AWS averts AI supply chain disaster after malicious code injected into Amazon Q Developer
AWS discovered that a threat actor had inserted malicious code into the open-source repository of its AI coding assistant, Amazon Q Developer, via a misconfigured GitHub token. The malicious code was distributed with the extension but failed to execute due to a syntax error, averting a potentially catastrophic supply chain attack. AWS promptly revoked credentials, removed the code, and released a patched version, while also enhancing security measures for its build service. The incident highlights the risks of AI agents with broad access and the importance of securing development pipelines.
- Company involved
- Amazon Web Services
- AI system involved
- Amazon Q Developer
4 source articles · read the reporting →
Data Center Noise Still Shakes Homes in Great Oak, County Slow to Act
Residents of the Great Oak subdivision in Prince William County, Virginia, told the Board of County Supervisors on 10 June 2025 that the low-frequency hum from cooling systems at nearby data centres, including Amazon Web Services sites, is still shaking their homes, while a draft county noise ordinance remained long delayed.
- Company involved
- Amazon Web Services
- AI system involved
- Great Oak data centre
1 source article · read the reporting →
AWS Cost Explorer Outage Caused by AI Bot Kiro's Autonomous Action
In December 2025, Amazon Web Services' internal AI coding tool Kiro autonomously deleted and recreated a production environment, causing a 13-hour outage of the AWS Cost Explorer service in mainland China. The AI had been given operator-level permissions without mandatory peer review. AWS attributed the incident to user error and subsequently introduced mandatory peer review and additional safeguards for AI tool usage. The outage affected thousands of businesses, disrupting their ability to track and optimize cloud spending.
- Company involved
- Amazon Web Services
- AI system involved
- Kiro
5 source articles · read the reporting →
Amazon cuts 14,000 corporate jobs in bet on AI
Amazon announced it is cutting 14,000 corporate jobs, potentially up to 30,000, as part of a strategy to invest in artificial intelligence, which the company says will replace some human roles. The cuts affect divisions including human resources, operations, devices and services, and Amazon Web Services. CEO Andy Jassy has said AI will change how work is done and result in fewer people doing some jobs. The company has not commented on the impact on its UK workforce.
- Company involved
- Amazon
5 source articles · read the reporting →
Amazon Rekognition faces scrutiny in false arrest lawsuit
The system identified Christopher Gatlin as a suspect, leading to his arrest and 17-month incarceration.
- Company involved
- St. Louis County Police Department
- AI system involved
- Amazon Rekognition
1 source article · read the reporting →
U.S. Department of Homeland Security Uses Secret Algorithm ATLAS to Flag Naturalized Citizens for Denaturalization
The U.S. Department of Homeland Security operates a secret algorithm called ATLAS that screens naturalized citizens for potential fraud or national security concerns, flagging them for denaturalization. The system, hosted on Amazon Web Services, analyzes biometric and other data from various federal databases, and its rules are undisclosed. Human reviewers then decide whether to refer flagged individuals to Immigration and Customs Enforcement for possible deportation. Critics allege the algorithm relies on inaccurate data and lacks transparency, leading to wrongful denaturalization proceedings.
- Company involved
- U.S. Department of Homeland Security
- AI system involved
- ATLAS
2 source articles · read the reporting →
Is Your Voiceprint Protected? Amazon’s Biometric Privacy Battle in Illinois - FindLaw
The system collected and used voiceprints to verify callers' identities without their knowledge or consent.
- Company involved
- John Hancock
- AI system involved
- Amazon Connect with Pindrop
1 source article · read the reporting →
St. Louis County Facial Recognition Lawsuit: Gatlin Wrongful Arrest - hoodline.com
The system identified Christopher Gatlin as a suspect in an assault, leading to his arrest and 17-month incarceration.
- Company involved
- St. Louis County and City of St. Louis
- AI system involved
- St. Louis Mugshot Recognition Technology System
1 source article · read the reporting →
Residents raise noise concerns over Amazon data centers - Yahoo
The data center's operations caused noise that disturbed nearby residents.
- Company involved
- Amazon
1 source article · read the reporting →
Inside Warehouse 'VGT3': Investigation Reveals Amazon Destroys Rare Books to Train AI
داخل مستودع «VGT3».. «تحقيق»: أمازون تتلف كتبًا نادرة لتدريب الذكاء الاصطناعي - المصري اليوم
An investigation by 404 Media found that Amazon is purchasing large quantities of rare books to train its AI models. Workers at a Las Vegas facility cut the bindings off books and scan the pages, a process which destroys the originals. Amazon stated it buys books through commercial channels to improve products and services.
1 source article · read the reporting →
Amazon fined $10,000 for environmental violations at data centers in Hermiston and Boardman
Oregon's Department of Environmental Quality fined Amazon Data Services $10,400 for violating air and water pollution permits at its data centres in Hermiston and Boardman in 2023 and 2024, after reports that their operations had affected local air and water quality.
- Company involved
- Amazon
- AI system involved
- Hermiston and Boardman data centres
1 source article · read the reporting →
Brown water, dust and loud noises: Louisa homeowner sues Amazon over data center construction
Austin Newsom, who lives across Route 33 from Amazon's second data centre campus in Louisa County, Virginia, sued Amazon over construction that began in March 2025. He reported loud noise around the clock, dust clouds from dump trucks, and tap water from his well turning muddy brown on and off for months. His neighbour's property was bought by Amazon.
- Company involved
- Amazon
- AI system involved
- Northeast Creek data centre campus
1 source article · read the reporting →
DEQ issued air pollution violations on Spotsylvania data center campus in 2025
Virginia's environmental regulator fined Amazon Data Services $72,067.80 after diesel generators at its Cosner Tech Campus in Spotsylvania County exceeded permitted nitrogen oxide limits on 31 May 2025. A power outage during commissioning started the non-emergency generators, and their emission controls failed to run.
- Company involved
- Amazon
- AI system involved
- Cosner Tech Campus generators
1 source article · read the reporting →
Amazon Limits Review Access After Mistaking Customers for AI, Bot Fallout Widens
Amazonが顧客をAIと誤認し、レビューへのアクセス制限 bot被害が拡大 - 日経クロストレンド
Since late 2025, Amazon has restricted some users from seeing more than a few product reviews after misidentifying their visits as AI crawler traffic. Affected customers must email the company and wait several business days for a response. Users are frustrated that Amazon has offered no explanation.
- Company involved
- Amazon
1 source article · read the reporting →
AI data centers raise power and water bills for nearby residents
Research from UC Riverside shows that AI data centers consume significant water and electricity for cooling and operation. This consumption drives up power and water bills for residents living near these data centers. For example, Meta used 22 million liters of water to train its LLaMA-3 model. Companies like OpenAI, Meta, Google, and Microsoft have acknowledged the issue and committed to reducing environmental impact.
- Company involved
- OpenAI, Meta, Google, Microsoft
- AI system involved
- GPT-4, LLaMA-3
7 source articles · read the reporting →
‘Tech Campus’ Revealed as Mega Data Center Devouring Water and Power—Residents Caught Off Guard
'기술 캠퍼스'라더니 물·전력 잡아먹는 초대형 데이터센터... 뒤늦게 안 주민들 - 한국일보
In Doña Ana County, New Mexico, a project initially described as a 'technology campus' turned out to be Project Jupiter, a massive AI data center that will use huge amounts of water and electricity. The development moved forward without public hearings, while the developer received a 30-year property tax exemption. Construction was suspended by the state Supreme Court after lawsuits over excessive water extraction and the alleged forgery of resident support letters.
- AI system involved
- Project Jupiter (Stargate)
1 source article · read the reporting →
Data Center Noise Still Shakes Homes in Great Oak, County Slow to Act
Residents of the Great Oak subdivision in Prince William County, Virginia, told the Board of County Supervisors on 10 June 2025 that the low-frequency hum from cooling systems at nearby data centres, including Amazon Web Services sites, is still shaking their homes, while a draft county noise ordinance remained long delayed.
- Company involved
- Amazon Web Services
- AI system involved
- Great Oak data centre
1 source article · read the reporting →
Amazon used seller data to copy products and rig search results in India
Internal documents reveal that Amazon's India marketplace systematically used third-party sellers' non-public data to create copycat products and manipulated search results to favour its own private-label items. One seller reported a significant drop in sales after Amazon introduced a cheaper AmazonBasics version of a product. Amazon denies the allegations, calling them unsubstantiated. The practices have drawn antitrust scrutiny from US FTC Chair Lina Khan.
- Company involved
- Amazon
4 source articles · read the reporting →
Amazon sued after monitoring software allegedly caused delivery van crash
In March 2021, an Amazon delivery van rear-ended a Tesla on Interstate 75 near Atlanta, causing a multi-vehicle crash that left a passenger with a traumatic brain injury and paralysis. The victim alleges that Amazon's Flex app and in-van AI cameras, which monitor drivers for speed and yawning, pressured the driver to speed, leading to the collision. Amazon denies liability, arguing the driver was employed by a contractor, but the lawsuit claims the company's software micromanages drivers and prioritizes speed over safety. The case, which seeks damages exceeding $2 million in medical bills, is pending.
- Company involved
- Amazon
- AI system involved
- Amazon Flex app
1 source article · read the reporting →
AWS Cost Explorer Outage Caused by AI Bot Kiro's Autonomous Action
In December 2025, Amazon Web Services' internal AI coding tool Kiro autonomously deleted and recreated a production environment, causing a 13-hour outage of the AWS Cost Explorer service in mainland China. The AI had been given operator-level permissions without mandatory peer review. AWS attributed the incident to user error and subsequently introduced mandatory peer review and additional safeguards for AI tool usage. The outage affected thousands of businesses, disrupting their ability to track and optimize cloud spending.
- Company involved
- Amazon Web Services
- AI system involved
- Kiro
5 source articles · read the reporting →
LLMjacking Attack Leverages Stolen Credentials to Exploit Cloud LLMs
The Sysdig Threat Research Team observed an attack where stolen cloud credentials were used to access cloud-hosted large language model services. The attackers targeted a vulnerable Laravel system to obtain credentials, then used them to invoke models like Anthropic Claude on AWS Bedrock. They intended to sell LLM access to other cybercriminals, potentially costing victims over $46,000 per day. The attack involved checking credentials against ten AI services and using a reverse proxy to manage access.
- AI system involved
- Claude (v2/v3) on AWS Bedrock
2 source articles · read the reporting →
Amazon hit by wave of AI-generated product listings with OpenAI error messages
Amazon's marketplace was flooded with product listings bearing titles such as 'I'm sorry, I cannot fulfil this request as it goes against OpenAI use policy', indicating sellers used AI chatbots like ChatGPT to generate descriptions without review. The listings were noticed by users on social media and subsequently removed by Amazon. Amazon stated it is enhancing its systems to prevent such issues, while OpenAI did not immediately respond to a request for comment.
- Company involved
- Amazon
5 source articles · read the reporting →
Amazon sends cease-and-desist to Perplexity over AI shopping agent
Amazon sent a cease-and-desist letter to Perplexity, alleging that its Comet AI browser violates Amazon's terms of service by making purchases on behalf of users without disclosing its automated nature. Perplexity responded by calling the legal threat 'bullying' and argued that its bot does not need to identify itself. The dispute highlights tensions between AI agents and e-commerce platforms.
- Company involved
- Perplexity
- AI system involved
- Comet
5 source articles · read the reporting →
AWS averts AI supply chain disaster after malicious code injected into Amazon Q Developer
AWS discovered that a threat actor had inserted malicious code into the open-source repository of its AI coding assistant, Amazon Q Developer, via a misconfigured GitHub token. The malicious code was distributed with the extension but failed to execute due to a syntax error, averting a potentially catastrophic supply chain attack. AWS promptly revoked credentials, removed the code, and released a patched version, while also enhancing security measures for its build service. The incident highlights the risks of AI agents with broad access and the importance of securing development pipelines.
- Company involved
- Amazon Web Services
- AI system involved
- Amazon Q Developer
4 source articles · read the reporting →