Facebook Allowed Age-Targeted Credit Card Ads Violating Its Policy
The Markup found that four companies—Aspiration, Hometap, Chime, and Varo Bank—ran Facebook ads for credit cards and home equity loans that were targeted by age, excluding users under 25 or 35. This practice violates Facebook's own anti-discrimination policy and may violate the Equal Credit Opportunity Act and California's Unruh Civil Rights Act. Facebook did not respond to requests for comment, and some advertisers said they would review their ad targeting.
- Company involved
- Facebook
- AI system involved
- Facebook Ad Platform
9 source articles · read the reporting →
GSMA fined €200,000 for facial recognition privacy violation at MWC
In 2021, Dr Anastasia Dedyukhina was invited to speak at Mobile World Congress in Barcelona. The organizers required her to upload biometric data (passport) online for identity verification, which she refused. She was then forced to attend virtually. She filed a complaint with the Spanish data protection agency (AEPD) along with Adam Leon Smith. Two years later, the AEPD fined GSMA €200,000 for infringing the privacy of nearly 20,000 attendees through the use of facial recognition without proper justification.
- Company involved
- GSMA
10 source articles · read the reporting →
Canadian Tire chided by BC privacy commissioner for facial recognition without consent
Canadian Tire deployed facial recognition in at least four British Columbia stores between 2018 and 2021 to curb theft and increase staff safety. The BC Privacy Commissioner investigated and found the retailer failed to show a reasonable purpose and did not obtain customer consent, violating the province's Personal Information Protection Act. After the investigation was announced, Canadian Tire discontinued use of the system at all 12 locations and deleted customer data. The commissioner recommended stronger privacy policies and government regulation of biometric technologies.
- Company involved
- Canadian Tire
10 source articles · read the reporting →
Mercadona fined €2.5 million for facial recognition pilot
Mercadona, a Spanish supermarket chain, tested an early-detection system using facial recognition in 48 stores to identify people with judicial restraining orders. The system, which operated with court authorisation, notified police when such a person was detected. The Spanish data protection authority (AEPD) imposed a €2.5 million fine, which Mercadona paid, and the company has since removed the system citing legal uncertainty.
- Company involved
- Mercadona
- AI system involved
- Sistema de Detección Anticipada (Early Detection System)
10 source articles · read the reporting →
CBSA tested facial recognition on millions at Toronto Pearson Airport in 2016
In 2016, the Canada Border Services Agency (CBSA) secretly tested facial recognition technology on millions of travellers at Toronto Pearson Airport without their knowledge. The system, supplied by Face4 Systems, matched faces against a database of previously deported individuals. The CBSA stated that no one was deported as a result of the pilot, and the technology was removed after six months. Privacy advocates raised concerns about lack of consent, transparency, and potential racial bias.
- Company involved
- Canada Border Services Agency
- AI system involved
- Faces on the Move
8 source articles · read the reporting →
Amazon expands palm-scanning payments to all Whole Foods stores amid privacy concerns
Amazon is expanding its Amazon One palm-scanning payment system to all Whole Foods stores by the end of 2023. The biometric technology, which creates a unique palm signature from vein patterns, is used for payments and identification. Privacy advocates and lawmakers have raised concerns about surveillance, data sharing, and security risks. Amazon faces a class action lawsuit under New York City's biometric privacy law for allegedly failing to provide adequate notice.
- Company involved
- Amazon
- AI system involved
- Amazon One
9 source articles · read the reporting →
Study finds credit score algorithms less accurate for minorities
A study of 50 million US consumers found that credit scoring algorithms used by mortgage lenders are less accurate for minority and low-income applicants due to sparse credit data, leading to higher rejection rates. The inaccuracy is due to noise in the data, not bias, so fairer algorithms cannot fix it. The study suggests that adjusting for bias had no effect, and that addressing the inaccuracy could reduce disparities by 50%.
- Company involved
- Mortgage lenders (unnamed)
- AI system involved
- Credit scoring algorithms
6 source articles · read the reporting →
LAPD told officers to collect social media data on every civilian stopped
The Los Angeles Police Department directed officers to record the social media accounts of every civilian they interviewed, including those not arrested or accused of a crime, according to records obtained by the Brennan Center for Justice. The field interview cards, which also ask for social security numbers, have raised civil liberties concerns. Prosecutors have accused three officers of using the cards to falsely label civilians as gang members. The LAPD said the policy was being updated but did not respond to questions about its use of social media monitoring tools including Media Sonar and Geofeedia.
- Company involved
- Los Angeles Police Department (LAPD)
- AI system involved
- Field interview cards, Media Sonar, Geofeedia
10 source articles · read the reporting →
Face recognition bypass used to register shell companies for tax fraud in Shanghai
In a major tax fraud case in Shanghai, criminals used face recognition cracking techniques to register shell companies on government platforms. They purchased high-resolution photos and used apps to create fake videos, then used modified phones to bypass face recognition authentication. The scheme resulted in fraudulent invoices totaling over 500 million yuan. The case was prosecuted by the Shanghai procuratorate.
7 source articles · read the reporting →
Zhengzhou officials punished for red health codes on depositors
Five officials in Zhengzhou were punished for ordering red health codes to be assigned to 1,317 depositors of four village banks, restricting their movement and preventing them from withdrawing savings. The officials acted without authorization, and the codes were later turned green after media coverage. Legal experts say the liability for privacy invasion remains unresolved, and the banks may face breach of contract claims.
- Company involved
- Zhengzhou municipal government
- AI system involved
- Health code system
10 source articles · read the reporting →
WorldCoin suspended in Kenya over data security concerns
WorldCoin, a digital identification protocol using iris scans, was suspended by Kenyan regulators (ODPC and Communications Authority) over concerns about data security, consent, and oversight. The system had issued digital IDs and cryptocurrency tokens to over 350,000 Kenyans. Reports of hacked orb operators and iris scans traded on the dark web have also emerged.
- Company involved
- Tools for Humanity GmbH
- AI system involved
- WorldCoin
10 source articles · read the reporting →
California DMV suspends Cruise LLC driverless and deployment permits
The California Department of Motor Vehicles suspended Cruise LLC's autonomous vehicle deployment and driverless testing permits, saying the vehicles were not safe for public operation and that Cruise had misrepresented safety information. The suspension took effect immediately under California regulations. Cruise may apply to reinstate the permits once it satisfies the department's requirements. Its permit for testing with a safety driver was not affected.
- Company involved
- Cruise LLC
10 source articles · read the reporting →
IRCC uses AI triage for Temporary Resident Visa applications
Immigration, Refugees and Citizenship Canada (IRCC) uses an AI system called Advanced Analytics to triage Temporary Resident Visa applications from India and China. The system categorizes applications into tiers, with Tier 1 approved automatically and others sent to human officers. Critics allege the system lacks transparency and may introduce bias, leading to visa refusals without clear rationale. The author, a Canadian immigration lawyer, is filing Federal Court cases on behalf of clients affected by refusals.
- Company involved
- Immigration, Refugees and Citizenship Canada (IRCC)
- AI system involved
- Advanced Analytics Triage of Overseas Temporary Resident Visa Applications
10 source articles · read the reporting →
US CBP deploys CBP One app using facial recognition for asylum seekers amid privacy concerns
The article reports that U.S. Customs and Border Protection quietly deployed the CBP One mobile app at the Mexico border. The app uses facial recognition and geolocation to collect and verify information on asylum seekers before they enter the United States. Privacy experts warn that the app poses risks of persistent surveillance and that the facial recognition algorithm is unreliable for people of colour. A previous CBP facial recognition pilot was hacked, exposing images. CBP says the app is voluntary and data is secure.
- Company involved
- U.S. Customs and Border Protection
- AI system involved
- CBP One
8 source articles · read the reporting →
N-Tech.lab's FindFace used to identify St Petersburg metro passengers without consent
Egor Tsvetkov photographed passengers on the St Petersburg metro without their permission and used N-Tech.lab's facial recognition service FindFace to match their faces to public Vkontakte profiles. He published the results in an art project called 'Your Face is Big Data', saying he wanted to show how 'digital narcissism' can lead to stalking. Privacy advocates said the project was ethically problematic because the subjects had not consented and their identities were exposed. FindFace had been launched by N-Tech.lab in February 2016.
- Company involved
- N-Tech.lab
- AI system involved
- FindFace
8 source articles · read the reporting →
OnlyFake site uses neural networks to generate fake IDs, bypasses OKX verification
An underground website called OnlyFake uses neural networks to generate realistic photos of fake IDs for $15. The journalist tested the service and obtained a convincing California driver's license. They then used another fake ID to successfully bypass the identity verification process on OKX, a cryptocurrency exchange. The article alleges that this technology could streamline bank fraud and money laundering, but reports no actual financial loss.
- Company involved
- OKX
- AI system involved
- OnlyFake
10 source articles · read the reporting →
Worldcoin collected biometric data from poor villagers in Indonesia without informed consent
Worldcoin, a cryptocurrency startup, recruited users in developing countries by offering free cash in exchange for iris scans. The company used deceptive marketing, collected more personal data than acknowledged, and failed to obtain meaningful informed consent. Many users received worthless tokens instead of promised money. The company acknowledged some friction but continued its operations.
- Company involved
- Worldcoin
- AI system involved
- chrome orb
5 source articles · read the reporting →
Northeast Ohio man scammed out of $20,000 by deepfake Elton John video
A 71-year-old man in Northeast Ohio was scammed out of $20,000 after watching a deepfake video of Elton John on Instagram that falsely promised easy money through an online store. He was guided by two individuals posing as company representatives to open bank accounts and credit cards, which they then used to charge his cards. The victim, who was working part-time and seeking extra income, is now in debt and has returned to full-time work. One credit card company has credited $9,400, and he is working to recover the remaining funds.
1 source article · read the reporting →
CJEU rules Dun & Bradstreet must explain automated credit decisions under GDPR
A customer was refused a mobile phone contract because of an automated credit assessment by Dun & Bradstreet Austria. The customer took the case to court, which found that Dun & Bradstreet had infringed the GDPR by failing to provide meaningful information about the logic involved. The CJEU ruled that data controllers must explain automated decisions and that trade secrets cannot automatically override the right of access.
- Company involved
- Dun & Bradstreet Austria GmbH
7 source articles · read the reporting →
Woman denied state welfare card groceries after face scan fails
A grandmother rode her motorcycle several kilometres to a shop in Sapphaya district, Chai Nat province, to use her state welfare card to buy groceries for her family. After selecting items, she failed repeated facial recognition scans because her ID card photo was years old and no longer matched her appearance. She left the shop empty-handed and in tears.
- Company involved
- Government of Thailand (state welfare card system)
2 source articles · read the reporting →
Parking Enforcement Services wrongly fines parents due to faulty licence plate cameras
Dozens of parents at a Christchurch childcare centre were wrongly issued $85 parking fines by Parking Enforcement Services after its licence plate recognition cameras failed to accurately capture multiple short visits. The company acknowledged some misreads and waived fines on appeal, but parents described the process as stressful and time-consuming. An additional camera was installed to improve accuracy.
- Company involved
- Parking Enforcement Services
1 source article · read the reporting →
DWP algorithm approved Kickstart gateways with no trading history or based abroad
An FE Week investigation found that the Department for Work and Pensions (DWP) approved dozens of companies as Kickstart gateways through automated due diligence checks using the Cabinet Office Spotlight Tool, although some had little or no trading history or were based abroad. The DWP said gateways were subject to stringent checks and later said human checks were also used. After the findings were shared with the Treasury and the DWP, the department stopped taking gateway applications and scrapped the requirement for small employers to use gateways from 3 February.
- Company involved
- Department for Work and Pensions
- AI system involved
- Cabinet Office Spotlight Tool
3 source articles · read the reporting →
CBSE OnMark portal vulnerability exposed student data to Google Gemini
A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.
- Company involved
- Central Board of Secondary Education (CBSE)
- AI system involved
- OnMark
1 source article · read the reporting →
Outabox hack exposes biometric data of patrons at bars, clubs and casinos
Hackers claiming to be former employees published a website allowing searches of Outabox's facial recognition database, exposing biometric and other sensitive data of patrons used for age verification at bars, clubs and casinos. The Surveillance Technology Oversight Project warns that the breach demonstrates the danger of facial recognition for age verification. S.T.O.P. has launched a campaign to ban facial recognition in public accommodations.
- Company involved
- Outabox
8 source articles · read the reporting →