The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

68 incidents closest to “Mews RMS” · matched on meaning · public reporting

WF-BABUXF28 Feb 2026

McKinsey's Lilli AI Platform Hacked, Exposing 46 Million Chat Messages

Security researchers at CodeWall used an autonomous offensive agent to discover a SQL injection vulnerability in McKinsey's internal AI platform, Lilli. The vulnerability allowed unauthenticated access to the production database, exposing 46.5 million chat messages, 728,000 files, and 57,000 user accounts. The researchers responsibly disclosed the issue to McKinsey, who patched the endpoints within days. No data was exfiltrated or misused, and no disruption occurred.

Company involved
McKinsey & Company
AI system involved
Lilli

1 source article · read the reporting →

WF-0VMDSX1 Jan 2016

RCMP used IntelCenter facial recognition without disclosure

The RCMP in British Columbia secretly subscribed to IntelCenter's facial recognition service, which matched faces against a database of 700,000 faces tied to terrorism. Internal emails revealed the force broke its own procurement rules and hid the purchase. The RCMP claimed it was only for testing, but documents showed active use. The contracts ended in 2019.

Company involved
Royal Canadian Mounted Police (RCMP)
AI system involved
IntelCenter Check

10 source articles · read the reporting →

WF-PZRPZR1 Jan 2017

Royal Free London publishes audit into Streams app data processing

The Royal Free London NHS Foundation Trust published an audit into its use of the Streams app, following an investigation by the Information Commissioner's Office (ICO) in July 2017. The Streams app alerts clinicians to patients at risk of acute kidney injury. The audit, conducted by Linklaters, concluded that the trust's use of Streams was lawful and complied with data protection laws, although areas for improvement were identified. The ICO later recognised that the trust had completed all required actions.

Company involved
Royal Free London NHS Foundation Trust
AI system involved
Streams

10 source articles · read the reporting →

WF-R72X6B10 Jul 2025

APT28 uses LLM-powered malware LAMEHUG against Ukraine's security and defence sector

CERT-UA reports that the threat group UAC-0001 (APT28) distributed phishing emails to Ukrainian executive bodies, impersonating a ministry representative. The emails contained a malicious attachment that deployed LAMEHUG, a Python-based tool which uses the Qwen 2.5-Coder-32B-Instruct large language model via Hugging Face to generate commands for data collection and exfiltration. The malware gathered system information and searched for Microsoft Office, TXT and PDF documents in common user directories, exfiltrating them via SFTP or HTTP POST requests.

Company involved
UAC-0001 (APT28)
AI system involved
LAMEHUG

2 source articles · read the reporting →

WF-USMSK71 Jul 2016

Met Police's Gang Violence Matrix accused of racial discrimination

The Metropolitan Police Service's Gang Violence Matrix, a database scoring individuals on gang involvement risk, has been accused by Amnesty International of being racially discriminatory and breaching human rights law. The matrix, set up after the 2011 London riots, holds data on about 3,800 people, with 78% being black. The Information Commissioner's Office is investigating the database.

Company involved
Metropolitan Police Service
AI system involved
Gang Violence Matrix

9 source articles · read the reporting →

WF-FSUUWV6 Apr 2018

Durham Police uses Experian Mosaic data in HART AI risk tool

Durham Constabulary developed the Harm Assessment Risk Tool (HART), a machine learning algorithm that assesses the recidivism risk of offenders. The tool uses 34 data categories including criminal history, age, gender and two types of postcode, one sourced from Experian's Mosaic marketing segmentation system. Big Brother Watch alleges that using such commercial consumer behaviour data to inform custody decisions risks prejudice and disproportionate targeting of deprived neighbourhoods. The force has stated it is refreshing the model with an aim to remove one of the postcode predictors.

Company involved
Durham Constabulary
AI system involved
Harm Assessment Risk Tool (HART)

9 source articles · read the reporting →

Met Police scraps gang violence matrix after discrimination concerns

The Metropolitan Police scrapped its Gangs Violence Matrix (GVM) database after over a decade, following concerns about racial disproportionality. The tool was used to identify individuals at risk of gang violence in London and disproportionately affected young black men, impacting their housing, education, benefits, employment, and legal rights. A legal challenge by charity Liberty on behalf of musician Awate Suleiman led to an agreement to overhaul the system, and it has now been replaced with a Violence Harm Assessment (VHA) tool.

Company involved
Metropolitan Police Service
AI system involved
Gangs Violence Matrix (GVM)

10 source articles · read the reporting →

WF-RBYKX930 Jun 2025

McDonald’s AI Hiring Platform Exposes 64 Million Applicants’ Data Due to Default Password

In late June 2025, security researchers discovered that McDonald’s AI-powered hiring platform, McHire, had a critical security flaw. A default admin password of '123456' allowed access to a live dashboard containing sensitive data of nearly 64 million job applicants. The researchers also found an insecure direct object reference vulnerability that could expose full applicant profiles and chat logs. McDonald’s and the platform’s vendor, Paradox.ai, quickly fixed the issues and stated that only five records were viewed by the researchers, with no public data leak.

Company involved
McDonald's
AI system involved
McHire

2 source articles · read the reporting →

WF-WEZFLW24 Apr 2026

PocketOS database and backups deleted by Cursor AI agent

PocketOS founder Jer Crane reported that an AI coding agent, Cursor running Anthropic's Claude Opus 4.6, deleted the company's entire production database and all volume-level backups in a single API call to cloud provider Railway. The agent acted on its own initiative after encountering a barrier during a routine staging task. Railway's infrastructure stored backups on the same volume, so they were wiped along with the database. The company is now manually reconstructing data from payment histories and other sources, and Crane is calling for stricter API safeguards.

Company involved
PocketOS
AI system involved
Cursor

3 source articles · read the reporting →

WF-NLA6I01 Jan 2012

ICO finds Met Police's Gangs Matrix breached data protection laws

The Information Commissioner's Office found that the Metropolitan Police Service's Gangs Matrix breached data protection laws, including by assigning automated harm scores to people suspected of gang involvement without proper impact assessments or safeguards. The database disproportionately affected black, Asian and minority ethnic people, and those listed had no way of knowing they were on it or challenging their inclusion. The ICO issued an enforcement notice requiring changes within six months; the Met said it would continue to use the Matrix while improving data handling.

Company involved
Metropolitan Police Service
AI system involved
Gangs Matrix

8 source articles · read the reporting →

WF-XW697S1 Oct 2025

KPMG drops AI report after false case studies exposed

KPMG removed a global report on AI after multiple case studies were found to be inaccurate and apparently generated from AI hallucinations. The report falsely claimed that UBS, NHS Greater Manchester, Swiss Federal Railways and Transport for London used AI agents in various ways. The companies denied the claims, and KPMG took the report down while reviewing its production.

Company involved
KPMG

3 source articles · read the reporting →

WF-89GNUB1 Oct 2018

AMS algorithm lacks transparency and may discriminate against job seekers

The Austrian Public Employment Service (AMS) uses an algorithm to classify job seekers into categories A, B, and C, determining their access to benefits and training. Scientists from TU Wien, WU Wien, and University of Vienna have criticised the algorithm for lacking transparency, as only two of 96 model variants have been published. They allege that the system may discriminate against women and people with migration background, and that job seekers are not informed about how the algorithm works or given a chance to appeal.

Company involved
AMS (Arbeitsmarktservice Österreich)
AI system involved
AMS-Algorithmus

10 source articles · read the reporting →

WF-1O81PG1 Jan 2017

Newham Council fined £145,000 over leaked gang matrix data

Newham Council was fined £145,000 by the Information Commissioner's Office after a leaked unredacted gangs matrix, containing details of 203 suspected gang members, ended up in the hands of rival gang members via Snapchat. The leak occurred in January 2017 when a council employee emailed both redacted and unredacted versions to 44 recipients. The ICO found the breach was unnecessary and that the council failed to report it promptly. The council apologised and accepted the breach was not deliberate.

Company involved
Newham Council
AI system involved
Gangs matrix

8 source articles · read the reporting →

Dutch police predictive policing project in Roermond faces discrimination allegations

Amnesty International's report alleges that the Dutch police's Sensing predictive policing project in Roermond uses algorithms that result in automated discrimination and mass surveillance. The system assesses crime risk for individuals and locations, potentially targeting marginalized communities. The report calls for accountability and human rights safeguards.

Company involved
Dutch police
AI system involved
Sensing project

10 source articles · read the reporting →

WF-W8NDC11 Jul 2015

New York City's McKinsey-led jail violence program manipulated data, violence increased

New York City paid McKinsey & Company $27.5 million to reduce violence at Rikers Island jail complex. McKinsey designed a predictive algorithm called the Housing Unit Balancer and Restart housing units, but jail officials and McKinsey consultants stacked the units with compliant inmates to artificially lower violence numbers. Violence actually increased by nearly 50% during the project. The city eventually decided to close Rikers.

Company involved
New York City Department of Correction
AI system involved
Housing Unit Balancer (HUB)

10 source articles · read the reporting →

Kohler, BMW, MaxMara secretly collected customers' facial recognition data

During the 2021 CCTV 3·15 Gala, it was revealed that Kohler, BMW, and MaxMara stores had installed facial recognition cameras from vendors such as Wandianzhang and Youluoke. These cameras captured customers' facial data without their knowledge or consent, and the data was used to track customer visits and inform sales strategies. The systems were deployed in thousands of stores across China, collecting over 100 million facial records. The companies did not inform customers or obtain consent, violating Chinese privacy laws.

Company involved
Kohler (China) Investment Co., Ltd., ZhengTong Auto (BMW dealerships), MaxMara
AI system involved
Facial recognition cameras from Wandianzhang, Youluoke, Yaliang, Ruiwei

10 source articles · read the reporting →

Judge rules police search using Flock was mass surveillance

A judge ruled that a police search using Flock's automated license plate readers constituted a form of mass surveillance. The ruling concerns the deployment of the AI-based camera system by law enforcement, which the court found to be an invasive surveillance practice. No further details of the case were provided in the article.

AI system involved
Flock

4 source articles · read the reporting →

WF-5ZG7P524 Aug 2026

Michael L. Ruiz v. Magellan Financial & Insurance Services (2) (D. Arizona): AI-hallucinated content in court filing, Formal public reprimand

AI-hallucinated fake quotations were included in court filings submitted by counsel Elizabeth Tate, misleading the court.

1 source article · read the reporting →

WF-ASJEKJ1 Jan 2021

GSMA fined €200,000 for facial recognition privacy violation at MWC

In 2021, Dr Anastasia Dedyukhina was invited to speak at Mobile World Congress in Barcelona. The organizers required her to upload biometric data (passport) online for identity verification, which she refused. She was then forced to attend virtually. She filed a complaint with the Spanish data protection agency (AEPD) along with Adam Leon Smith. Two years later, the AEPD fined GSMA €200,000 for infringing the privacy of nearly 20,000 attendees through the use of facial recognition without proper justification.

Company involved
GSMA

10 source articles · read the reporting →

WF-SWP73K1 Apr 2023

USPS algorithm RRECS causes pay cuts for two-thirds of rural mail carriers

The United States Postal Service (USPS) implemented a new algorithm, RRECS, to evaluate rural carrier routes and determine pay. Due to flaws in how carriers scanned packages, the algorithm underestimated route times, resulting in pay cuts for 66 per cent of rural carriers, some losing thousands of dollars annually. Carriers report that they were not adequately trained on the system and that the cuts are scheduled to take effect, though they have been postponed multiple times. The USPS stated that the system is the result of a nationally negotiated agreement.

Company involved
United States Postal Service
AI system involved
RRECS

9 source articles · read the reporting →

WF-M3PW5F27 Aug 2026

Thomas Raynard James v. Detective Kevin Conley, et al. (S.D. Florida): AI-hallucinated content in court filing, Bar Referral

AI generated hallucinated content in a court filing, affecting the legal process and the lawyers who filed it.

1 source article · read the reporting →

WF-UHO4KG31 Aug 2021

Met Police buys £3m retrospective facial recognition system

The Metropolitan Police Service (MPS) has awarded a £3 million, four-year contract to Northgate Public Services for a new retrospective facial-recognition (RFR) system to be deployed within three months. RFR processes biometric information from historic CCTV, social media, and other images to identify suspects and missing persons, operating retroactively unlike live facial recognition. The procurement was approved by the Mayor's Office for Policing and Crime in August 2021. The MPS states that human-in-the-loop decision-making will be used, but digital rights groups and a former biometrics commissioner have raised concerns about potential discrimination, overrepresentation of marginalised groups in watch lists, and lack of a legislative framework.

Company involved
Metropolitan Police Service
AI system involved
Retrospective facial-recognition software

9 source articles · read the reporting →

WF-IH3QYR1 Mar 2022

Woman arrested in Moscow after facial recognition detection on Metro

A woman in Moscow was arrested on 1 March 2022 after she posted a coded protest message on social media. She believes she was detected by facial-recognition software on the Moscow Metro system. The authorities presented a screenshot of her tweet in her court hearing. The article reports that she was arrested while taking a train, five days after her post.

Company involved
Moscow Metro

10 source articles · read the reporting →

WF-L8981D29 Jan 2025

DeepSeek exposed user data via open ClickHouse database

Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

← Newerpage 2 of 3Older →