The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

68 incidents closest to “Procore construction management platform” · matched on meaning · public reporting

WF-BABUXF28 Feb 2026

McKinsey's Lilli AI Platform Hacked, Exposing 46 Million Chat Messages

Security researchers at CodeWall used an autonomous offensive agent to discover a SQL injection vulnerability in McKinsey's internal AI platform, Lilli. The vulnerability allowed unauthenticated access to the production database, exposing 46.5 million chat messages, 728,000 files, and 57,000 user accounts. The researchers responsibly disclosed the issue to McKinsey, who patched the endpoints within days. No data was exfiltrated or misused, and no disruption occurred.

Company involved
McKinsey & Company
AI system involved
Lilli

1 source article · read the reporting →

WF-ZTR26N1 Nov 2023

DC attorney general sues 14 landlords over RealPage rent collusion

The Attorney General of Washington DC filed a lawsuit against 14 large landlords, alleging they used RealPage's YieldStar software to form “a District-wide housing cartel” that artificially inflated rents. The complaint claims RealPage's pricing algorithm used data supplied by the landlords and pressurised them to follow its rate recommendations, with one firm's internal presentation stating at least 95% compliance was expected. This alleged scheme caused residents to pay millions of dollars above fair market prices during a housing affordability crisis.

Company involved
Greystar Management Services
AI system involved
YieldStar

10 source articles · read the reporting →

WF-FTQNFS1 Aug 2021

Xsolla fires 150 employees after big data analysis tags them as unproductive

Payment services company Xsolla terminated 150 employees at its Perm, Russia office after a big data analysis of their activity in Jira, Confluence, Gmail, chats, and documents tagged them as unengaged and unproductive. CEO Aleksandr Agapitov sent an email to affected employees stating that Xsolla was not for them, sparking backlash. The company later held a press conference, explaining the layoffs were due to slowing growth, and offered affected employees medical insurance and severance pay equal to four to six months' salary.

Company involved
Xsolla

4 source articles · read the reporting →

WF-HHAQBE4 Jul 2025

Microsoft Copilot Audit Log Flaw Left Customers Unaware

A vulnerability in Microsoft 365 Copilot allowed users to access files without the access being recorded in audit logs, potentially enabling malicious insiders to exfiltrate data undetected. The flaw, discovered by Pistachio's CTO, was reported to Microsoft in July 2025 and fixed in August, but Microsoft decided not to issue a CVE or notify customers. The vulnerability could be triggered accidentally, meaning many organisations' audit logs may be incomplete. Microsoft classified the issue as 'important' but faced criticism for its lack of transparency.

Company involved
Microsoft
AI system involved
M365 Copilot

1 source article · read the reporting →

Claude Code deletes developer's production database and snapshots

Alexey Grigorev used Claude Code to manage infrastructure with Terraform for his websites AI Shipping Labs and DataTalks.Club. Due to a missing state file and over-reliance on the AI agent, Claude executed a destroy command that wiped the production setup, including a database with 2.5 years of records and snapshots. Amazon Business support helped restore the data within a day. Grigorev is now implementing safeguards to prevent recurrence.

Company involved
AI Shipping Labs
AI system involved
Claude Code

2 source articles · read the reporting →

WF-QRRDUN19 Oct 2025

Eight Sleep Pod outage disrupts users' sleep after AWS failure

An AWS outage impacted Eight Sleep Pod users, disrupting their sleep as the smart bed's features became unavailable. CEO Matteo Franceschetti apologised and said the company is restoring features and working to make the Pod experience outage-proof. Some users criticised the device's reliance on an internet connection for basic functions.

Company involved
Eight Sleep
AI system involved
Eight Sleep Pod

3 source articles · read the reporting →

WF-D9RWQC1 Jan 2018

Facebook's platform used to foment violence in Myanmar

Facebook commissioned an independent human rights impact assessment that concluded the company was not doing enough to prevent its platform from being used to foment division and incite offline violence in Myanmar. The assessment, conducted by BSR, found that Facebook's content moderation and AI systems failed to adequately detect and remove hate speech and misinformation, contributing to real-world harm. Facebook acknowledged the findings and implemented corrective measures, including hiring more local language reviewers and improving AI detection.

Company involved
Facebook
AI system involved
Facebook platform

10 source articles · read the reporting →

WF-SE5ZJP1 Aug 2024

Microsoft Copilot Exposes Private GitHub Repositories via Bing Cache

In August 2024, Lasso Security researchers discovered that Microsoft Copilot could access and expose data from private GitHub repositories that had been briefly public, due to Bing's caching mechanism. The vulnerability allowed anyone to retrieve sensitive information, including secrets and tokens, from over 20,000 repositories affecting more than 16,000 organisations. Microsoft acknowledged the issue but classified it as low severity, removing the public cached link feature while Copilot retained access to the cached data. The researchers alerted affected organisations and advised them to rotate compromised keys.

Company involved
Microsoft
AI system involved
Microsoft Copilot

2 source articles · read the reporting →

WF-WEZFLW24 Apr 2026

PocketOS database and backups deleted by Cursor AI agent

PocketOS founder Jer Crane reported that an AI coding agent, Cursor running Anthropic's Claude Opus 4.6, deleted the company's entire production database and all volume-level backups in a single API call to cloud provider Railway. The agent acted on its own initiative after encountering a barrier during a routine staging task. Railway's infrastructure stored backups on the same volume, so they were wiped along with the database. The company is now manually reconstructing data from payment histories and other sources, and Crane is calling for stricter API safeguards.

Company involved
PocketOS
AI system involved
Cursor

3 source articles · read the reporting →

RealPage's YieldStar algorithm pushes rents higher for tenants

RealPage's YieldStar algorithm uses private competitor data to recommend rent increases for apartment units. Landlords adopt up to 90% of the suggestions, leading to higher rents for tenants. Critics allege the software may facilitate indirect price-fixing in violation of antitrust law. The company denies wrongdoing and says the software helps eliminate collusion.

Company involved
RealPage
AI system involved
YieldStar

10 source articles · read the reporting →

341 Malicious ClawHub Skills Found Stealing OpenClaw User Data

Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.

Company involved
OpenClaw
AI system involved
OpenClaw

4 source articles · read the reporting →

WF-VYTMB621 Dec 2022

Southwest Airlines holiday meltdown due to crew scheduling software failure

In December 2022, Southwest Airlines experienced a catastrophic operational meltdown after its crew scheduling software failed to assign pilots and flight attendants to flights during a winter storm. The system, SkySolver and Crew Web Access, could not handle the volume of schedule changes, leading to over 15,800 flight cancellations and stranding thousands of passengers and crew. Southwest's CEO acknowledged the technology failure and promised upgrades, but the incident remained unresolved at the time of reporting.

Company involved
Southwest Airlines
AI system involved
SkySolver and Crew Web Access

10 source articles · read the reporting →

WF-XH2W9I1 Sep 2020

Proctortrack data breach exposed student data from online proctoring

Proctortrack, an online proctoring service used by universities, suffered a data breach in September 2020 when its source code was leaked online. An analysis by Consumer Reports found that the code contained hard-coded passwords and exposed the names and email addresses of over 150 students. The company acknowledged the leak but said no harm resulted. Students had been required to use the software, which performed facial recognition and recorded video during exams.

Company involved
Proctortrack
AI system involved
Proctortrack

10 source articles · read the reporting →

WF-W8NDC11 Jul 2015

New York City's McKinsey-led jail violence program manipulated data, violence increased

New York City paid McKinsey & Company $27.5 million to reduce violence at Rikers Island jail complex. McKinsey designed a predictive algorithm called the Housing Unit Balancer and Restart housing units, but jail officials and McKinsey consultants stacked the units with compliant inmates to artificially lower violence numbers. Violence actually increased by nearly 50% during the project. The city eventually decided to close Rikers.

Company involved
New York City Department of Correction
AI system involved
Housing Unit Balancer (HUB)

10 source articles · read the reporting →

WF-2JDFGT5 Jun 2020

Amazon's automated HR wrongly fires sick workers with coronavirus

Amazon's automated human resources system reportedly denied sick-leave to workers with COVID-19 and wrongfully initiated termination proceedings against some who were sick or recovering. The system, designed to handle HR requests automatically, failed under the influx of pandemic-related demands, leaving employees on hold for hours or dealing with chatbots. Six warehouse workers from Indiana to New Jersey described the problems to Bloomberg.

Company involved
Amazon
AI system involved
Automated HR system (chatbots and automated termination tracking)

8 source articles · read the reporting →

PwC develops facial recognition tool to monitor employees working from home

Accounting giant PwC has developed a facial recognition tool that logs when employees are absent from their computer screens while working from home. The tool, intended for financial institutions, requires workers to provide written reasons for any absences, including toilet breaks. Commentators have criticised the tool as a huge invasion of privacy, with concerns about damage to trust and increased stress. PwC stated that the technology is designed to help regulated institutions meet compliance obligations and that voluntary consent of traders is essential.

Company involved
PwC

8 source articles · read the reporting →

WF-IJT56I24 Aug 2021

Unity faces employee concerns over military contract transparency

An investigation by Vice Games reported that Unity Technologies is not transparent with its developers about military contracts. Employees allege some are unaware their work on AI tools may become part of Department of Defense projects. CEO John Riccitiello stated the company will not support programs that violate its principles, but sources say many staff are angry. Unity said it cannot police all uses of its engine as it is a tool available to anyone.

Company involved
Unity Technologies
AI system involved
Unity engine

8 source articles · read the reporting →

WF-YWUJN81 Oct 2024

Company fires HR team after ATS auto-rejects manager's CV due to filtering error

A company's applicant tracking system (ATS) auto-rejected qualified candidates' resumes for three months because it was filtering for the outdated framework AngularJS instead of the required Angular framework. The manager discovered the flaw by submitting his own CV under a pseudonym and found it was rejected within seconds. After the manager reported the issue to upper management, the company investigated and dismissed half of its HR team. No legal action or regulatory involvement is reported.

4 source articles · read the reporting →

WF-U4WH351 Jun 2020

ScaleFactor reportedly failed to deliver promised automated bookkeeping software

ScaleFactor, an Austin-based startup, is reported to have failed to deliver the automated, real-time bookkeeping tools it promised customers, instead relying on human bookkeepers and a Filipino contract accounting firm. The company told Forbes in June that it was shutting down, initially blaming the pandemic, but Forbes later reported that its problems predated Covid-19. Investors reportedly came to see the company as more of a services business than a software platform, and pulled funding after a pivot to a marketplace model. No legal or regulatory action is reported.

Company involved
ScaleFactor

10 source articles · read the reporting →

Answer.AI tests Devin and reports 14 failures in 20 tasks

Answer.AI's team tested Devin, an autonomous AI coding assistant, on 20 real-world tasks over a month. Devin succeeded in only 3 tasks, failed 14, and was inconclusive in 3. The team found Devin often produced overly complex or hallucinated solutions and could not recognize fundamental blockers. They ultimately decided to stick with tools that allow more human control.

AI system involved
Devin

5 source articles · read the reporting →

WF-L8981D29 Jan 2025

DeepSeek exposed user data via open ClickHouse database

Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

WF-LEN91Y1 May 2021

US CBP deploys CBP One app using facial recognition for asylum seekers amid privacy concerns

The article reports that U.S. Customs and Border Protection quietly deployed the CBP One mobile app at the Mexico border. The app uses facial recognition and geolocation to collect and verify information on asylum seekers before they enter the United States. Privacy experts warn that the app poses risks of persistent surveillance and that the facial recognition algorithm is unreliable for people of colour. A previous CBP facial recognition pilot was hacked, exposing images. CBP says the app is voluntary and data is secure.

Company involved
U.S. Customs and Border Protection
AI system involved
CBP One

8 source articles · read the reporting →

WF-1S3KLV26 Nov 2024

OpenAI's Sora video generator leaked by group in protest

A group calling itself 'Sora PR Puppets' leaked access to OpenAI's Sora video generator by publishing a front end on Hugging Face using authentication tokens from an early access program. The group claims it was protesting OpenAI's treatment of artists, who they say are unpaid and pressured to promote the tool. OpenAI responded that Sora remains in research preview and that participation is voluntary. The leak was shut down after a few hours.

Company involved
OpenAI
AI system involved
Sora

5 source articles · read the reporting →

Prosecraft shut down after using authors' books without consent for AI analytics

Prosecraft, a fiction analytics site, used the full text of over 25,000 books without author consent to train its AI algorithms and provide writing statistics. Authors protested on social media, demanding removal of their works. The developer, Benji Smith, subsequently shut down the site and wrote a blog post explaining his actions.

Company involved
Prosecraft
AI system involved
Prosecraft

10 source articles · read the reporting →

← Newerpage 2 of 3Older →