Analysis

What Is In-Browser Data Exfiltration? Definition & Examples

Page published

Publication date unknown · First observed: 10 Oct 2026

Coverage timeline

10 Oct 2026nhimg.orgobserved

Single-source analysis — one report is available.

Why it matters

In-browser data exfiltration bypasses server-side controls to steal sensitive AI conversation context, making it a distinct theft surface defenders must protect for copilots and chat interfaces.

A glossary entry from NHI Management Group defines in-browser data exfiltration, the theft of data already rendered in the browser via DOM scraping, clipboard harvesting, malicious extensions, injected scripts, and tab observation. The entry highlights AI chat tools as high-value targets because prompts, responses, and session context can be copied after authentication, citing EchoLeak (Microsoft 365 Copilot) and SalesBleed (Salesforce Agentforce) as examples.