Back to news

Fake Perplexity Extension Harvested Searches; Scattered Spider Members Plead Guilty

Two separate cybersecurity developments this week highlight both active threats to end users and accountability closing in on major threat actors.

Fake Perplexity Extension Harvested Searches; Scattered Spider Members Plead Guilty

What happened

Microsoft researchers uncovered a rogue Chrome extension that impersonated the popular AI search tool Perplexity, silently capturing every search query and keystroke entered into the browser's address bar and forwarding them to an attacker-controlled server before passing users on to legitimate results. Google pulled the extension from the Chrome Web Store following responsible disclosure by Microsoft. Separately, two members of the notorious cybercrime collective Scattered Spider entered guilty pleas in a United Kingdom court on the opening day of what had been scheduled as a six-week trial. The charges relate to an August 2024 attack that severely disrupted Transport for London, the agency overseeing the British capital's public transit network.

Why it matters for your business

The fake Perplexity extension is a reminder that browser extensions represent a persistently underestimated attack surface — one that sits directly inside the tools employees use every day. Any extension with permission to read address bar input can exfiltrate search behavior, internal URLs, and sensitive query strings without triggering conventional endpoint alerts. Organizations should audit approved extensions across their fleet and enforce allow-listing policies through endpoint management platforms. The Scattered Spider guilty pleas reinforce that even sophisticated, loosely organized cybercrime groups face real legal consequences, but the group's prior success in breaching large enterprises should prompt security leaders to revisit social engineering controls and multi-factor authentication resilience.

What to watch next

Sentencing details for the two Scattered Spider members have yet to be announced, and other alleged associates of the group face parallel proceedings in the United States, making the coming months a significant test of cross-border cybercrime prosecution. On the browser-extension front, security teams should monitor whether Microsoft or Google disclose additional copycat extensions targeting other high-profile AI brands, a tactic likely to grow as AI-branded tools proliferate and user trust in them deepens.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp