SenseNets silent after data leak exposes millions of people's records
SenseNets Technology Ltd., a Shenzhen-based facial recognition company, left a database containing personal information of more than 2.5 million people publicly accessible without password protection for months. Dutch security researcher Victor Gevers and the GDI Foundation discovered the exposure in July and warned the company, which did not respond. The database was secured in February after the leak was reported, and the company is reported to be conducting an internal investigation. SenseNets has declined to comment publicly.
- Company involved
- SenseNets Technology Ltd.
10 source articles · read the reporting →
UDR Sued Over Alleged Use of RealPage Algorithm to Set Rents in San Diego
A class action lawsuit alleges that UDR, Inc. used RealPage's YieldStar algorithmic pricing software to set rental rates and occupancy levels for its San Diego properties, in violation of a local ordinance. The suit claims the software relied on nonpublic competitor data, contributing to inflated rents and making housing less affordable. The lawsuit, filed in July 2026, seeks to represent all affected tenants. UDR has previously acknowledged using YieldStar as one tool among others in its decision-making.
- Company involved
- UDR, Inc.
- AI system involved
- RealPage YieldStar
1 source article · read the reporting →
Cense exposed 2.5 million records of auto accident victims online
On July 7, 2020, a security researcher discovered 2.5 million records containing personal and medical data of auto accident victims exposed online. The records, belonging to New York-based AI company Cense, included names, insurance policy numbers, claim numbers, and medical diagnosis notes. The data was labeled as staging data, possibly intended for temporary storage before being loaded into an AI system. After the researcher sent a responsible disclosure notice, Cense restricted public access to the database.
- Company involved
- Cense
- AI system involved
- Cense
5 source articles · read the reporting →
CivitAI hosts AI models generating non-consensual porn of real people
A 404 Media investigation found that CivitAI, a platform for sharing AI image generation models, hosts numerous models that can produce pornographic images of real people without their consent. These models are trained on images scraped from the internet, and have been downloaded tens of thousands of times, enabling widespread creation of non-consensual sexual content. Sex workers and public figures are particularly affected, with no remediation or recourse reported.
- Company involved
- CivitAI
7 source articles · read the reporting →
UK councils use Covid OneView AI to harvest personal data for risk scoring
UK local authorities are using a system called Covid OneView, developed by data analytics firm Xantura, to harvest millions of personal details from council records. The system uses predictive analytics and AI to assign risk scores to households and individuals, aiming to identify those vulnerable to Covid or likely to break lockdown rules. Privacy campaigners and MPs have criticised the lack of transparency and the extent of data collection, which includes sensitive information such as debt levels, living arrangements, and even notes on unfaithful sex. Xantura and Barking and Dagenham Council have defended the system as compliant with data protection rules and focused on providing support.
- Company involved
- UK local authorities
- AI system involved
- Covid OneView
6 source articles · read the reporting →
DiveFace face-recognition dataset reuses Flickr photos despite licence restrictions
DiveFace is a face-recognition dataset published in 2019 with 139,677 images of about 24,000 people. The authors say the images came from Flickr via the MegaFace and YFCC100M datasets and were automatically labelled by gender and ethnicity. Exposing.ai found that many of the photos carry Creative Commons licences which prohibit derivative use, suggesting the dataset may have been assembled without proper permission. The dataset remains available from the authors' GitHub page.
- AI system involved
- DiveFace
3 source articles · read the reporting →
Meta sues Voyager Labs for scraping Facebook and Instagram user data
Meta filed a legal action against Voyager Labs, alleging that the company used fake accounts and proprietary software to scrape user data from Facebook and Instagram. The scraping collected profile information, posts, friends lists, photos and comments. Meta disabled Voyager's accounts and sought a permanent injunction. The case was settled in December 2024, with Voyager agreeing to a permanent injunction and monetary payment.
- Company involved
- Voyager Labs
10 source articles · read the reporting →
Study finds Italian car insurers charge more based on birthplace
A study by the Universities of Padua, Udine and Carnegie Mellon found that Italian car insurers, including Genertel, Mps, Quixa and Con.Te, use birthplace and citizenship in pricing algorithms, charging some drivers over €1,000 more. The practice was ruled against in a 2018 decree involving Linear, but the study says it continues. The companies contacted denied or explained the findings.
- Company involved
- Genertel, Mps, Quixa, Con.Te
8 source articles · read the reporting →
Portland Metro ends Replica partnership over data privacy concerns
Portland Metro, an elected regional government in Oregon, ended its pilot project with movement data company Replica after a disagreement about data sharing. Portland Metro requested raw, disaggregated data, which Replica refused to provide, citing user privacy concerns. The partnership was terminated without payment.
- Company involved
- Portland Metro
- AI system involved
- Replica
10 source articles · read the reporting →
ViaQuatro's facial recognition system in São Paulo metro challenged in court
In April 2018, ViaQuatro installed the Digital Interactive Doors System, developed by AdMobilize, on the São Paulo metro's yellow line. The system used cameras to detect passengers' faces and claimed to infer their emotion, age, and gender in order to target advertisements. The Brazilian Institute of Consumer Protection (IDEC) filed a public civil action alleging that the system violated consumer and data protection laws by processing biometric data without consent and making pseudoscientific and discriminatory inferences. A judge ordered the cameras removed in August 2018, and the case is pending a final ruling.
- Company involved
- ViaQuatro
- AI system involved
- Digital Interactive Doors System (DID system)
10 source articles · read the reporting →
Google and HCA Healthcare partner to analyze 32 million patient records
Google Cloud has announced a partnership with HCA Healthcare to analyze around 32 million patient records. The anonymized data will be used to develop algorithms that could advise doctors on treatment options. Privacy advocates have raised concerns about the data sharing and the potential for AI to re-identify patients. HCA insists that patient-identifiable information will be stripped and that access will be tightly controlled.
- Company involved
- HCA Healthcare
- AI system involved
- Google Cloud
9 source articles · read the reporting →
California regulator accuses Maxpread Technologies of using AI-generated fake CEO to scam investors
Maxpread Technologies allegedly used an AI-generated avatar to pose as its CEO in a YouTube video to deceive investors. The California DFPI issued cease and desist letters to Maxpread and four other companies for offering unqualified securities and making false promises. The regulator claims the companies promised high daily returns using AI trading, but these claims were false. Maxpread did not respond to requests for comment.
- Company involved
- Maxpread Technologies
8 source articles · read the reporting →
iRobot considers selling Roomba home mapping data to advertisers
iRobot's Roomba vacuum cleaners with mapping technology collect detailed floor plan data of users' homes. The company's CEO stated he is considering selling this data to companies like Amazon, Apple, or Google for advertising purposes. Robotics experts express concern about the lack of user consent and potential privacy implications.
- Company involved
- iRobot
- AI system involved
- Roomba 960/980
10 source articles · read the reporting →
WorldCoin suspended in Kenya over data security concerns
WorldCoin, a digital identification protocol using iris scans, was suspended by Kenyan regulators (ODPC and Communications Authority) over concerns about data security, consent, and oversight. The system had issued digital IDs and cryptocurrency tokens to over 350,000 Kenyans. Reports of hacked orb operators and iris scans traded on the dark web have also emerged.
- Company involved
- Tools for Humanity GmbH
- AI system involved
- WorldCoin
10 source articles · read the reporting →
LINAGORA closes Lucie 7B after user mockery
LINAGORA, a French open-source software company, launched a beta version of its large language model Lucie 7B. The model was intended to be a transparent and ethical alternative to big tech AI. However, after users tested it and highlighted its shortcomings, the model was mocked online. LINAGORA subsequently closed the platform to address the issues and collect more data.
- Company involved
- LINAGORA
- AI system involved
- Lucie 7B
6 source articles · read the reporting →
OpenAI accuses DeepSeek of inappropriately using its data
OpenAI has accused Chinese AI company DeepSeek of inappropriately using data from its ChatGPT model to train DeepSeek's own large language model. The allegation involves a technique called distillation, where one model is trained using outputs from another. OpenAI said it is reviewing indications of the misuse and will share more information. DeepSeek has not responded to the accusation.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek
6 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
Bavarian police test Palantir data mining with real personal data
The Bavarian State Criminal Police Office (LKA) has been testing Palantir's data mining software, called VeRa, with real personal data for months. The Bavarian data protection commissioner only learned of the test through a media inquiry and has announced a review. The Interior Ministry claims the test is lawful under current law, but critics argue a legal basis is missing.
- Company involved
- Bayerisches Landeskriminalamt
- AI system involved
- VeRa
7 source articles · read the reporting →
N-Tech.lab's FindFace used to identify St Petersburg metro passengers without consent
Egor Tsvetkov photographed passengers on the St Petersburg metro without their permission and used N-Tech.lab's facial recognition service FindFace to match their faces to public Vkontakte profiles. He published the results in an art project called 'Your Face is Big Data', saying he wanted to show how 'digital narcissism' can lead to stalking. Privacy advocates said the project was ethically problematic because the subjects had not consented and their identities were exposed. FindFace had been launched by N-Tech.lab in February 2016.
- Company involved
- N-Tech.lab
- AI system involved
- FindFace
8 source articles · read the reporting →
University of Michigan halts vendor offering student data for AI training
The University of Michigan asked a vendor to stop work after a LinkedIn message offered to license student data for AI training for $25,000. The data came from past research studies and did not contain personal identifiers. The university stated that student data was never for sale and that the vendor had shared inaccurate information. The vendor was asked to halt their work.
- Company involved
- University of Michigan
5 source articles · read the reporting →
AAIP investigates Worldcoin's personal data processing in Argentina
The Argentine Agency for Access to Public Information (AAIP) has initiated an investigation into the data processing practices of Worldcoin in Argentina. The investigation focuses on the collection, storage, and use of biometric data, including facial and iris scans, carried out in several cities in exchange for financial compensation. The AAIP aims to verify compliance with the country's data protection law, Ley 25.326, regarding sensitive data handling.
- Company involved
- Worldcoin (Fundación Worldcoin)
- AI system involved
- Worldcoin
8 source articles · read the reporting →
Worldcoin collected biometric data from poor villagers in Indonesia without informed consent
Worldcoin, a cryptocurrency startup, recruited users in developing countries by offering free cash in exchange for iris scans. The company used deceptive marketing, collected more personal data than acknowledged, and failed to obtain meaningful informed consent. Many users received worthless tokens instead of promised money. The company acknowledged some friction but continued its operations.
- Company involved
- Worldcoin
- AI system involved
- chrome orb
5 source articles · read the reporting →
Italian privacy regulator investigates OpenAI's Sora video generation model
The Italian Data Protection Authority (Garante Privacy) has opened an investigation into OpenAI's new AI model 'Sora', which creates short videos from text instructions. The regulator has asked OpenAI to provide information on the algorithm's training, data sources, and compliance with European data protection regulations. OpenAI must respond within 20 days.
- Company involved
- OpenAI
- AI system involved
- Sora
7 source articles · read the reporting →
CJEU rules Dun & Bradstreet must explain automated credit decisions under GDPR
A customer was refused a mobile phone contract because of an automated credit assessment by Dun & Bradstreet Austria. The customer took the case to court, which found that Dun & Bradstreet had infringed the GDPR by failing to provide meaningful information about the logic involved. The CJEU ruled that data controllers must explain automated decisions and that trade secrets cannot automatically override the right of access.
- Company involved
- Dun & Bradstreet Austria GmbH
7 source articles · read the reporting →