MeetingTV sues Palo Alto Networks' Koi Security over AI-hallucinated threat report
MeetingTV, a video conferencing startup, alleges that Koi Security used an AI system to generate a threat report that falsely linked it to a Chinese espionage operation. The report, published in December 2025, caused security providers to block MeetingTV's domains, severely impacting its business. MeetingTV contacted Palo Alto Networks, which had acquired Koi, but the blocks remained. The company has now filed a lawsuit alleging defamation and seeking to have the report retracted and the blocks removed.
- Company involved
- Koi Security
- AI system involved
- Wings
2 source articles · read the reporting →
Court orders suspension of facial recognition in São Paulo metro
A court in São Paulo ordered the suspension of a facial recognition system in the city's metro stations following a lawsuit by civil society groups. The system, SecurOS by ISS and operated by ViaQuatro, was capturing biometric data of millions of daily users without adequate transparency or risk assessment. The court also barred the metro operator, METRO, from installing new biometric equipment and imposed daily fines for non-compliance. METRO stated it would appeal the ruling and prove compliance with data protection regulations.
- Company involved
- Companhia do Metropolitano de São Paulo (METRO)
- AI system involved
- SecurOS
3 source articles · read the reporting →
McKinsey's Lilli AI Platform Hacked, Exposing 46 Million Chat Messages
Security researchers at CodeWall used an autonomous offensive agent to discover a SQL injection vulnerability in McKinsey's internal AI platform, Lilli. The vulnerability allowed unauthenticated access to the production database, exposing 46.5 million chat messages, 728,000 files, and 57,000 user accounts. The researchers responsibly disclosed the issue to McKinsey, who patched the endpoints within days. No data was exfiltrated or misused, and no disruption occurred.
- Company involved
- McKinsey & Company
- AI system involved
- Lilli
1 source article · read the reporting →
FACIL'iti sues accessibility consultant Julie Moynat over critical tweet
In November 2020, Julie Moynat, a web accessibility consultant, tweeted criticism of FACIL'iti, an accessibility product. FACIL'iti sent a formal notice to her employer and later subpoenaed her for denigration in May 2021. Moynat is raising funds for her legal defense. The case is ongoing at the Judiciary Tribunal of Paris.
- Company involved
- FACIL'iti
- AI system involved
- FACIL'iti
10 source articles · read the reporting →
LLMjacking Attack Leverages Stolen Credentials to Exploit Cloud LLMs
The Sysdig Threat Research Team observed an attack where stolen cloud credentials were used to access cloud-hosted large language model services. The attackers targeted a vulnerable Laravel system to obtain credentials, then used them to invoke models like Anthropic Claude on AWS Bedrock. They intended to sell LLM access to other cybercriminals, potentially costing victims over $46,000 per day. The attack involved checking credentials against ten AI services and using a reverse proxy to manage access.
- AI system involved
- Claude (v2/v3) on AWS Bedrock
2 source articles · read the reporting →
OpenAI ordered to pay damages for ChatGPT copyright infringement in Germany
A Munich court ruled that OpenAI's ChatGPT violated German copyright law by reproducing protected song lyrics without a license. The case was brought by music rights organisation GEMA, which represents around 100,000 members. The court ordered OpenAI to pay undisclosed damages. OpenAI disagrees with the ruling and is considering next steps.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
4 source articles · read the reporting →
Amazon sends cease-and-desist to Perplexity over AI shopping agent
Amazon sent a cease-and-desist letter to Perplexity, alleging that its Comet AI browser violates Amazon's terms of service by making purchases on behalf of users without disclosing its automated nature. Perplexity responded by calling the legal threat 'bullying' and argued that its bot does not need to identify itself. The dispute highlights tensions between AI agents and e-commerce platforms.
- Company involved
- Perplexity
- AI system involved
- Comet
5 source articles · read the reporting →
Royal Free London publishes audit into Streams app data processing
The Royal Free London NHS Foundation Trust published an audit into its use of the Streams app, following an investigation by the Information Commissioner's Office (ICO) in July 2017. The Streams app alerts clinicians to patients at risk of acute kidney injury. The audit, conducted by Linklaters, concluded that the trust's use of Streams was lawful and complied with data protection laws, although areas for improvement were identified. The ICO later recognised that the trust had completed all required actions.
- Company involved
- Royal Free London NHS Foundation Trust
- AI system involved
- Streams
10 source articles · read the reporting →
MoviePass to use eye-tracking to ensure users watch adverts
MoviePass, the movie subscription service, has announced that its new app will use facial recognition and eye-tracking technology to ensure users are watching adverts. The system, which uses the phone's camera, will pause content if the user looks away. The company says the technology is designed to give advertisers the impact they are looking for. No harm has been reported yet, but the tracking raises privacy concerns.
- Company involved
- MoviePass
- AI system involved
- MoviePass app
10 source articles · read the reporting →
McDonald’s AI Hiring Platform Exposes 64 Million Applicants’ Data Due to Default Password
In late June 2025, security researchers discovered that McDonald’s AI-powered hiring platform, McHire, had a critical security flaw. A default admin password of '123456' allowed access to a live dashboard containing sensitive data of nearly 64 million job applicants. The researchers also found an insecure direct object reference vulnerability that could expose full applicant profiles and chat logs. McDonald’s and the platform’s vendor, Paradox.ai, quickly fixed the issues and stated that only five records were viewed by the researchers, with no public data leak.
- Company involved
- McDonald's
- AI system involved
- McHire
2 source articles · read the reporting →
Inland Revenue warns of AI scam using commissioner's image
Scammers used AI-generated images and messaging to impersonate New Zealand's Commissioner of Inland Revenue, Peter Mersi, in social media ads inviting people to a fake crypto tax webinar. The ads aimed to trick people into giving personal information for identity theft or account access. Inland Revenue received over 3000 scam reports in three months and worked to have the ads removed, but they kept reappearing. The department warned the public about the increasing use of AI in investment scams.
2 source articles · read the reporting →
Florida man nearly loses $1,900 in AI puppy scam
Dennis Morida of St. Petersburg, Florida, was scammed after his missing German Shepherd puppy Hazel was falsely reported as injured. A caller claiming to be a police sergeant sent an AI-generated image of Hazel on an operating table and demanded $1,900 for surgery. Morida paid via Zelle, but the dog returned home unharmed and his bank flagged the transaction as fraud, so he recovered the money.
2 source articles · read the reporting →
Newham Council fined £145,000 over leaked gang matrix data
Newham Council was fined £145,000 by the Information Commissioner's Office after a leaked unredacted gangs matrix, containing details of 203 suspected gang members, ended up in the hands of rival gang members via Snapchat. The leak occurred in January 2017 when a council employee emailed both redacted and unredacted versions to 44 recipients. The ICO found the breach was unnecessary and that the council failed to report it promptly. The council apologised and accepted the breach was not deliberate.
- Company involved
- Newham Council
- AI system involved
- Gangs matrix
8 source articles · read the reporting →
Shipt's new V2 algorithm reduces pay for 41% of workers, study finds
A study by MIT Media Lab and Coworker.org found that Shipt's new V2 payment algorithm reduced pay for 41% of workers by an average of 11% per shop. The algorithm, rolled out in September 2020, replaced a transparent payment system with a black-box model. Workers pooled data to analyze the impact, revealing uneven distribution of earnings.
- Company involved
- Shipt
- AI system involved
- V2
10 source articles · read the reporting →
Meta sues Voyager Labs for scraping Facebook and Instagram user data
Meta filed a legal action against Voyager Labs, alleging that the company used fake accounts and proprietary software to scrape user data from Facebook and Instagram. The scraping collected profile information, posts, friends lists, photos and comments. Meta disabled Voyager's accounts and sought a permanent injunction. The case was settled in December 2024, with Voyager agreeing to a permanent injunction and monetary payment.
- Company involved
- Voyager Labs
10 source articles · read the reporting →
GSMA fined €200,000 for facial recognition privacy violation at MWC
In 2021, Dr Anastasia Dedyukhina was invited to speak at Mobile World Congress in Barcelona. The organizers required her to upload biometric data (passport) online for identity verification, which she refused. She was then forced to attend virtually. She filed a complaint with the Spanish data protection agency (AEPD) along with Adam Leon Smith. Two years later, the AEPD fined GSMA €200,000 for infringing the privacy of nearly 20,000 attendees through the use of facial recognition without proper justification.
- Company involved
- GSMA
10 source articles · read the reporting →
USPS algorithm RRECS causes pay cuts for two-thirds of rural mail carriers
The United States Postal Service (USPS) implemented a new algorithm, RRECS, to evaluate rural carrier routes and determine pay. Due to flaws in how carriers scanned packages, the algorithm underestimated route times, resulting in pay cuts for 66 per cent of rural carriers, some losing thousands of dollars annually. Carriers report that they were not adequately trained on the system and that the cuts are scheduled to take effect, though they have been postponed multiple times. The USPS stated that the system is the result of a nationally negotiated agreement.
- Company involved
- United States Postal Service
- AI system involved
- RRECS
9 source articles · read the reporting →
Amazon sellers lose thousands after RepricerExpress pricing glitch
A software glitch in RepricerExpress's automated repricing system caused products sold by Amazon sellers to be priced at 1p, leading to significant financial losses for the sellers. RepricerExpress apologised but did not offer compensation, while Amazon said it had reached out to affected sellers but many reported no response. Some sellers have instructed lawyers to take legal action against RepricerExpress and Amazon.
- Company involved
- RepricerExpress
- AI system involved
- RepricerExpress
10 source articles · read the reporting →
TOV Realty, LLC v. Suarez; Kosel Equity, LLC v. MacGregor (SC Connecticut): AI-hallucinated content in court filing, 6 hours CLE;…
The AI generated legal briefs containing fabricated citations, which were submitted to the Connecticut Supreme Court.
- Company involved
- GLG Law LLC
- AI system involved
- ChatGPT
1 source article · read the reporting →
Met Police buys £3m retrospective facial recognition system
The Metropolitan Police Service (MPS) has awarded a £3 million, four-year contract to Northgate Public Services for a new retrospective facial-recognition (RFR) system to be deployed within three months. RFR processes biometric information from historic CCTV, social media, and other images to identify suspects and missing persons, operating retroactively unlike live facial recognition. The procurement was approved by the Mayor's Office for Policing and Crime in August 2021. The MPS states that human-in-the-loop decision-making will be used, but digital rights groups and a former biometrics commissioner have raised concerns about potential discrimination, overrepresentation of marginalised groups in watch lists, and lack of a legislative framework.
- Company involved
- Metropolitan Police Service
- AI system involved
- Retrospective facial-recognition software
9 source articles · read the reporting →
Mazaheri v Law Society of Ontario (Law Society Tribunal (ON)): AI-hallucinated content in court filing, Adverse Costs Order
AI generated fabricated legal citations in a court filing by Shahryar Mazaheri.
1 source article · read the reporting →
DevTernity conference cancelled after fake women speakers exposed
The DevTernity software developer conference was cancelled after allegations that organiser Eduards Sizovs added fake women speakers to the lineup. Sizovs admitted at least one profile, 'Anna Boyko', was an auto-generated 'demo persona' that appeared on the site by mistake. The conference was scheduled to begin December 7 but was called off after several speakers withdrew. Sizovs denied wrongdoing and said he had fixed the code and written a test to prevent a recurrence.
- Company involved
- DevTernity
9 source articles · read the reporting →
Serco Leisure issued enforcement notices for unlawful biometric monitoring of employees
Serco Leisure and associated trusts used facial recognition and fingerprint scanning to monitor employee attendance at 38 leisure facilities. The ICO found they unlawfully processed biometric data of over 2,000 employees. Enforcement notices were issued ordering them to stop.
- Company involved
- Serco Leisure Operating Limited
8 source articles · read the reporting →
Teething problems in Mater Dei's medicine robots addressed
The Malta Union for Midwives and Nurses claimed that a €23 million investment in two computerised drug administration robots, Mario and Sophia, at Mater Dei Hospital had resulted in a complete failure. However, sources within the Health Ministry said that most teething problems have been addressed and that the supplier has not been paid yet. They reported that out of over 1,700 medication rounds, only four required a contingency plan.
- Company involved
- Mater Dei Hospital
- AI system involved
- Mario and Sophia
6 source articles · read the reporting →