Many have browser extensions installed. At a minimum, ad blocker. But when installing extensions, you should be careful: not all of them are useful, and some are used for surveillance at all.



| Extension name | Number of users | Browser | Chrome extension ID (if any) |
| Hover zoom | More than 800,000 | Chrome | nonjdcjchghhkdoolnlbekcfllmednbl |
| SpeakIt! | More than 1.4 million | Chrome | pgeolalilifpodheeocdmbhehgnkkbak |
| Superzoom | 329,000+ | Chrome and Firefox | gnamdgilanlgeeljfnckhboobddoahbl |
| SaveFrom.net Helper | Up to 140,000 | Firefox | N / a |
| Fairshare unlock | More than 1 million | Chrome and Firefox | alecjlhgldihcjjcffgjalappiifdhae |
| PanelMeasurement | More than 500,000 | Chrome | kelbkhobcfhdcfhohdkjnaimmicmhcbo |
| Branded surveys | eight | Chrome | dpglnfbihebejclmfmdcbgjembbfjneo |
| Panel Community Surveys | one | Chrome | lpjhpdcflkecpciaehfbpafflkeomcnb |
| Company | Nacho Analytics Data |
| 23andMe | Published reports 23andMe |
| Alienvault | JIRA data from alienvault.atlassian.net |
| Amazon web services | AWS S3 Authentication Request Strings |
| American airlines | Passenger information: name, confirmation number from the ticket |
| Amgen | Corporate Network Data |
| Apple | The last 4 digits of a credit card when ordering Apple products, type of card, place of receipt of the order, name of the customer, iCloud mailing address |
| AthenaHealth | Corporate Network Data |
| Atlassian | Almost real-time update of tasks for company employees with thousands of sub-domains atlassian.net |
| Blue origin | JIRA data from the domain blueorigin.com |
| Buzzfeed | JIRA data from domain buzzfeed.atlassian.net |
| Capitalone | Zoom Conferences URL from capitalone.zoom.us |
| Cardinalhealth | JIRA data from cardinalhealth.atlassian.net |
| Dell | Zoom Conferences URL from dell.zoom.us |
| Drchrono | Patient names, prescription drug names |
| Epic systems | Network data LAN of corporate network visitors |
| Facebook Messenger applications, including tax returns | |
| Fireye | JIRA data from fireeye.com domain from the corporate network |
| Intuit | Quickbook invoices |
| Kaiser permanente | Network data from a corporate LAN |
| Kareo | Patient Names |
| Merck | Network data from a corporate LAN |
| Microsoft OneDrive | Files from OneDrive hosting, including tax returns |
| NBCDigital | JIRA data from nbcdigital.atlassian.net |
| Nest | Video Recordings from Nest Security Cameras |
| Netapp | Zoom conferencing URL with netapp.zoom.us |
| Oracle | Zoom Conferences URL with oracle.zoom.us |
| Palo alto networks | Corporate Network Data |
| Pfizer | Corporate Network Data |
| JIRA data from reddit.atlassian.net | |
| Roche | Corporate Network Data |
| Shopify | AWS S3 parameter leakage victim |
| Skype | Skype Chat URLs |
| Southwest airlines | Information about passengers: it was possible to track passengers on board almost in real time, and there was enough confidential data in the service to cancel a flight or change a flight |
| Spacex | Corporate Network Data |
| Symantec | Corporate Network Data |
| Tesla | Corporate Network Data |
| Tmobile | JIRA data from tmobile.atlassian.net |
| Trend micro | JIRA data from visitors to the internal subdomain trendmicro.com |
| Uber | Coordinates of taxi pick-up and drop-off points, Zoom conference URLs from uber.zoom.us |
| UCLA | Zoom Conferences URL from ucla.zoom.us |
| Under armor | JIRA data from underarmour.atlassian.net |
| United airlines | Passenger last names and their flight confirmation numbers |
| Walmart | Zoom Conferences URL from walmart.zoom.us |
| Zendesk | Application for tickets in the support service, among which you can search for a specific client |
| Zoom video communications | Zoom Conference URL |

Source: https://habr.com/ru/post/460987/
All Articles