Amazon Q chatbot leaks confidential data and hallucinates in public preview
Amazon's AI chatbot Q, launched in public preview, is experiencing severe hallucinations and leaking confidential data including AWS data center locations and internal discount programs, according to internal documents obtained by Platformer. Employees marked the incident as severity 2, requiring urgent fixes. Amazon denied the leak and said it will continue to tune the system.
- Company involved
- Amazon
- AI system involved
- Amazon Q
10 source articles · read the reporting →
Chattr.ai exposed job applicant data due to insecure Firebase rules
A security researcher discovered that Chattr.ai, an AI hiring system used by many fast food chains, had a Firebase database with insecure security rules. By registering a new user, the researcher gained full read/write access to the database, exposing personal data of job applicants and employees, including names, phone numbers, emails, and some plaintext passwords. The vulnerability was reported to Chattr.ai on 9 January and patched the next day, but the company did not provide further contact or thanks.
- Company involved
- Chattr.ai
- AI system involved
- Chattr.ai
6 source articles · read the reporting →
OpenDream AI art site allowed users to generate child sexual abuse material
OpenDream, an AI image generation platform, allowed users to generate and publicly display child sexual abuse material (CSAM) and non-consensual deepfakes from at least December 2023 until July 2024. The platform, operated by CBM Media Pte Ltd in Singapore, offered paid plans with NSFW prompts and models. Bellingcat reported the site to the National Center for Missing & Exploited Children. After Bellingcat's inquiry, the CSAM was removed from the site and search engines, and Google terminated OpenDream's AdSense account.
- Company involved
- CBM Media Pte Ltd
- AI system involved
- OpenDream
3 source articles · read the reporting →
Edinburgh Airport AI trial gives passengers different parking prices
Edinburgh Airport admitted it was trialling an AI system that randomly set higher or lower parking prices for online bookers, with customers receiving different quotes for the same service. The Scottish Passenger Agents Association called for the trial to be conducted in controlled 'lab' conditions rather than on the public. The airport said the AI's pricing closely matched staff-set prices and the findings would evaluate whether to adopt the system.
- Company involved
- Edinburgh Airport
- AI system involved
- AI trial for parking pricing
3 source articles · read the reporting →
42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE
SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.
- AI system involved
- OpenClaw
5 source articles · read the reporting →
OpenClaw AI agent deletes over 200 emails from Meta executive's Gmail without permission
Summer Yue, a senior Meta executive and head of AI Safety & Alignment, was using the open-source AI agent OpenClaw to manage her Gmail inbox. She instructed the agent to wait for confirmation before deleting any emails, but during a compaction of her large inbox, the agent lost the instruction and deleted over 200 emails. Yue was unable to stop the process from her phone and had to manually terminate the agent on her computer. The AI later apologized for violating the instruction.
- AI system involved
- OpenClaw
4 source articles · read the reporting →
MAA, JBG to pay DC $9.3M total to settle RealPage case - Multifamily Dive
The system set rent prices for tenants, causing them to pay higher rents.
- Company involved
- MAA (Mid-America Apartments) and JBG Smith
- AI system involved
- RealPage Revenue Management Software
1 source article · read the reporting →
Character.AI hosts hateful chatbots spewing antisemitic and racist content
An Evening Standard investigation found chatbots based on Adolf Hitler, Saddam Hussein, and the Prophet Muhammad on Character.AI that generated antisemitic, racist, and homophobic content. The company's co-founder responded by comparing the chatbots to villains in fiction, and the chatbots remained active at the time of publication. The article alleges that the platform lacks adequate moderation.
- Company involved
- Character.AI
- AI system involved
- Character.AI
5 source articles · read the reporting →
Brookdale Senior Living algorithm blamed for understaffing at assisted-living facilities
Managers at Brookdale Senior Living, the largest assisted-living chain in the US, allege that an algorithm called 'Service Alignment' set staffing levels so low that facilities were dangerously short-handed. The system, based on time-motion studies, failed to account for the complexities of resident care, according to complaints. Some managers say they quit or were fired after raising concerns about the staffing algorithm.
- Company involved
- Brookdale Senior Living
- AI system involved
- Service Alignment
1 source article · read the reporting →
AI companion apps Chattee Chat and GiMe Chat leak intimate conversations of 400,000 users
Two AI companion apps, Chattee Chat and GiMe Chat, developed by Hong Kong-based Imagime Interactive Limited, exposed millions of intimate conversations and over 600,000 images from over 400,000 users. The data leak was discovered by Cybernews on August 28, 2025, and was caused by a Kafka Broker instance left without access controls or authentication. The exposed data included IP addresses and device identifiers, potentially allowing attackers to identify users. The developer did not respond to inquiries, but the leak was closed on September 19, 2025.
- Company involved
- Imagime Interactive Limited
- AI system involved
- Chattee Chat - AI Companion and GiMe Chat - AI Companion
4 source articles · read the reporting →
OpenClaw vulnerabilities enable data leakage and prompt injection
In January 2026, researchers at Giskard exploited a deployment of OpenClaw, an open-source agentic AI. They found that architectural weaknesses in the Control UI and session management allowed prompt injection and unauthorized tool use, leading to potential data leakage across user sessions. The article outlines hardening steps to prevent such vulnerabilities.
- AI system involved
- OpenClaw
6 source articles · read the reporting →
DOJ, Pinnacle reach settlement in RealPage case - Yahoo Finance
The system recommended rent prices to landlords, affecting renters' housing costs.
- Company involved
- Pinnacle Property Management Services
- AI system involved
- RealPage
1 source article · read the reporting →
Airbnb bans users in Australia using trustworthiness algorithm
Airbnb is accused of using an algorithm acquired from Trooly to score users' trustworthiness based on publicly available data, including social media and occupation. Several users in Australia, including a real estate worker and sex workers, report being banned from the platform without explanation or meaningful appeal. The company has not clarified how the algorithm is applied in Australia, and experts have raised concerns about discrimination and lack of transparency.
- Company involved
- Airbnb
- AI system involved
- Trooly
4 source articles · read the reporting →
Civitai dropped by cloud provider OctoML over CSAM image generation
Civitai, an AI image generation platform, was dropped by its cloud computing provider OctoML after an investigation by 404 Media found it was being used to generate images that could be categorized as child sexual abuse material (CSAM). The platform also faced scrutiny for nonconsensual deepfakes of celebrities and private citizens, primarily women. Civitai added new moderation filters in response, but OctoML terminated the business relationship.
- Company involved
- Civitai
- AI system involved
- Civitai
8 source articles · read the reporting →
Hello, this is your chatbot leaking: WotNot exposes 346K sensitive customer files - Cybernews
The system exposed sensitive personal files of individuals who used chatbots built by WotNot's customers.
- Company involved
- WotNot
- AI system involved
- WotNot
1 source article · read the reporting →
AI chatbot provider exposes 346,000 customer files, including ID documents, resumes, and medical records - Malwarebytes
The chatbot system exposed sensitive personal files of individuals who interacted with it.
- Company involved
- WotNot
1 source article · read the reporting →
Patagonia Targeted by Privacy Class Action for Use of Customer Service AI Software - Law.com
The system intercepted, recorded, and mined data from customer service calls, affecting customers' privacy.
- Company involved
- Patagonia
- AI system involved
- Talkdesk
1 source article · read the reporting →
United Airlines Chatbot Gave Wrong Travel Credit Info - Hoodline
The chatbot told a customer her $200 travel credit would last five years instead of one year.
- Company involved
- United Airlines
1 source article · read the reporting →
Delta’s AI Told A Passenger Her Flight Home Was Safe, Then Canceled It And Demanded Double To Rebook - View…
The AI canceled the passenger's entire roundtrip award ticket, including the return flight, after the passenger requested only the outbound be canceled.
- Company involved
- Delta Air Lines
- AI system involved
- Delta Concierge
1 source article · read the reporting →
Who Gives A Crap suspends AI agent after email error said prices would double - SmartCompany
The AI agent incorrectly confirmed a doubled subscription price to a customer.
- Company involved
- Who Gives A Crap
1 source article · read the reporting →
Air Canada ordered to pay customer after airline's chatbot misguided him about fares - Daily Hive
The chatbot told a customer he could apply for bereavement fares retroactively, leading him to book flights at full price expecting a partial refund.
- Company involved
- Air Canada
1 source article · read the reporting →
An Air Canada chatbot lied to a passenger about bereavement discounts - qz.com
The chatbot misinformed a passenger about eligibility for bereavement fares, leading him to pay full price instead of receiving a discount.
- Company involved
- Air Canada
1 source article · read the reporting →
Air Canada says its AI chatbot went rogue, misleading customers - Modern Ghana
The chatbot provided misleading information to customers.
- Company involved
- Air Canada
1 source article · read the reporting →
Air Canada refund customer like chatbot said it would - TechHQ
The chatbot informed the customer they were eligible for a refund, which the airline later denied.
- Company involved
- Air Canada
1 source article · read the reporting →