The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

68 incidents closest to “Equifax Ignite” · matched on meaning · public reporting

WF-ZRNJMY22 Feb 2023

Journalist Bypasses Lloyds Bank Voice ID with AI-Generated Voice Clone

A journalist used an AI-generated clone of his own voice to bypass the voice authentication system of Lloyds Bank, gaining access to his account. The experiment, conducted using ElevenLabs' free voice synthesis service, demonstrated that voice biometrics can be fooled by synthetic voices. Lloyds Bank stated it is aware of the threat and is deploying countermeasures, but has not seen real-world fraud using this method. The incident raises concerns about the security of voice verification used by many banks.

Company involved
Lloyds Bank
AI system involved
Voice ID

1 source article · read the reporting →

WF-MQJRJZ20 Oct 2022

French regulator fines Clearview AI €20 million for privacy breaches

France's privacy watchdog CNIL fined US facial recognition firm Clearview AI €20 million for unlawfully collecting and processing facial images of individuals without consent. The company scraped billions of images from websites and social media, selling access to law enforcement. Clearview AI denied being subject to EU law and refused to delete the data, claiming it was impossible to determine French residency from public photos. The CNIL ordered the firm to stop collecting data and delete existing data within two months or face daily fines.

Company involved
Clearview AI

10 source articles · read the reporting →

WF-MTDPWE17 Jul 2025

AI-generated Centrelink phishing emails target 270,000 Australians

More than 270,000 fake emails impersonating Services Australia and Centrelink were detected over four months in a broad phishing campaign. Cybersecurity firm Mimecast reports that cybercriminals are using artificial intelligence to create highly convincing clones of legitimate government communications about benefits. The attack targets vulnerable people and can lead to identity theft, data theft, malware, or ransomware.

Company involved
Services Australia

4 source articles · read the reporting →

Arity collected drivers' data via apps for insurance scores

Popular smartphone apps including Life360, MyRadar and GasBuddy reportedly shared users' location and motion data with Arity, an Allstate-owned company. Arity used the data to calculate driving scores that could be sold to car insurers to set rates. Users were said not to be clearly informed that their data would be used for insurance pricing. Life360 and Arity stated that users had to opt in and that no personally identifiable driving data was shared without consent.

Company involved
Arity
AI system involved
Arity IQ network

2 source articles · read the reporting →

WF-HHAQBE4 Jul 2025

Microsoft Copilot Audit Log Flaw Left Customers Unaware

A vulnerability in Microsoft 365 Copilot allowed users to access files without the access being recorded in audit logs, potentially enabling malicious insiders to exfiltrate data undetected. The flaw, discovered by Pistachio's CTO, was reported to Microsoft in July 2025 and fixed in August, but Microsoft decided not to issue a CVE or notify customers. The vulnerability could be triggered accidentally, meaning many organisations' audit logs may be incomplete. Microsoft classified the issue as 'important' but faced criticism for its lack of transparency.

Company involved
Microsoft
AI system involved
M365 Copilot

1 source article · read the reporting →

Gamma AI Presentation Tool Exploited in Multi-Stage Phishing Campaign

Threat actors used Gamma, an AI-powered presentation builder, to host a page that redirected recipients to a fake Microsoft SharePoint login portal. Emails sent from compromised legitimate accounts passed authentication checks, while a Cloudflare Turnstile blocked automated security scanners. An adversary-in-the-middle framework validated credentials in real time and captured session cookies, enabling multi-factor authentication bypass on Microsoft accounts. Abnormal reported the campaign on 15 April 2025.

AI system involved
Gamma

7 source articles · read the reporting →

Claude Code deletes developer's production database and snapshots

Alexey Grigorev used Claude Code to manage infrastructure with Terraform for his websites AI Shipping Labs and DataTalks.Club. Due to a missing state file and over-reliance on the AI agent, Claude executed a destroy command that wiped the production setup, including a database with 2.5 years of records and snapshots. Amazon Business support helped restore the data within a day. Grigorev is now implementing safeguards to prevent recurrence.

Company involved
AI Shipping Labs
AI system involved
Claude Code

2 source articles · read the reporting →

WF-RQ6Z5D10 Jul 2024

Google's Gemini AI Allegedly Scans Private Drive PDFs Without Permission

Kevin Bankston, a privacy activist, alleges that Google's Gemini AI automatically summarised his private tax return PDF in Google Drive without his explicit consent. Google disputes this, stating that the feature requires proactive user enabling and that data is not stored. Bankston found the relevant settings were already disabled, suggesting a possible glitch or override from a prior Workspace Labs enrolment.

Company involved
Google
AI system involved
Gemini AI

1 source article · read the reporting →

WF-YFC2FF29 Oct 2015

CFPB fines General Information Services for inaccurate background checks

The Consumer Financial Protection Bureau took action against General Information Services and its affiliate e-Background-checks.com for failing to ensure the accuracy of employment background screening reports. The companies allegedly provided inaccurate criminal history information to employers, potentially affecting job applicants' eligibility and causing reputational harm. The CFPB ordered the companies to provide $10.5 million in relief to harmed consumers and pay a $2.5 million penalty.

Company involved
General Information Services

10 source articles · read the reporting →

WF-U5X4EM1 May 2026

Google sues Chinese gang over AI-powered fraud targeting Americans

Google has filed a lawsuit against a Chinese cybercrime group called Outsider Enterprise, alleging it used Google's Gemini AI to create hundreds of fake websites impersonating companies and government services. The group allegedly sent millions of phishing messages to Android users, defrauding hundreds of thousands of Americans of millions of dollars. Google is coordinating with the FBI and wireless carriers to dismantle the network. The lawsuit, filed in the Southern District of New York, seeks an injunction to take down the operation.

Company involved
Outsider Enterprise
AI system involved
Gemini

3 source articles · read the reporting →

WF-VFS58P1 Aug 2025

Microsoft Recall still captures credit cards and passwords despite filter

The Register tested Microsoft Recall's sensitive information filter and found it frequently fails to block credit card numbers, passwords, and other personal data. The AI-powered screenshot tool, which is enabled by default on some new PCs, could expose users to identity theft if an attacker gains access. Microsoft declined to comment but has previously acknowledged the filter is not perfect and promised improvements. Privacy advocates warn that vulnerable users, such as domestic violence victims, could be particularly at risk.

Company involved
Microsoft
AI system involved
Recall

2 source articles · read the reporting →

WF-2K8ESG1 Mar 2019

Fraudsters use AI voice deepfake to trick UK energy firm CEO into transferring $243,000

In March 2019, criminals used commercially available AI voice-generation software to impersonate the CEO of a German parent company. They tricked the CEO of a UK-based energy firm into urgently wiring $243,000 to a Hungarian supplier. The fraud was discovered when the fraudsters attempted a second transfer, which the CEO refused. The company was insured and the loss was covered.

Company involved
Unnamed UK-based energy firm
AI system involved
Commercially available voice-generating AI software

10 source articles · read the reporting →

WF-JWRXGY7 Jul 2020

Cense exposed 2.5 million records of auto accident victims online

On July 7, 2020, a security researcher discovered 2.5 million records containing personal and medical data of auto accident victims exposed online. The records, belonging to New York-based AI company Cense, included names, insurance policy numbers, claim numbers, and medical diagnosis notes. The data was labeled as staging data, possibly intended for temporary storage before being loaded into an AI system. After the researcher sent a responsible disclosure notice, Cense restricted public access to the database.

Company involved
Cense
AI system involved
Cense

5 source articles · read the reporting →

SEC warns public of deep fake investment scams featuring Lance Gokongwei

The Securities and Exchange Commission (SEC) warned the public that scammers are using deep fake videos and audio of Lance Gokongwei to endorse fraudulent investment schemes. The manipulated media circulate on social media, deceiving people into investing in a platform registered in Cyprus. Victims are asked to provide credit card details and OTPs, then lose contact when attempting to withdraw funds. The SEC advises the public to verify investment offers with the agency.

2 source articles · read the reporting →

WF-YK9Q5P10 Feb 2020

Barclays pilot of Sapience monitoring software causes employee stress

Barclays introduced a pilot of employee monitoring software from Sapience in its product control department at Canary Wharf. The system monitors computer activity and admonishes staff if they are not deemed active enough, recording breaks as "unaccounted activity". Employees reported significant stress and worry about taking breaks. Barclays acknowledged the pilot and said it would listen to feedback.

Company involved
Barclays
AI system involved
Sapience employee monitoring software

10 source articles · read the reporting →

DeepScore markets facial and voice analysis app for trustworthiness scoring despite experts' doubts

DeepScore, a Tokyo-based company, is marketing an app that uses facial and voice recognition to score people's trustworthiness for lenders and insurers in Japan, Indonesia, Vietnam and the Philippines. The company says the app can detect deception with 70 per cent accuracy, but researchers and privacy advocates say there is no reliable scientific basis for such judgments and warn of discrimination and privacy harms. The chief executive said the system is only one part of lenders' and insurers' decision-making and that people can choose not to use it. Critics respond that an unequal balance of power makes consent difficult.

Company involved
DeepScore
AI system involved
DeepScore

6 source articles · read the reporting →

WF-IEVM2516 Mar 2021

Facebook Allowed Age-Targeted Credit Card Ads Violating Its Policy

The Markup found that four companies—Aspiration, Hometap, Chime, and Varo Bank—ran Facebook ads for credit cards and home equity loans that were targeted by age, excluding users under 25 or 35. This practice violates Facebook's own anti-discrimination policy and may violate the Equal Credit Opportunity Act and California's Unruh Civil Rights Act. Facebook did not respond to requests for comment, and some advertisers said they would review their ad targeting.

Company involved
Facebook
AI system involved
Facebook Ad Platform

9 source articles · read the reporting →

WF-VU5D658 Apr 2023

California regulator accuses Maxpread Technologies of using AI-generated fake CEO to scam investors

Maxpread Technologies allegedly used an AI-generated avatar to pose as its CEO in a YouTube video to deceive investors. The California DFPI issued cease and desist letters to Maxpread and four other companies for offering unqualified securities and making false promises. The regulator claims the companies promised high daily returns using AI trading, but these claims were false. Maxpread did not respond to requests for comment.

Company involved
Maxpread Technologies

8 source articles · read the reporting →

WF-VR6R0O1 Aug 2019

LoanDepot algorithm denied mortgage to Black couple in Charlotte

In August 2019, Crystal Marie and Eskias McDaniels, a Black couple, were denied a mortgage for a house in Charlotte, North Carolina, by loanDepot's automated underwriting algorithm. The algorithm rejected the application because Crystal Marie was a contractor, not a full-time employee, despite her high credit score and income. After the couple enlisted their real estate agent and employer to intervene, the lender reversed the decision and cleared them to close. The couple alleged that race played a role in the denial, which loanDepot denied.

Company involved
loanDepot
AI system involved
Classic FICO and Fannie Mae/Freddie Mac automated underwriting software

10 source articles · read the reporting →

WF-J5IU7Z3 Dec 2024

FTC settles with IntelliVision over deceptive facial recognition claims

The Federal Trade Commission (FTC) took action against IntelliVision Technologies Corp. for making false, misleading, or unsubstantiated claims about its AI-powered facial recognition software. The company allegedly claimed its software had one of the highest accuracy rates on the market and was free of gender or racial bias, without supporting evidence. The FTC also alleged that IntelliVision did not train its software on millions of faces as claimed, but on images of approximately 100,000 individuals. Under a proposed consent order, IntelliVision is prohibited from making such misrepresentations without competent and reliable testing.

Company involved
IntelliVision Technologies Corp.
AI system involved
IntelliVision facial recognition software

9 source articles · read the reporting →

WF-U4WH351 Jun 2020

ScaleFactor reportedly failed to deliver promised automated bookkeeping software

ScaleFactor, an Austin-based startup, is reported to have failed to deliver the automated, real-time bookkeeping tools it promised customers, instead relying on human bookkeepers and a Filipino contract accounting firm. The company told Forbes in June that it was shutting down, initially blaming the pandemic, but Forbes later reported that its problems predated Covid-19. Investors reportedly came to see the company as more of a services business than a software platform, and pulled funding after a pivot to a marketplace model. No legal or regulatory action is reported.

Company involved
ScaleFactor

10 source articles · read the reporting →

WF-L8981D29 Jan 2025

DeepSeek exposed user data via open ClickHouse database

Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

WF-3333OU22 Sep 2021

EviCore denied heart catheterization for patient using algorithm

In fall 2021, Little John Cupp's doctor requested a left heart catheterization exam. EviCore, a company hired by UnitedHealthcare, denied the request twice using an algorithm called 'the dial' that adjusts thresholds for review. The algorithm flagged the request for review, and EviCore's doctors determined it was not medically necessary. Cupp did not receive the procedure and his symptoms continued.

Company involved
EviCore (a Cigna company)
AI system involved
the dial

6 source articles · read the reporting →

IRCC uses AI triage for Temporary Resident Visa applications

Immigration, Refugees and Citizenship Canada (IRCC) uses an AI system called Advanced Analytics to triage Temporary Resident Visa applications from India and China. The system categorizes applications into tiers, with Tier 1 approved automatically and others sent to human officers. Critics allege the system lacks transparency and may introduce bias, leading to visa refusals without clear rationale. The author, a Canadian immigration lawyer, is filing Federal Court cases on behalf of clients affected by refusals.

Company involved
Immigration, Refugees and Citizenship Canada (IRCC)
AI system involved
Advanced Analytics Triage of Overseas Temporary Resident Visa Applications

10 source articles · read the reporting →

← Newerpage 2 of 3Older →