The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

68 incidents closest to “Mews Payments” · matched on meaning · public reporting

WF-7SKCJ430 Dec 2025

MeetingTV sues Palo Alto Networks' Koi Security over AI-hallucinated threat report

MeetingTV, a video conferencing startup, alleges that Koi Security used an AI system to generate a threat report that falsely linked it to a Chinese espionage operation. The report, published in December 2025, caused security providers to block MeetingTV's domains, severely impacting its business. MeetingTV contacted Palo Alto Networks, which had acquired Koi, but the blocks remained. The company has now filed a lawsuit alleging defamation and seeking to have the report retracted and the blocks removed.

Company involved
Koi Security
AI system involved
Wings

2 source articles · read the reporting →

WF-AY8BHA1 Mar 2022

Court orders suspension of facial recognition in São Paulo metro

A court in São Paulo ordered the suspension of a facial recognition system in the city's metro stations following a lawsuit by civil society groups. The system, SecurOS by ISS and operated by ViaQuatro, was capturing biometric data of millions of daily users without adequate transparency or risk assessment. The court also barred the metro operator, METRO, from installing new biometric equipment and imposed daily fines for non-compliance. METRO stated it would appeal the ruling and prove compliance with data protection regulations.

Company involved
Companhia do Metropolitano de São Paulo (METRO)
AI system involved
SecurOS

3 source articles · read the reporting →

WF-BABUXF28 Feb 2026

McKinsey's Lilli AI Platform Hacked, Exposing 46 Million Chat Messages

Security researchers at CodeWall used an autonomous offensive agent to discover a SQL injection vulnerability in McKinsey's internal AI platform, Lilli. The vulnerability allowed unauthenticated access to the production database, exposing 46.5 million chat messages, 728,000 files, and 57,000 user accounts. The researchers responsibly disclosed the issue to McKinsey, who patched the endpoints within days. No data was exfiltrated or misused, and no disruption occurred.

Company involved
McKinsey & Company
AI system involved
Lilli

1 source article · read the reporting →

WF-XI40RM16 May 2021

FACIL'iti sues accessibility consultant Julie Moynat over critical tweet

In November 2020, Julie Moynat, a web accessibility consultant, tweeted criticism of FACIL'iti, an accessibility product. FACIL'iti sent a formal notice to her employer and later subpoenaed her for denigration in May 2021. Moynat is raising funds for her legal defense. The case is ongoing at the Judiciary Tribunal of Paris.

Company involved
FACIL'iti
AI system involved
FACIL'iti

10 source articles · read the reporting →

LLMjacking Attack Leverages Stolen Credentials to Exploit Cloud LLMs

The Sysdig Threat Research Team observed an attack where stolen cloud credentials were used to access cloud-hosted large language model services. The attackers targeted a vulnerable Laravel system to obtain credentials, then used them to invoke models like Anthropic Claude on AWS Bedrock. They intended to sell LLM access to other cybercriminals, potentially costing victims over $46,000 per day. The attack involved checking credentials against ten AI services and using a reverse proxy to manage access.

AI system involved
Claude (v2/v3) on AWS Bedrock

2 source articles · read the reporting →

WF-ZNMB5S1 Nov 2024

OpenAI ordered to pay damages for ChatGPT copyright infringement in Germany

A Munich court ruled that OpenAI's ChatGPT violated German copyright law by reproducing protected song lyrics without a license. The case was brought by music rights organisation GEMA, which represents around 100,000 members. The court ordered OpenAI to pay undisclosed damages. OpenAI disagrees with the ruling and is considering next steps.

Company involved
OpenAI
AI system involved
ChatGPT

4 source articles · read the reporting →

WF-JLBJ8B5 Nov 2025

Amazon sends cease-and-desist to Perplexity over AI shopping agent

Amazon sent a cease-and-desist letter to Perplexity, alleging that its Comet AI browser violates Amazon's terms of service by making purchases on behalf of users without disclosing its automated nature. Perplexity responded by calling the legal threat 'bullying' and argued that its bot does not need to identify itself. The dispute highlights tensions between AI agents and e-commerce platforms.

Company involved
Perplexity
AI system involved
Comet

5 source articles · read the reporting →

WF-PZRPZR1 Jan 2017

Royal Free London publishes audit into Streams app data processing

The Royal Free London NHS Foundation Trust published an audit into its use of the Streams app, following an investigation by the Information Commissioner's Office (ICO) in July 2017. The Streams app alerts clinicians to patients at risk of acute kidney injury. The audit, conducted by Linklaters, concluded that the trust's use of Streams was lawful and complied with data protection laws, although areas for improvement were identified. The ICO later recognised that the trust had completed all required actions.

Company involved
Royal Free London NHS Foundation Trust
AI system involved
Streams

10 source articles · read the reporting →

MoviePass to use eye-tracking to ensure users watch adverts

MoviePass, the movie subscription service, has announced that its new app will use facial recognition and eye-tracking technology to ensure users are watching adverts. The system, which uses the phone's camera, will pause content if the user looks away. The company says the technology is designed to give advertisers the impact they are looking for. No harm has been reported yet, but the tracking raises privacy concerns.

Company involved
MoviePass
AI system involved
MoviePass app

10 source articles · read the reporting →

WF-RBYKX930 Jun 2025

McDonald’s AI Hiring Platform Exposes 64 Million Applicants’ Data Due to Default Password

In late June 2025, security researchers discovered that McDonald’s AI-powered hiring platform, McHire, had a critical security flaw. A default admin password of '123456' allowed access to a live dashboard containing sensitive data of nearly 64 million job applicants. The researchers also found an insecure direct object reference vulnerability that could expose full applicant profiles and chat logs. McDonald’s and the platform’s vendor, Paradox.ai, quickly fixed the issues and stated that only five records were viewed by the researchers, with no public data leak.

Company involved
McDonald's
AI system involved
McHire

2 source articles · read the reporting →

Inland Revenue warns of AI scam using commissioner's image

Scammers used AI-generated images and messaging to impersonate New Zealand's Commissioner of Inland Revenue, Peter Mersi, in social media ads inviting people to a fake crypto tax webinar. The ads aimed to trick people into giving personal information for identity theft or account access. Inland Revenue received over 3000 scam reports in three months and worked to have the ads removed, but they kept reappearing. The department warned the public about the increasing use of AI in investment scams.

2 source articles · read the reporting →

WF-XG4V8420 Jan 2026

Florida man nearly loses $1,900 in AI puppy scam

Dennis Morida of St. Petersburg, Florida, was scammed after his missing German Shepherd puppy Hazel was falsely reported as injured. A caller claiming to be a police sergeant sent an AI-generated image of Hazel on an operating table and demanded $1,900 for surgery. Morida paid via Zelle, but the dog returned home unharmed and his bank flagged the transaction as fraud, so he recovered the money.

2 source articles · read the reporting →

WF-1O81PG1 Jan 2017

Newham Council fined £145,000 over leaked gang matrix data

Newham Council was fined £145,000 by the Information Commissioner's Office after a leaked unredacted gangs matrix, containing details of 203 suspected gang members, ended up in the hands of rival gang members via Snapchat. The leak occurred in January 2017 when a council employee emailed both redacted and unredacted versions to 44 recipients. The ICO found the breach was unnecessary and that the council failed to report it promptly. The council apologised and accepted the breach was not deliberate.

Company involved
Newham Council
AI system involved
Gangs matrix

8 source articles · read the reporting →

WF-KBSLAS16 Sep 2020

Shipt's new V2 algorithm reduces pay for 41% of workers, study finds

A study by MIT Media Lab and Coworker.org found that Shipt's new V2 payment algorithm reduced pay for 41% of workers by an average of 11% per shop. The algorithm, rolled out in September 2020, replaced a transparent payment system with a black-box model. Workers pooled data to analyze the impact, revealing uneven distribution of earnings.

Company involved
Shipt
AI system involved
V2

10 source articles · read the reporting →

Meta sues Voyager Labs for scraping Facebook and Instagram user data

Meta filed a legal action against Voyager Labs, alleging that the company used fake accounts and proprietary software to scrape user data from Facebook and Instagram. The scraping collected profile information, posts, friends lists, photos and comments. Meta disabled Voyager's accounts and sought a permanent injunction. The case was settled in December 2024, with Voyager agreeing to a permanent injunction and monetary payment.

Company involved
Voyager Labs

10 source articles · read the reporting →

WF-ASJEKJ1 Jan 2021

GSMA fined €200,000 for facial recognition privacy violation at MWC

In 2021, Dr Anastasia Dedyukhina was invited to speak at Mobile World Congress in Barcelona. The organizers required her to upload biometric data (passport) online for identity verification, which she refused. She was then forced to attend virtually. She filed a complaint with the Spanish data protection agency (AEPD) along with Adam Leon Smith. Two years later, the AEPD fined GSMA €200,000 for infringing the privacy of nearly 20,000 attendees through the use of facial recognition without proper justification.

Company involved
GSMA

10 source articles · read the reporting →

WF-SWP73K1 Apr 2023

USPS algorithm RRECS causes pay cuts for two-thirds of rural mail carriers

The United States Postal Service (USPS) implemented a new algorithm, RRECS, to evaluate rural carrier routes and determine pay. Due to flaws in how carriers scanned packages, the algorithm underestimated route times, resulting in pay cuts for 66 per cent of rural carriers, some losing thousands of dollars annually. Carriers report that they were not adequately trained on the system and that the cuts are scheduled to take effect, though they have been postponed multiple times. The USPS stated that the system is the result of a nationally negotiated agreement.

Company involved
United States Postal Service
AI system involved
RRECS

9 source articles · read the reporting →

WF-LBFMV812 Dec 2014

Amazon sellers lose thousands after RepricerExpress pricing glitch

A software glitch in RepricerExpress's automated repricing system caused products sold by Amazon sellers to be priced at 1p, leading to significant financial losses for the sellers. RepricerExpress apologised but did not offer compensation, while Amazon said it had reached out to affected sellers but many reported no response. Some sellers have instructed lawyers to take legal action against RepricerExpress and Amazon.

Company involved
RepricerExpress
AI system involved
RepricerExpress

10 source articles · read the reporting →

TOV Realty, LLC v. Suarez; Kosel Equity, LLC v. MacGregor (SC Connecticut): AI-hallucinated content in court filing, 6 hours CLE;…

The AI generated legal briefs containing fabricated citations, which were submitted to the Connecticut Supreme Court.

Company involved
GLG Law LLC
AI system involved
ChatGPT

1 source article · read the reporting →

WF-UHO4KG31 Aug 2021

Met Police buys £3m retrospective facial recognition system

The Metropolitan Police Service (MPS) has awarded a £3 million, four-year contract to Northgate Public Services for a new retrospective facial-recognition (RFR) system to be deployed within three months. RFR processes biometric information from historic CCTV, social media, and other images to identify suspects and missing persons, operating retroactively unlike live facial recognition. The procurement was approved by the Mayor's Office for Policing and Crime in August 2021. The MPS states that human-in-the-loop decision-making will be used, but digital rights groups and a former biometrics commissioner have raised concerns about potential discrimination, overrepresentation of marginalised groups in watch lists, and lack of a legislative framework.

Company involved
Metropolitan Police Service
AI system involved
Retrospective facial-recognition software

9 source articles · read the reporting →

Mazaheri v Law Society of Ontario (Law Society Tribunal (ON)): AI-hallucinated content in court filing, Adverse Costs Order

AI generated fabricated legal citations in a court filing by Shahryar Mazaheri.

1 source article · read the reporting →

WF-E48MLU24 Nov 2023

DevTernity conference cancelled after fake women speakers exposed

The DevTernity software developer conference was cancelled after allegations that organiser Eduards Sizovs added fake women speakers to the lineup. Sizovs admitted at least one profile, 'Anna Boyko', was an auto-generated 'demo persona' that appeared on the site by mistake. The conference was scheduled to begin December 7 but was called off after several speakers withdrew. Sizovs denied wrongdoing and said he had fixed the code and written a test to prevent a recurrence.

Company involved
DevTernity

9 source articles · read the reporting →

Serco Leisure issued enforcement notices for unlawful biometric monitoring of employees

Serco Leisure and associated trusts used facial recognition and fingerprint scanning to monitor employee attendance at 38 leisure facilities. The ICO found they unlawfully processed biometric data of over 2,000 employees. Enforcement notices were issued ordering them to stop.

Company involved
Serco Leisure Operating Limited

8 source articles · read the reporting →

Teething problems in Mater Dei's medicine robots addressed

The Malta Union for Midwives and Nurses claimed that a €23 million investment in two computerised drug administration robots, Mario and Sophia, at Mater Dei Hospital had resulted in a complete failure. However, sources within the Health Ministry said that most teething problems have been addressed and that the supplier has not been paid yet. They reported that out of over 1,700 medication rounds, only four required a contingency plan.

Company involved
Mater Dei Hospital
AI system involved
Mario and Sophia

6 source articles · read the reporting →

← Newerpage 2 of 3Older →