Data type harvested
How it is captured
Why attackers want it
Business impact
Full URLs and referrers
Site-wide access and network observation
Reconstruct behaviour, infer tools and vendors, build profiles
Competitive intelligence, targeted phishing
Search queries and browsing history
History, like telemetry, is sent to servers
Advertising value and intent data
Privacy breach, policy violations
Page content from authenticated apps
Content scripts reading the DOM
Emails, tickets, internal docs, customer records
Data breach, regulatory exposure
Cookies or session-adjacent identifiers
Leakage through URLs or page scraping
Session hijack preparation and correlation
Account compromise risk
Extension unique identifiers
Background beacons and storage
Long-term tracking across sessions
Persistent surveillance



