Verkada security breach exposes customer video and data
In March 2021, attackers compromised Verkada's platform and accessed video and image data from 97 customer organisations. The attackers used a misconfigured customer support server to gain access and viewed live video, accessed badge credentials for eight customers, and downloaded user lists. Verkada cut off access within hours and notified affected customers. The attacker, Tillie Kottmann, was later indicted by the U.S. Department of Justice.
- Company involved
- Verkada
- AI system involved
- Verkada Command platform with People Analytics
10 source articles · read the reporting →
Art gallery owner loses business after AI deepfake scam impersonating Pierce Brosnan
Simone Simms, owner of a Nottingham art gallery, was deceived by scammers using AI deepfake technology to impersonate actor Pierce Brosnan. She exchanged messages and had video calls with the fake Brosnan, leading her to send £3,000 and organise an exhibition, selling £20,000 in tickets. After the real Brosnan issued a cease-and-desist, she refunded the tickets and was forced to close her gallery, losing her £30,000 business.
1 source article · read the reporting →
Johnson / Estate of Fisher v. City of Annapolis (D. Maryland): AI-hallucinated content in court filing, (Attorney was dismissed by…
The AI generated fabricated case law and quotes that were included in a court filing, affecting the plaintiffs and the judicial process.
- Company involved
- City of Annapolis
1 source article · read the reporting →
Landberg v City of New York (CA NY (2d)): AI-hallucinated content in court filing, Monetary Sanction
AI-generated fake legal citations were included in a court filing, resulting in monetary sanctions against the attorney and his law firm.
1 source article · read the reporting →
Barteca Holdings v. Tacobarn (D. Connecticut): AI-hallucinated content in court filing, Monetary Sanction; Bar Referral
The attorney filed a court document containing AI-hallucinated legal authorities, misleading the court and opposing party.
- Company involved
- Hilary Miller
1 source article · read the reporting →
Thomas Raynard James v. Detective Kevin Conley, et al. (S.D. Florida): AI-hallucinated content in court filing, Bar Referral
AI generated hallucinated content in a court filing, affecting the legal process and the lawyers who filed it.
1 source article · read the reporting →
Heriberto Perez-Castillo v. Todd W. Blanche (7th Cir. CA): AI-hallucinated content in court filing, Monetary Sanction; Admonishment; Bar Referral
The AI generated false legal citations and quotations in an appellate brief, misleading the court and harming the client's immigration appeal.
1 source article · read the reporting →
TOV Realty, LLC v. Suarez; Kosel Equity, LLC v. MacGregor (SC Connecticut): AI-hallucinated content in court filing, 6 hours CLE;…
The AI generated legal briefs containing fabricated citations, which were submitted to the Connecticut Supreme Court.
- Company involved
- GLG Law LLC
- AI system involved
- ChatGPT
1 source article · read the reporting →
In re Rosslyn2016, LLC, et al. (S.D. Texas (Bankruptcy)): AI-hallucinated content in court filing, CLE on generative AI; Civil Contempt;…
The AI generated fabricated legal citations that were submitted to the bankruptcy court.
1 source article · read the reporting →
Hackers use deep voice tech in $35 million theft
Hackers used deep voice technology to impersonate a person and steal $35 million. The Dubai Public Prosecution Office is investigating the money laundering that occurred in January 2020. The United States Department of Justice filed an application to assist the UAE in collecting evidence.
7 source articles · read the reporting →
Henry v. Long Island University (E.D. New York): AI-hallucinated content in court filing, Two-year filing-disclosure sanction
The court granted a motion to dismiss and imposed sanctions on plaintiff's counsel for submitting a brief with AI-hallucinated fake cases.
1 source article · read the reporting →
JMOR Properties v. Artist Alley Townhomes et al. (CA Florida (4d)): AI-hallucinated content in court filing, Bar Referral
The AI generated fabricated legal citations that were included in a court filing, affecting the court and the opposing party.
1 source article · read the reporting →
Beus Gilbert PLLC v. Brigham Young University et al. (D. Utah): AI-hallucinated content in court filing, Two AI-ethics CLE courses;…
The AI system generated fake legal citations that were included in a court filing, misleading the court and opposing counsel.
1 source article · read the reporting →
Jessica Fuller v. Hyde School, et al. (D. Maine): AI-hallucinated content in court filing, CLE; Firm procedures and certification; Serve…
The AI generated fictitious legal citations that were submitted to the court in a legal filing.
- AI system involved
- ChatGPT or Claude
1 source article · read the reporting →
Answer.AI tests Devin and reports 14 failures in 20 tasks
Answer.AI's team tested Devin, an autonomous AI coding assistant, on 20 real-world tasks over a month. Devin succeeded in only 3 tasks, failed 14, and was inconclusive in 3. The team found Devin often produced overly complex or hallucinated solutions and could not recognize fundamental blockers. They ultimately decided to stick with tools that allow more human control.
- AI system involved
- Devin
5 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
City analyst Michael Hewson cloned in AI deepfake scam on social media
A deepfake video using AI to impersonate City analyst Michael Hewson circulated on Facebook and Instagram, directing users to a WhatsApp group promising undervalued investments. The scam used fear-of-missing-out tactics to lure victims. Hewson publicly disavowed the video and reported it to Meta, expressing anger.
- Company involved
- Meta
4 source articles · read the reporting →
SEC charges American Bitcoin Academy over $1.2M AI scam
Brian Sewell, through his company American Bitcoin Academy, allegedly defrauded 15 students of $1.2 million by claiming his Rockwell Fund would use AI to generate high returns. The SEC charged that Sewell never launched the fund and lost the investors' money when his Bitcoin wallet was hacked. The case was settled with Sewell agreeing to pay $1.6 million in disgorgement and a $233,229 penalty.
- Company involved
- American Bitcoin Academy
6 source articles · read the reporting →
Hive Box Facial-Recognition Lockers Hacked by Children Using Photos
Fourth-grade students in Jiaxing, China, demonstrated that Hive Box's facial-recognition smart lockers could be opened with a printed photo. The company, which operates a large network of delivery lockers, acknowledged the flaw and suspended the beta feature. The incident raised concerns about the security of facial recognition technology.
- Company involved
- Hive Box
1 source article · read the reporting →
Hacker tricks Freysa AI chatbot into transferring $47,000 prize pool
A hacker using the alias 'p0pular.eth' successfully manipulated the Freysa AI chatbot through a prompt injection attack, tricking it into transferring its entire balance of 13.19 ETH (approximately $47,000) from a prize pool. The chatbot was designed to never transfer money, but the hacker crafted a message that redefined the 'approveTransfer' function and announced a fake $100 deposit, causing the bot to release the funds. The incident occurred during a pay-to-play contest where participants paid escalating fees to attempt the hack, with the winner receiving the prize pool.
- Company involved
- Freysa.ai
- AI system involved
- Freysa
4 source articles · read the reporting →
Paradox security vulnerability exposed candidate data to researchers
On June 30, 2025, security researchers discovered a vulnerability in Paradox's test account that allowed access to chat interaction records. The researchers viewed five candidates' personal information including names, email addresses, phone numbers, and IP addresses. Paradox fixed the issue within hours and stated that no data was leaked publicly. The company has since implemented new security measures.
- Company involved
- Paradox
- AI system involved
- Paradox conversational AI platform
10 source articles · read the reporting →
Prime Video AI-generated Fallout recap gets plot details wrong
Prime Video used generative AI to create an official recap of Fallout's first season. The AI got major plot details wrong, describing a pre-war scene as a '1950s Flashback' when the bombs dropped in 2077, and misrepresenting Lucy's decision to join The Ghoul. The article criticises Amazon for using AI instead of human writers for the recap.
- Company involved
- Prime Video
5 source articles · read the reporting →
Bots and short sellers spread misinformation to trigger First Republic Bank run
A report by Valent Technologies alleges that AI-powered bots and fake accounts spread misinformation about First Republic Bank in March 2023, coinciding with a $100 billion deposit withdrawal and the bank's collapse. The report suggests short sellers likely orchestrated the bots to drive down the share price. Federal regulators closed the bank and sold its assets to J.P. Morgan, and the bank's former CEO attributed the collapse to 'contamination' by anxiety.
2 source articles · read the reporting →
Anthropic's Claude Cowork AI deletes user's 15 years of family photos
A venture capitalist used Anthropic's Claude Cowork AI agent to organise his wife's desktop, granting it permission to delete temporary files. The AI mistakenly deleted a folder containing over 15,000 irreplaceable family photos, bypassing the trash. The user described the experience as harrowing and nearly causing a heart attack. He was able to recover the files with help from Apple Support using an iCloud feature.
- AI system involved
- Claude Cowork
1 source article · read the reporting →