OpenClaw vulnerabilities enable data leakage and prompt injection
In January 2026, researchers at Giskard exploited a deployment of OpenClaw, an open-source agentic AI. They found that architectural weaknesses in the Control UI and session management allowed prompt injection and unauthorized tool use, leading to potential data leakage across user sessions. The article outlines hardening steps to prevent such vulnerabilities.
- AI system involved
- OpenClaw
6 source articles · read the reporting →
Mother targeted by AI voice cloning scam in fake kidnapping
A mother in Arizona received a phone call from scammers who used AI to clone her daughter's voice, making her believe her daughter had been kidnapped. The scammers demanded a ransom, but the mother confirmed her daughter was safe before paying. The incident highlights the growing threat of AI voice cloning scams.
3 source articles · read the reporting →
Mexican government agencies hacked using Anthropic's Claude AI
Anthropic's Claude large language model was weaponized by attackers to compromise numerous Mexican government agencies over a month-long campaign starting December 2025. The attackers used Claude to identify 20 security flaws and craft exploit scripts, stealing 150 GB of data including 195 million taxpayer records, civil registry files, voter lists, and government employee credentials. Both Mexico's tax authority and national electoral institute have dismissed the breach.
- Company involved
- Anthropic
- AI system involved
- Claude
5 source articles · read the reporting →
Herbert Brooks v. Lowes Home Centers LLC (W.D. Louisiana): AI-hallucinated content in court filing, Monetary Sanction; CLE
Generated a legal brief with hallucinated case law, filed in court.
- AI system involved
- Claude
1 source article · read the reporting →
CommNV vs Uprise (Nevada DC): AI-hallucinated content in court filing, Monetary Penalty OR Order to volunteer and teach about AI…
The AI system generated fabricated legal citations that were included in a court filing, misleading the court and opposing counsel.
- Company involved
- Christopher Day
1 source article · read the reporting →
Edinburgh Woman Loses £17,000 in Deepfake Romance Scam
A 77-year-old retired lecturer from Edinburgh lost £17,000 after being deceived by deepfake videos in an online romance scam. The victim, Nikki MacLeod, believed she was in a relationship with a woman named Alla Morgan and sent money via gift cards, bank transfer, and PayPal. She later realised the videos were fake and is warning others about the use of AI by scammers.
6 source articles · read the reporting →
Italian bank (Fideuram / Intesa Sanpaolo) loses about 95 million euro to AI voice-clone scam
The AI-generated voice deceived the chairman into authorizing transfers of about 95 million euros.
1 source article · read the reporting →
Lawsuit claims facial recognition program led to wrongful arrest - FOX 2
Identified Christopher Gatlin as a suspect in an assault, leading to his arrest and 17 months in jail.
- Company involved
- St. Louis County Police Department
- AI system involved
- Rekognition
1 source article · read the reporting →
Mr Craig Hadley wrongly accused of fraud at Sports Direct shop using Facewatch facial recognition.
Mr Craig Hadley was wrongly accused of being a fraudster at a Rotherham Sports Direct shop using facial recognition technology supplied by Facewatch. The system flagged him as a known fraudster, but the alert was later attributed to human error. Big Brother Watch, a privacy campaign group, has raised concerns about the lack of due process in such systems.
- Company involved
- Sports Direct
- AI system involved
- Facewatch
2 source articles · read the reporting →
Illinois appeals court fines lawyer $15,000 for fictitious citations in Scott v. Illinois Human Rights Commission
In Scott v. Illinois Human Rights Commission, an Illinois Appellate Court case, a lawyer's filings contained fictitious legal citations and misquoted statutes. The court fined the lawyer $15,000 and referred the matter to the bar.
- AI system involved
- ChatGPT
1 source article · read the reporting →
Carlisle woman, 82, dies after losing 35,000 pounds to Nigel Farage deepfake scam
The deepfake video convinced the victim to invest in a fraudulent scheme, leading to financial loss.
1 source article · read the reporting →
Pearl Gardner v. Nationstar Mortgage LLC (D. Arizona): AI-hallucinated content in court filing, Bar Referral
Pro Se Litigant | D. Arizona | State(s): USA. AI tool: Clearpoint. Problem: Fabricated: Case Law. Consequence: Bar Referral.
1 source article · read the reporting →
AI-generated deepfake used in scam claiming Croatian doctor was murdered
A video generated by artificial intelligence was posted on Facebook falsely claiming that Dr. Alemka Markotić, director of a Zagreb infectious disease clinic, had been murdered. The deepfake depicted a TV host and Dr. Markotić promoting a non-existent joint pain treatment. The accompanying link led to a fake article designed to trick users into purchasing a dubious medical product, with the scam exploiting the doctor's public image to appear credible.
- Company involved
- Facebook
- AI system involved
- AI video generator
1 source article · read the reporting →
Del Biaggio v. Bansen (CA California (4d)): AI-hallucinated content in court filing, Monetary Sanction
The AI generated fake legal citations that were included in an appellate brief, affecting the court and the client.
- Company involved
- Carlton Floyd
1 source article · read the reporting →
Ashley St. Clair alleges Grok generated sexual deepfake images of her
Ashley St. Clair, the mother of one of Elon Musk's children, alleges that xAI's chatbot Grok generated and published sexual deepfake images of her on X without her consent. She says she asked Grok to stop but it continued producing more explicit images. She filed a report with xAI, and some images were removed. She is considering legal action.
- Company involved
- xAI
- AI system involved
- Grok
4 source articles · read the reporting →
Capital Standard, LLC v. U.S. Bank National Association (CA Florida (2d)): AI-hallucinated content in court filing, Monetary Sanction; Adverse Costs…
The AI generated false legal citations that were included in a court filing, misleading the court.
1 source article · read the reporting →
Michael Smith pleads guilty to AI-powered streaming fraud for $8 million in royalties
Michael Smith, a North Carolina man, pleaded guilty to conspiracy to commit wire fraud for operating a scheme that used AI-generated music tracks and automated bots to generate billions of fake streams, fraudulently obtaining over $8 million in royalties from streaming platforms. The scheme diverted money from real artists and rights holders. Smith agreed to forfeit the $8,091,843.64 and faces up to five years in prison at sentencing in July 2026.
2 source articles · read the reporting →
AI deepfake scam cons Los Angeles woman out of life savings
A South Los Angeles woman, Abigail, was deceived by scammers using AI-generated deepfake videos to impersonate 'General Hospital' actor Steve Burton. Believing she was in a relationship with the celebrity, she sent at least $81,304 in gift cards, cash and bitcoin, and sold her condo for $350,000 before her daughter intervened. The family has filed a lawsuit to reverse the home sale, and the real Steve Burton says hundreds of fans have been similarly targeted. The victim, who has bipolar disorder, is now in debt and facing bankruptcy.
3 source articles · read the reporting →
Jackie L. Miller v. Regions Bank (N.D. Alabama): AI-hallucinated content in court filing, DQ from case and court (6 months);…
Attorney H. Gregory Harp was sanctioned with a public reprimand, disqualification from the case, a six-month court suspension, and a bar referral for filing AI-hallucinated legal citations and deleting evidence.
- Company involved
- Regions Bank
- AI system involved
- ChatGPT
1 source article · read the reporting →
State ex rel. Steven Schnell v. Honorable Rebecca Richardson (CA Missouri): AI-hallucinated content in court filing, Monetary Sanction
The AI-generated fictitious case citations misled the court and caused opposing counsel to incur attorney's fees.
- Company involved
- Jenna Rohr Conley
1 source article · read the reporting →
DFFH breaches privacy by using ChatGPT in child protection report
A child protection worker at the Department of Families, Fairness and Housing (DFFH) used ChatGPT to draft a Protection Application Report for the Children’s Court, entering sensitive personal information about a child. The generated content contained inaccuracies that downplayed risks to the child, and the information was disclosed to OpenAI overseas. An investigation by the Office of the Victorian Information Commissioner found DFFH failed to ensure accuracy and protect personal information, contravening IPPs 3.1 and 4.1. DFFH accepted the findings and must now block the use of ChatGPT by child protection workers under a compliance notice.
- Company involved
- Department of Families, Fairness and Housing
- AI system involved
- ChatGPT
9 source articles · read the reporting →
Bengaluru woman loses Rs 3.75 crore in Sadhguru deepfake investment scam
A 57-year-old retired woman in Bengaluru was defrauded of Rs 3.75 crore after scammers used an AI-generated deepfake video of spiritual leader Sadhguru Jaggi Vasudev to promote a fake investment platform called Mirrox. Between February and April 2025, she transferred the money across multiple transactions after being added to a WhatsApp group where fabricated profits were shared to build trust. She realised the fraud when she attempted to withdraw funds and the scammers demanded additional fees, then ceased communication. Police are coordinating with banks to freeze the fraudsters' accounts, but recovery is expected to be challenging.
- Company involved
- Mirrox
- AI system involved
- Mirrox stock trading app
2 source articles · read the reporting →
Consumer Reports calls for action against Meta over scam ad proliferation
Consumer Reports has called on the FTC and state attorneys general to take enforcement action against Meta for allowing billions of scam advertisements on its platforms. According to a Reuters investigation, Meta's own documents showed that the company delivered an estimated 15 billion scam ads per day in 2024, generating billions of dollars in revenue. Meta is accused of failing to identify and remove most scam ads, exposing users to fraudulent schemes and illegal products. Consumer Reports argues that Meta's practices constitute unfair business practices under the FTC Act and state laws.
- Company involved
- Meta
6 source articles · read the reporting →
Solicitors Regulation Authority Ltd v Abhishek Kumar (Solicitors Disciplinary Tribunal): AI-hallucinated content in court filing, Counsel struck off the Register…
AI-generated false legal citations were submitted to the Solicitors Disciplinary Tribunal, misleading the tribunal and the regulator.
1 source article · read the reporting →