Booking.com still misleading consumers with false '1 room left' claims
Booking.com continues to display misleading scarcity messages on its hotel booking platform, claiming that only one room is left when in fact many more are available. Which? Travel found that five out of ten such claims were inaccurate, with one example showing 34 rooms still available at a London hotel. The Competition and Markets Authority had given Booking.com until 1 September 2019 to change its practices, but the platform has not fully complied. Booking.com says it has worked to implement the commitments agreed with the CMA.
- Company involved
- Booking.com
10 source articles · read the reporting →
RealPage's YieldStar algorithm pushes rents higher for tenants
RealPage's YieldStar algorithm uses private competitor data to recommend rent increases for apartment units. Landlords adopt up to 90% of the suggestions, leading to higher rents for tenants. Critics allege the software may facilitate indirect price-fixing in violation of antitrust law. The company denies wrongdoing and says the software helps eliminate collusion.
- Company involved
- RealPage
- AI system involved
- YieldStar
10 source articles · read the reporting →
341 Malicious ClawHub Skills Found Stealing OpenClaw User Data
Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.
- Company involved
- OpenClaw
- AI system involved
- OpenClaw
4 source articles · read the reporting →
Air Canada Chatbot Fabricates Discount, Leading to Court Case
Air Canada's customer service chatbot allegedly fabricated a discount during a conversation with a customer last year. The incident resulted in a court case against the airline. Insurer Armilla stated that its new AI mishap policy would have covered the loss from selling tickets at the discounted price if the chatbot was found to have underperformed.
- Company involved
- Air Canada
- AI system involved
- chatbot
6 source articles · read the reporting →
Fake Luma Dream Machine AI sites deliver Noodlophile infostealer
Cybercriminals set up Facebook pages impersonating Luma Dream Machine and linked to fake AI video generation websites. Users who uploaded images received an archive containing a malicious executable instead of a video. The executable launched a multi-stage attack that installed Noodlophile, which harvests browser credentials, cookies and cryptocurrency wallet information. Morphisec reported the campaign.
8 source articles · read the reporting →
UDR Sued Over Alleged Use of RealPage Algorithm to Set Rents in San Diego
A class action lawsuit alleges that UDR, Inc. used RealPage's YieldStar algorithmic pricing software to set rental rates and occupancy levels for its San Diego properties, in violation of a local ordinance. The suit claims the software relied on nonpublic competitor data, contributing to inflated rents and making housing less affordable. The lawsuit, filed in July 2026, seeks to represent all affected tenants. UDR has previously acknowledged using YieldStar as one tool among others in its decision-making.
- Company involved
- UDR, Inc.
- AI system involved
- RealPage YieldStar
1 source article · read the reporting →
Trivago loses Australian appeal over misleading hotel rate rankings
The Federal Court of Australia has dismissed Trivago's appeal against a ruling that the online travel company breached Australian consumer law. The court found that Trivago's website used an algorithm that gave prominence to hotels paying higher fees, so the most prominent offers were not always the cheapest for consumers. Consumers may therefore have paid more for rooms, and hotels lost direct bookings. The case returns to the Federal Court for consideration of penalties and other orders sought by the Australian Competition and Consumer Commission.
- Company involved
- Trivago
10 source articles · read the reporting →
Banjo's Live Time system overstated capabilities and posed privacy risks for Utah public safety data
The Utah State Auditor reviewed the contract for Banjo's Live Time public safety application. The system was found to lack advertised AI technology and posed security risks due to direct database queries to PSAP databases. Banjo also overstated its capabilities in its response to the RFP. The auditor concluded that personally identifiable information was unlikely accessed but recommended more rigorous vetting and better security practices.
- Company involved
- Utah Attorney General's Office
- AI system involved
- Live Time
5 source articles · read the reporting →
Gradient app charges users unexpected subscription fees after free trial
The Gradient app, a celebrity lookalike app promoted by the Kardashians, charges users $19.99 per month after a three-day free trial without clear disclosure. Users complained on social media about unexpected credit card charges. The app's developer, Ticket to the Moon, has not addressed the billing complaints but denied collecting user data.
- Company involved
- Ticket to the Moon, Inc.
- AI system involved
- Gradient
9 source articles · read the reporting →
Airbnb smart-pricing algorithm increased racial revenue gap, study finds
A study by Carnegie Mellon University found that Airbnb's smart-pricing algorithm increased the revenue gap between White and Black hosts, even though it narrowed the gap among hosts who adopted it. The algorithm, which sets daily prices automatically, was adopted by fewer Black hosts, so its suggested prices were closer to the optimum for White hosts. The researchers said the tool could reduce racial disparities only if more Black hosts adopted it.
- Company involved
- Airbnb
- AI system involved
- Airbnb smart-pricing algorithm
10 source articles · read the reporting →
Adobe uses Creative Cloud user data to train AI
Adobe's content analysis feature may scan Creative Cloud and Document Cloud files to train machine learning models, including object recognition in Lightroom and Liquid Mode in Acrobat. The company says it may analyze images, audio, video, text and other documents stored on its servers. Adobe offers an opt-out in account privacy settings, but the article notes the company did not ask first.
- Company involved
- Adobe
- AI system involved
- Content analysis
10 source articles · read the reporting →
Tapia robot vulnerability at Henn na Hotels allows remote spying on guests.
A security researcher disclosed a vulnerability in the Tapia robot deployed at Henn na Hotels (Robot Hotels) in Japan. The robot accepts unsigned code via NFC, allowing an attacker to gain remote access to its camera and microphone. The researcher reported the issue to the vendor 90 days prior but received no response. The vulnerability potentially affects all future hotel guests.
- Company involved
- Henn na Hotels
- AI system involved
- Tapia robot
10 source articles · read the reporting →
Amazon sellers lose thousands after RepricerExpress pricing glitch
A software glitch in RepricerExpress's automated repricing system caused products sold by Amazon sellers to be priced at 1p, leading to significant financial losses for the sellers. RepricerExpress apologised but did not offer compensation, while Amazon said it had reached out to affected sellers but many reported no response. Some sellers have instructed lawyers to take legal action against RepricerExpress and Amazon.
- Company involved
- RepricerExpress
- AI system involved
- RepricerExpress
10 source articles · read the reporting →
ScaleFactor reportedly failed to deliver promised automated bookkeeping software
ScaleFactor, an Austin-based startup, is reported to have failed to deliver the automated, real-time bookkeeping tools it promised customers, instead relying on human bookkeepers and a Filipino contract accounting firm. The company told Forbes in June that it was shutting down, initially blaming the pandemic, but Forbes later reported that its problems predated Covid-19. Investors reportedly came to see the company as more of a services business than a software platform, and pulled funding after a pivot to a marketplace model. No legal or regulatory action is reported.
- Company involved
- ScaleFactor
10 source articles · read the reporting →
AI-generated travel guides flood Amazon, deceiving customers
AI-generated travel guides are flooding Amazon, allegedly written by scammers using AI to produce generic, low-quality content. Customers who purchase these guides receive poor information and feel defrauded. Amazon claims to enforce content guidelines but many such books remain on the platform.
- Company involved
- Amazon
8 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
King Features AI tool produces reading list recommending nonexistent books
King Features, a content syndication unit of Hearst, has acknowledged that a summer reading list it produced for newspapers was created with an AI tool and included books that do not exist. A freelance creator used the AI agent without disclosing it, contrary to King Features' policy. The Chicago Sun-Times, which published the section, removed it from its e-paper and said subscribers would not be charged.
- Company involved
- King Features
5 source articles · read the reporting →
Eventbrite algorithm recommended illegal opioid sales to addiction recovery seekers
Eventbrite's recommendation algorithm promoted thousands of listings selling illegal prescription drugs like oxycodone and Xanax alongside addiction recovery events. The listings, which appeared in search results and related events, directed users to unlicensed online pharmacies. Eventbrite acknowledged the issue and removed the listings after WIRED alerted them.
- Company involved
- Eventbrite
- AI system involved
- Eventbrite recommendation algorithm
4 source articles · read the reporting →
Prosecraft shut down after using authors' books without consent for AI analytics
Prosecraft, a fiction analytics site, used the full text of over 25,000 books without author consent to train its AI algorithms and provide writing statistics. Authors protested on social media, demanding removal of their works. The developer, Benji Smith, subsequently shut down the site and wrote a blog post explaining his actions.
- Company involved
- Prosecraft
- AI system involved
- Prosecraft
10 source articles · read the reporting →
OpenDream AI art site allowed users to generate child sexual abuse material
OpenDream, an AI image generation platform, allowed users to generate and publicly display child sexual abuse material (CSAM) and non-consensual deepfakes from at least December 2023 until July 2024. The platform, operated by CBM Media Pte Ltd in Singapore, offered paid plans with NSFW prompts and models. Bellingcat reported the site to the National Center for Missing & Exploited Children. After Bellingcat's inquiry, the CSAM was removed from the site and search engines, and Google terminated OpenDream's AdSense account.
- Company involved
- CBM Media Pte Ltd
- AI system involved
- OpenDream
3 source articles · read the reporting →
Delta uses AI from Fetcherr for domestic ticket pricing
Delta Air Lines is using generative AI from Fetcherr to determine some domestic flight prices, currently covering 3% of its network with plans to reach 20% by end of 2025. Democratic senators expressed concern that the AI could be used for individualized pricing based on personal data, leading to higher fares. Delta denies using personal data in pricing and states it complies with regulations. No actual harm has been reported.
- Company involved
- Delta Air Lines
- AI system involved
- Fetcherr
8 source articles · read the reporting →
Check Point Research finds Google Bard can generate phishing emails and malware
Check Point Research analysed Google's generative AI platform Bard and found it could be used to create phishing emails, malware keyloggers, and basic ransomware code with minimal manipulation. Bard's anti-abuse restrictors were significantly lower than ChatGPT's, making it easier to generate malicious content. The researchers demonstrated these capabilities in controlled tests but did not report actual harm to specific individuals or organisations.
- Company involved
- Google
- AI system involved
- Bard
4 source articles · read the reporting →
CBP One app strands migrants in Mexico, aids organised crime, says HRW
The US Customs and Border Protection's CBP One app, which is mandatory for asylum seekers, offers only 1,450 appointments per day while border arrivals average 7,240. Human Rights Watch reports that this digital metering leaves migrants stranded in Mexico, vulnerable to kidnapping and extortion by organised crime groups. The report alleges that the app enriches criminal cartels and that exceptions for imminent threats are often ignored.
- Company involved
- US Customs and Border Protection
- AI system involved
- CBP One
10 source articles · read the reporting →
Edinburgh Airport AI trial gives passengers different parking prices
Edinburgh Airport admitted it was trialling an AI system that randomly set higher or lower parking prices for online bookers, with customers receiving different quotes for the same service. The Scottish Passenger Agents Association called for the trial to be conducted in controlled 'lab' conditions rather than on the public. The airport said the AI's pricing closely matched staff-set prices and the findings would evaluate whether to adopt the system.
- Company involved
- Edinburgh Airport
- AI system involved
- AI trial for parking pricing
3 source articles · read the reporting →