report is available.
Why it matters
In-browser data exfiltration bypasses server-side controls to steal sensitive AI conversation context, making it a distinct theft surface defenders must protect for copilots and chat interfaces.
A glossary entry from NHI Management Group defines in-browser data exfiltration, the theft of data already rendered in the browser via DOM scraping, clipboard harvesting, malicious extensions, injected scripts, and tab observation. The entry highlights AI chat tools as high-value targets because prompts, responses, and session context can be copied after authentication, citing EchoLeak (Microsoft 365 Copilot) and SalesBleed (Salesforce Agentforce) as examples.