Verkada security breach exposes customer video and data
In March 2021, attackers compromised Verkada's platform and accessed video and image data from 97 customer organisations. The attackers used a misconfigured customer support server to gain access and viewed live video, accessed badge credentials for eight customers, and downloaded user lists. Verkada cut off access within hours and notified affected customers. The attacker, Tillie Kottmann, was later indicted by the U.S. Department of Justice.
- Company involved
- Verkada
- AI system involved
- Verkada Command platform with People Analytics
10 source articles · read the reporting →
Judge rules police search using Flock was mass surveillance
A judge ruled that a police search using Flock's automated license plate readers constituted a form of mass surveillance. The ruling concerns the deployment of the AI-based camera system by law enforcement, which the court found to be an invasive surveillance practice. No further details of the case were provided in the article.
- AI system involved
- Flock
4 source articles · read the reporting →
Airbnb smart-pricing algorithm increased racial revenue gap, study finds
A study by Carnegie Mellon University found that Airbnb's smart-pricing algorithm increased the revenue gap between White and Black hosts, even though it narrowed the gap among hosts who adopted it. The algorithm, which sets daily prices automatically, was adopted by fewer Black hosts, so its suggested prices were closer to the optimum for White hosts. The researchers said the tool could reduce racial disparities only if more Black hosts adopted it.
- Company involved
- Airbnb
- AI system involved
- Airbnb smart-pricing algorithm
10 source articles · read the reporting →
Adobe uses Creative Cloud user data to train AI
Adobe's content analysis feature may scan Creative Cloud and Document Cloud files to train machine learning models, including object recognition in Lightroom and Liquid Mode in Acrobat. The company says it may analyze images, audio, video, text and other documents stored on its servers. Adobe offers an opt-out in account privacy settings, but the article notes the company did not ask first.
- Company involved
- Adobe
- AI system involved
- Content analysis
10 source articles · read the reporting →
Hospitals use Epic AI to predict Covid-19 decline without validation
Dozens of hospitals across the US are using Epic's deterioration index AI system to predict which Covid-19 patients will become critically ill, despite the tool not being validated for the new disease. The rapid deployment during the pandemic bypassed normal testing and validation processes.
- AI system involved
- Deterioration index
9 source articles · read the reporting →
Senators question privacy of facial recognition tablets in Uber and Lyft vehicles
U.S. Senators Amy Klobuchar and Richard Blumenthal sent a letter to Uber and Lyft demanding information about interactive tablets installed in vehicles that use facial recognition to target ads. The tablets, provided by company Alfi, use AI to identify passengers' race, gender, and approximate age to serve personalized content. The senators expressed concerns about data collection and privacy, while Alfi claims its automation respects privacy without tracking identifiable information. No specific harm has been reported, but the senators are seeking answers about how the technology is used.
- Company involved
- Uber and Lyft
- AI system involved
- Alfi interactive tablets with facial recognition AI
10 source articles · read the reporting →
Tapia robot vulnerability at Henn na Hotels allows remote spying on guests.
A security researcher disclosed a vulnerability in the Tapia robot deployed at Henn na Hotels (Robot Hotels) in Japan. The robot accepts unsigned code via NFC, allowing an attacker to gain remote access to its camera and microphone. The researcher reported the issue to the vendor 90 days prior but received no response. The vulnerability potentially affects all future hotel guests.
- Company involved
- Henn na Hotels
- AI system involved
- Tapia robot
10 source articles · read the reporting →
Character.AI accidentally exposes users' chat histories and personal data
Character.AI users reported being unexpectedly logged into strangers' accounts, exposing their chat histories, personas, and identifying information. The Google-backed chatbot company acknowledged the security lapse and said it quickly corrected the issue. The incident raises serious privacy concerns for the platform's users.
- Company involved
- Character.AI
- AI system involved
- Character.AI
1 source article · read the reporting →
Cloudflare outage on November 18, 2025 due to Bot Management error
On 18 November 2025, Cloudflare's network experienced a significant outage from 11:20 to 17:06 UTC, returning HTTP 5xx errors to users accessing customers' sites. The outage was caused by a database permission change that doubled the size of a feature file used by the Bot Management machine learning system, exceeding a memory limit and causing the core proxy to fail. Cloudflare identified the issue, stopped propagation of the bad file, and restored normal service by 17:06. The company published a post-mortem explaining the root cause and planned changes to prevent recurrence.
- Company involved
- Cloudflare
- AI system involved
- Bot Management
7 source articles · read the reporting →
Google indexed public Bard chat URLs, raising privacy concerns
In September 2023, users discovered that Google Search was indexing URLs of shared conversations with its Bard chatbot, potentially exposing personal information shared in those chats to anyone via search. Google acknowledged the issue and said it was working to block indexing. By September 28, the conversations were no longer showing up in search results, and Google had fixed the problem.
- Company involved
- Google
- AI system involved
- Bard
10 source articles · read the reporting →
Apple's Enhanced Visual Search raises privacy concerns over default data sharing
Apple's iOS 18 update introduced an 'Enhanced Visual Search' feature that automatically shares encrypted photo data with Apple to identify landmarks. The feature is enabled by default, requiring users to manually opt out, which has sparked privacy concerns. Critics argue it should be opt-in, given Apple's usual privacy standards. The article reports on the feature's design and the resulting debate, not on any specific harm to an individual.
- Company involved
- Apple
- AI system involved
- Enhanced Visual Search
5 source articles · read the reporting →
AI-generated travel guides flood Amazon, deceiving customers
AI-generated travel guides are flooding Amazon, allegedly written by scammers using AI to produce generic, low-quality content. Customers who purchase these guides receive poor information and feel defrauded. Amazon claims to enforce content guidelines but many such books remain on the platform.
- Company involved
- Amazon
8 source articles · read the reporting →
Good Daily operates AI-generated local news network without disclosure
Good Daily Inc., run by Matthew Henderson, operates hundreds of AI-generated local newsletters across the U.S. that aggregate and summarize news from local outlets. The newsletters use large language models without disclosing this to subscribers, and feature fabricated testimonials. Some readers reported being signed up without their consent. Local news outlets have criticized the network for not driving meaningful traffic and for undermining trust.
- Company involved
- Good Daily Inc.
- AI system involved
- Good Daily
3 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
Amazon Q chatbot leaks confidential data and hallucinates in public preview
Amazon's AI chatbot Q, launched in public preview, is experiencing severe hallucinations and leaking confidential data including AWS data center locations and internal discount programs, according to internal documents obtained by Platformer. Employees marked the incident as severity 2, requiring urgent fixes. Amazon denied the leak and said it will continue to tune the system.
- Company involved
- Amazon
- AI system involved
- Amazon Q
10 source articles · read the reporting →
Presto Automation uses off-site human agents to double-check AI drive-thru orders
Presto Automation Inc, which markets an AI voice assistant for drive-thru ordering, used off-site human agents in countries including the Philippines to double-check orders in more than 70% of customer interactions, according to SEC filings reported by Bloomberg. The company told Bloomberg that the process helps train its system and should reduce human intervention over time. Presto's drive-thru AI is used in more than 400 restaurants, including Del Taco, Carl's Jr and Checkers, and its stock fell more than 10% after the reports.
- Company involved
- Presto Automation Inc.
8 source articles · read the reporting →
Chattr.ai exposed job applicant data due to insecure Firebase rules
A security researcher discovered that Chattr.ai, an AI hiring system used by many fast food chains, had a Firebase database with insecure security rules. By registering a new user, the researcher gained full read/write access to the database, exposing personal data of job applicants and employees, including names, phone numbers, emails, and some plaintext passwords. The vulnerability was reported to Chattr.ai on 9 January and patched the next day, but the company did not provide further contact or thanks.
- Company involved
- Chattr.ai
- AI system involved
- Chattr.ai
6 source articles · read the reporting →
SoundCloud revises AI training terms after artist backlash
SoundCloud faced criticism after artists and AI experts spotted a February 2024 Terms of Use update that appeared to allow the platform to use uploaded content to train AI models. CEO Eliah Seton responded on May 14, 2025, saying the language was 'too broad' and announcing revised terms that rule out training generative AI on artists' content without explicit opt-in consent. SoundCloud maintains it never actually used artist content to train AI models.
- Company involved
- SoundCloud
4 source articles · read the reporting →
Evolv weapon detection system falsely flags Chromebooks as weapons
Evolv's AI-based weapon detection system has been reported to falsely identify certain Chromebook laptops as weapons, causing false alarms at security checkpoints. The system is used in venues such as schools. The article discusses the flaw and user experiences. No official response from Evolv has been mentioned.
- Company involved
- Evolv
- AI system involved
- Evolv
5 source articles · read the reporting →
Slack trains AI features on user messages and files by default
Slack uses user messages, files, and data to train its machine learning features such as channel recommendations and emoji suggestions. Users are opted in by default and cannot individually opt out; only workspace administrators can request exclusion via email. A user publicly criticized the practice, and Slack acknowledged the policy but did not change it.
- Company involved
- Slack
10 source articles · read the reporting →
Baltimore schools monitor student laptops for suicide signs using GoGuardian Beacon
Baltimore City Public Schools uses GoGuardian Beacon software to monitor student laptops for signs of suicide. Since March 2021, the system has flagged 786 alerts, with nine students taken to emergency rooms. Privacy advocates warn the monitoring could lead to disciplinary actions, outing of LGBTQ students, and disproportionately affect disadvantaged students. School officials defend the practice as a safeguard.
- Company involved
- Baltimore City Public Schools
- AI system involved
- GoGuardian Beacon
10 source articles · read the reporting →
OpenDream AI art site allowed users to generate child sexual abuse material
OpenDream, an AI image generation platform, allowed users to generate and publicly display child sexual abuse material (CSAM) and non-consensual deepfakes from at least December 2023 until July 2024. The platform, operated by CBM Media Pte Ltd in Singapore, offered paid plans with NSFW prompts and models. Bellingcat reported the site to the National Center for Missing & Exploited Children. After Bellingcat's inquiry, the CSAM was removed from the site and search engines, and Google terminated OpenDream's AdSense account.
- Company involved
- CBM Media Pte Ltd
- AI system involved
- OpenDream
3 source articles · read the reporting →
Delta uses AI from Fetcherr for domestic ticket pricing
Delta Air Lines is using generative AI from Fetcherr to determine some domestic flight prices, currently covering 3% of its network with plans to reach 20% by end of 2025. Democratic senators expressed concern that the AI could be used for individualized pricing based on personal data, leading to higher fares. Delta denies using personal data in pricing and states it complies with regulations. No actual harm has been reported.
- Company involved
- Delta Air Lines
- AI system involved
- Fetcherr
8 source articles · read the reporting →
Vumacam's AI CCTV system flagged 28 black people as suspicious in Johannesburg suburbs
In Johannesburg suburbs, Vumacam's AI-powered CCTV network using iSentry software flagged 28 black individuals as 'suspicious' in a shift report, according to a 2019 article. The system, deployed by private security firms, uses video analytics to detect abnormal behavior and alerts security guards. The article alleges that the system disproportionately targets people of color, reflecting racial bias in a racially divided country.
- Company involved
- Vumacam
- AI system involved
- iSentry
6 source articles · read the reporting →