Companies face AI deepfake job candidates for remote roles
US companies report a surge in fake job seekers using generative AI tools to fabricate identities, employment histories, and conduct deepfake video interviews for remote positions. Cybersecurity firms Pindrop and CAT Labs, along with BrightHire, describe incidents where scammers, including North Korean operatives, attempted to gain employment to install malware, demand ransoms, steal data, or collect salaries fraudulently. One candidate, 'Ivan X', was detected by Pindrop's video authentication tool after a recruiter noticed his facial expressions were out of sync with his words.
- Company involved
- Pindrop Security
- AI system involved
- video authentication program
1 source article · read the reporting →
Texas AG Settles with Pieces Technologies Over Deceptive Healthcare AI Claims
The Texas Attorney General investigated Pieces Technologies, a Dallas-based healthcare AI company, for making false and misleading statements about the accuracy of its generative AI product used in hospitals. The company claimed an error rate of less than 1 per 100,000, but the investigation found these metrics were likely inaccurate. As part of the settlement, Pieces agreed to accurately disclose its product's accuracy and ensure hospital staff understand the appropriate reliance on its AI. The case marks the first-of-its-kind healthcare generative AI investigation by the AG.
- Company involved
- Pieces Technologies
4 source articles · read the reporting →
Microsoft funded Israeli facial recognition firm surveilling West Bank Palestinians
Microsoft invested in AnyVision, an Israeli facial recognition company whose technology powers a secret military surveillance project in the West Bank. The system, called Better Tomorrow, identifies and tracks Palestinians in live camera feeds. Microsoft said it would audit AnyVision for compliance with its ethical principles.
- Company involved
- Israeli Defense Forces
- AI system involved
- Better Tomorrow
10 source articles · read the reporting →
Attempted deepfake CEO voicemail fraud against an unnamed technology company
An attacker used synthetic audio deepfake to leave a voicemail impersonating the CEO of a technology company, asking an employee to call back to finalize an urgent business deal. The employee found it suspicious and referred the matter to the legal department, avoiding any loss. Nisos analyzed the audio and found inconsistencies in pitch and tone.
10 source articles · read the reporting →
UBC students raise concerns over Proctorio's privacy breach and discrimination
The University of British Columbia (UBC) uses Proctorio, an algorithmic test proctoring software, for remote exams. In June 2020, a UBC student reported an issue with Proctorio, and the company's CEO released the student's support chat logs, sparking privacy concerns. The AMS of UBC published an open letter alleging that Proctorio discriminates against students of colour, those with disabilities, and other groups by flagging 'abnormal' behaviours and denying access. The letter calls on UBC to end its contract with Proctorio and conduct an external audit.
- Company involved
- University of British Columbia
- AI system involved
- Proctorio
10 source articles · read the reporting →
ProctorU threatens UC Santa Barbara faculty over privacy criticism
ProctorU, an online proctoring service, sent a legal threat letter to the University of California Santa Barbara faculty association after the association expressed concerns about ProctorU's data privacy policies. The letter, from ProctorU's lawyer, invoked defamation, copyright, and trademark claims, and was copied to state and federal prosecutors. The faculty association had asked the university to reconsider its relationship with ProctorU due to concerns about student data sharing.
- Company involved
- ProctorU
- AI system involved
- ProctorU
10 source articles · read the reporting →
Proctortrack data breach exposed student data from online proctoring
Proctortrack, an online proctoring service used by universities, suffered a data breach in September 2020 when its source code was leaked online. An analysis by Consumer Reports found that the code contained hard-coded passwords and exposed the names and email addresses of over 150 students. The company acknowledged the leak but said no harm resulted. Students had been required to use the software, which performed facial recognition and recorded video during exams.
- Company involved
- Proctortrack
- AI system involved
- Proctortrack
10 source articles · read the reporting →
Portland Metro ends Replica partnership over data privacy concerns
Portland Metro, an elected regional government in Oregon, ended its pilot project with movement data company Replica after a disagreement about data sharing. Portland Metro requested raw, disaggregated data, which Replica refused to provide, citing user privacy concerns. The partnership was terminated without payment.
- Company involved
- Portland Metro
- AI system involved
- Replica
10 source articles · read the reporting →
PwC develops facial recognition tool to monitor employees working from home
Accounting giant PwC has developed a facial recognition tool that logs when employees are absent from their computer screens while working from home. The tool, intended for financial institutions, requires workers to provide written reasons for any absences, including toilet breaks. Commentators have criticised the tool as a huge invasion of privacy, with concerns about damage to trust and increased stress. PwC stated that the technology is designed to help regulated institutions meet compliance obligations and that voluntary consent of traders is essential.
- Company involved
- PwC
8 source articles · read the reporting →
California regulator accuses Maxpread Technologies of using AI-generated fake CEO to scam investors
Maxpread Technologies allegedly used an AI-generated avatar to pose as its CEO in a YouTube video to deceive investors. The California DFPI issued cease and desist letters to Maxpread and four other companies for offering unqualified securities and making false promises. The regulator claims the companies promised high daily returns using AI trading, but these claims were false. Maxpread did not respond to requests for comment.
- Company involved
- Maxpread Technologies
8 source articles · read the reporting →
Unity faces employee concerns over military contract transparency
An investigation by Vice Games reported that Unity Technologies is not transparent with its developers about military contracts. Employees allege some are unaware their work on AI tools may become part of Department of Defense projects. CEO John Riccitiello stated the company will not support programs that violate its principles, but sources say many staff are angry. Unity said it cannot police all uses of its engine as it is a tool available to anyone.
- Company involved
- Unity Technologies
- AI system involved
- Unity engine
8 source articles · read the reporting →
ScaleFactor reportedly failed to deliver promised automated bookkeeping software
ScaleFactor, an Austin-based startup, is reported to have failed to deliver the automated, real-time bookkeeping tools it promised customers, instead relying on human bookkeepers and a Filipino contract accounting firm. The company told Forbes in June that it was shutting down, initially blaming the pandemic, but Forbes later reported that its problems predated Covid-19. Investors reportedly came to see the company as more of a services business than a software platform, and pulled funding after a pivot to a marketplace model. No legal or regulatory action is reported.
- Company involved
- ScaleFactor
10 source articles · read the reporting →
Kaedim used human artists instead of AI for 3D model generation
Kaedim, an AI startup that claimed to use machine learning to convert 2D illustrations into 3D models, actually used human artists to produce the models, according to sources. The company's founder was featured in Forbes 30 Under 30 for the technology. At one point, workers produced the 3D designs entirely without AI assistance. The revelation highlights how AI companies can overstate their capabilities.
- Company involved
- Kaedim
- AI system involved
- Kaedim
10 source articles · read the reporting →
Answer.AI tests Devin and reports 14 failures in 20 tasks
Answer.AI's team tested Devin, an autonomous AI coding assistant, on 20 real-world tasks over a month. Devin succeeded in only 3 tasks, failed 14, and was inconclusive in 3. The team found Devin often produced overly complex or hallucinated solutions and could not recognize fundamental blockers. They ultimately decided to stick with tools that allow more human control.
- AI system involved
- Devin
5 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
Presto Automation uses off-site human agents to double-check AI drive-thru orders
Presto Automation Inc, which markets an AI voice assistant for drive-thru ordering, used off-site human agents in countries including the Philippines to double-check orders in more than 70% of customer interactions, according to SEC filings reported by Bloomberg. The company told Bloomberg that the process helps train its system and should reduce human intervention over time. Presto's drive-thru AI is used in more than 400 restaurants, including Del Taco, Carl's Jr and Checkers, and its stock fell more than 10% after the reports.
- Company involved
- Presto Automation Inc.
8 source articles · read the reporting →
DevTernity conference cancelled after fake women speakers exposed
The DevTernity software developer conference was cancelled after allegations that organiser Eduards Sizovs added fake women speakers to the lineup. Sizovs admitted at least one profile, 'Anna Boyko', was an auto-generated 'demo persona' that appeared on the site by mistake. The conference was scheduled to begin December 7 but was called off after several speakers withdrew. Sizovs denied wrongdoing and said he had fixed the code and written a test to prevent a recurrence.
- Company involved
- DevTernity
9 source articles · read the reporting →
OpenAI's Sora video generator leaked by group in protest
A group calling itself 'Sora PR Puppets' leaked access to OpenAI's Sora video generator by publishing a front end on Hugging Face using authentication tokens from an early access program. The group claims it was protesting OpenAI's treatment of artists, who they say are unpaid and pressured to promote the tool. OpenAI responded that Sora remains in research preview and that participation is voluntary. The leak was shut down after a few hours.
- Company involved
- OpenAI
- AI system involved
- Sora
5 source articles · read the reporting →
Prosecraft shut down after using authors' books without consent for AI analytics
Prosecraft, a fiction analytics site, used the full text of over 25,000 books without author consent to train its AI algorithms and provide writing statistics. Authors protested on social media, demanding removal of their works. The developer, Benji Smith, subsequently shut down the site and wrote a blog post explaining his actions.
- Company involved
- Prosecraft
- AI system involved
- Prosecraft
10 source articles · read the reporting →
Lattice cancels plan to give AI digital workers employee records after backlash
Lattice, an HR software company, announced on July 9th that it would give AI digital workers official employee records. After strong backlash from HR professionals and others on LinkedIn, the company canceled the feature on July 12th, stating it 'will not further pursue digital workers in the product.' The feature was intended to manage AI bots such as Devin and Piper, but the company reversed course.
- Company involved
- Lattice
- AI system involved
- Lattice
6 source articles · read the reporting →
Irish DPC takes Twitter to court over using user data to train Grok AI
The Irish Data Protection Commission has initiated High Court proceedings against Twitter International Unlimited Company over concerns that the company is processing personal data of millions of European X users to train its Grok AI system without adequate consent. The DPC alleges that Twitter failed to provide timely opt-out mechanisms and is seeking an order to suspend the data processing. Twitter denies any wrongdoing.
- Company involved
- Twitter International Unlimited Company
- AI system involved
- Grok
10 source articles · read the reporting →
Microsoft Copilot vulnerable to automated phishing and data theft
Security researcher Michael Bargury demonstrated at Black Hat that Microsoft's Copilot AI can be manipulated by attackers to send phishing emails, extract private data, and bypass security protections. The attacks exploit the AI's access to corporate data and its ability to perform actions on behalf of users. Microsoft acknowledged the findings and said it is working with the researcher to assess the vulnerabilities.
- Company involved
- Microsoft
- AI system involved
- Copilot
3 source articles · read the reporting →
Publishers sue AI startup Cohere over alleged copyright infringement
A consortium of 14 publishers including Condé Nast, The Atlantic, and Forbes filed a lawsuit against Cohere, alleging that the generative AI startup engaged in massive, systematic copyright infringement by using at least 4,000 copyrighted works to train its AI models and display large portions of articles, harming referral traffic. Cohere denied the allegations, calling the lawsuit misguided and frivolous.
- Company involved
- Cohere
- AI system involved
- Cohere's AI models
8 source articles · read the reporting →
US Central Command used Anthropic's Claude in Iran airstrikes after Trump ban.
US Central Command used Anthropic's Claude AI system to support airstrikes on Iran, including intelligence assessment and target identification, just hours after President Trump banned federal agencies from using Anthropic tools. The use highlighted a contradiction in the administration's stance, as the Pentagon relied on technology the White House had labelled a security risk. Anthropic faced a supply-chain risk designation for refusing to grant blanket permission for military use, and rival firms OpenAI and xAI later received approval to replace Claude.
- Company involved
- US Central Command (Centcom)
- AI system involved
- Claude
4 source articles · read the reporting →