ProctorU data breach exposes 444,000 user records
ProctorU, an online exam proctoring service, confirmed a data breach after a threat actor leaked a database of user records on a hacker forum. The database contained email addresses, names, addresses, phone numbers, and hashed passwords for approximately 444,000 users, including students from universities such as UCLA, Princeton, and Harvard, as well as U.S. military members. ProctorU stated that the breach involved records from 2014 and that they are investigating the incident.
- Company involved
- ProctorU
- AI system involved
- ProctorU
8 source articles · read the reporting →
Proctortrack data breach exposed student data from online proctoring
Proctortrack, an online proctoring service used by universities, suffered a data breach in September 2020 when its source code was leaked online. An analysis by Consumer Reports found that the code contained hard-coded passwords and exposed the names and email addresses of over 150 students. The company acknowledged the leak but said no harm resulted. Students had been required to use the software, which performed facial recognition and recorded video during exams.
- Company involved
- Proctortrack
- AI system involved
- Proctortrack
10 source articles · read the reporting →
Proctorio's exam proctoring system allows human agents to review student feeds despite privacy claims
A security researcher analyzed Proctorio's Chrome extension and found evidence that the system allows human agents to review students' room scans and live ID checks, contrary to Proctorio's claims that only professors can access recordings. The system flags students based on behavioral metrics and can terminate exams. The researcher also raised concerns about discrimination against low-income students and privacy violations.
- Company involved
- Proctorio
- AI system involved
- Proctorio
10 source articles · read the reporting →
ExamSoft failure during Michigan Bar Exam
On July 28, 2020, ExamSoft's software platform failed during the Michigan Bar Exam, preventing some test takers from completing the exam. ExamSoft posted a statement on X (formerly Twitter) with the hashtag #MichiganBarExam, but critics noted the company deleted and reposted the statement multiple times, allegedly to hide negative comments. The incident affected a group of examinees and caused disruption to their ability to take the exam.
- Company involved
- ExamSoft
- AI system involved
- ExamSoft platform
10 source articles · read the reporting →
Student flagged by ProctorU for reading aloud during exam
A college student, Dana Jo, was flagged by ProctorU test proctoring software for talking during an exam, which she says was reading a question aloud. Her professor initially gave her a zero and placed an academic infraction on her record, jeopardizing her scholarships. After reviewing a video recording, the professor apologized, reinstated her grade, and removed the infraction. ProctorU's CEO stated that the incident highlights the importance of video recordings for review.
- Company involved
- University (not named)
- AI system involved
- ProctorU
5 source articles · read the reporting →
Teleperformance plans AI webcam surveillance for home-working staff
Teleperformance, a global call centre company, told some staff it would install AI-powered webcams to monitor home-working infractions such as eating, phone use, or leaving desks. The system would randomly scan for breaches and send alerts to managers. After the Guardian inquired, the company said the remote scans would not be used in the UK, but the plan raised concerns from unions and MPs about invasive surveillance.
- Company involved
- Teleperformance
10 source articles · read the reporting →
Faces of the Riot publishes extracted faces from Parler Capitol riot videos
The website Faces of the Riot used open source facial recognition software to extract and publish over 6,000 faces from Parler videos of the January 6 Capitol riot. The creator, an anonymous college student, aimed to help identify participants in the insurrection. The site has been criticised for privacy violations and potential vigilante misuse. The creator says they are working to remove non-rioter faces.
- Company involved
- Faces of the Riot
- AI system involved
- Faces of the Riot
8 source articles · read the reporting →
California bar exam facial recognition system fails to verify Arab-American student's identity
Ahmed Alamri, an Arab-American law student, was unable to register for the practice California bar exam because ExamSoft's facial recognition system repeatedly failed to recognize his face, citing poor lighting. Alamri attempted to verify his identity over 75 times in different rooms and lighting conditions without success. He and other students filed an emergency petition with the California Supreme Court, alleging that the system discriminates against people of color. The incident highlights concerns about bias in facial recognition technology used for exam proctoring.
- Company involved
- California State Bar
- AI system involved
- ExamSoft
10 source articles · read the reporting →
Cleveland State University's room scan requirement ruled unconstitutional
A federal judge ruled that Cleveland State University's requirement for a student to undergo a 360-degree room scan before an online exam was an unreasonable search under the Fourth Amendment. The student, enrolled at the public university, was told shortly before the exam that he would need to scan his private space. The court found that the university's justifications did not outweigh the privacy protections of the home. No final judgment or injunction has been issued yet.
- Company involved
- Cleveland State University
10 source articles · read the reporting →
UW-Madison disables Honorlock after skin tone recognition failure
The University of Wisconsin-Madison disabled the exam pause feature of its Honorlock anti-cheating software in March 2021 after three students complained that the software failed to recognize their darker skin tones and paused their exams. The software, used since online classes began, automatically pauses exams when it cannot detect facial features. Honorlock denied the issue was related to skin tone, attributing it to students looking away from their webcams. The university responded by disabling the feature.
- Company involved
- University of Wisconsin-Madison
- AI system involved
- Honorlock
10 source articles · read the reporting →
Userviz machine-learning aimbot shut down after Activision request
A developer known as User101 shut down the Userviz cheat after Activision requested that he stop developing it. The software used computer vision and machine learning to automate aiming in games such as Call of Duty: Warzone, and was marketed as undetectable. It was never published, and the developer said his intention was not to do anything illegal.
- Company involved
- User101
- AI system involved
- Userviz
7 source articles · read the reporting →
Company fires HR team after ATS auto-rejects manager's CV due to filtering error
A company's applicant tracking system (ATS) auto-rejected qualified candidates' resumes for three months because it was filtering for the outdated framework AngularJS instead of the required Angular framework. The manager discovered the flaw by submitting his own CV under a pseudonym and found it was rejected within seconds. After the manager reported the issue to upper management, the company investigated and dismissed half of its HR team. No legal action or regulatory involvement is reported.
4 source articles · read the reporting →
WebinarTV secretly records Zoom calls and turns them into AI podcasts
WebinarTV, a company that bills itself as a search engine for webinars, is secretly scanning the internet for Zoom meeting links, recording the calls, and turning them into AI-generated podcasts for profit. People only found out their calls were recorded when WebinarTV contacted them to promote its services. The recordings may put call participants at risk.
- Company involved
- WebinarTV
4 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
OPC launches investigation into OpenAI's ChatGPT over privacy complaint
The Office of the Privacy Commissioner of Canada (OPC) has launched an investigation into OpenAI, operator of the ChatGPT chatbot, in response to a complaint alleging the collection, use, and disclosure of personal information without consent. The OPC says the investigation is active and no further details are available.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
9 source articles · read the reporting →
DeepSeek-R1 censors 85% of sensitive Chinese political prompts in tests
Promptfoo tested DeepSeek-R1 against a dataset of 1,360 politically sensitive prompts and found that about 85% of them were refused. The refusals followed a standard form aligned with Chinese Communist Party policy. The testing also demonstrated that the censorship could be trivially bypassed using simple jailbreak techniques, such as prompt injection or changing the context.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
Meta tracks employee keystrokes on Google, LinkedIn, Wikipedia for AI training
Meta is using an internal tool, Model Capability Initiative (MCI), to capture employees' keystrokes, mouse movements and screen contents on work computers, including on sites such as Google, LinkedIn, Wikipedia and Slack, to train AI agents. Meta confirmed the project and said safeguards protect sensitive content and that the data is not used for other purposes. Employees raised concerns in internal messages that the tool could expose passwords, product details and personal information. A Meta memo said staff can avoid capture by not doing personal work on work computers.
- Company involved
- Meta
- AI system involved
- Model Capability Initiative (MCI)
5 source articles · read the reporting →
UIUC students petition to stop Proctorio exam proctoring over privacy concerns
A petition at the University of Illinois at Urbana-Champaign (UIUC) alleges that Proctorio, an online exam proctoring system, violates student privacy by accessing websites, downloads, screen content, and app settings. The petition claims the terms of service allow monitoring by 'any other means necessary', which students find unsettling. The petition, created on September 30, 2020, gathered 1,087 supporters but does not report any specific incident of harm. It calls on UIUC to discontinue use of Proctorio in favour of alternatives.
- Company involved
- UIUC
- AI system involved
- Proctorio
9 source articles · read the reporting →
Evolv weapon detection system falsely flags Chromebooks as weapons
Evolv's AI-based weapon detection system has been reported to falsely identify certain Chromebook laptops as weapons, causing false alarms at security checkpoints. The system is used in venues such as schools. The article discusses the flaw and user experiences. No official response from Evolv has been mentioned.
- Company involved
- Evolv
- AI system involved
- Evolv
5 source articles · read the reporting →
Baltimore schools monitor student laptops for suicide signs using GoGuardian Beacon
Baltimore City Public Schools uses GoGuardian Beacon software to monitor student laptops for signs of suicide. Since March 2021, the system has flagged 786 alerts, with nine students taken to emergency rooms. Privacy advocates warn the monitoring could lead to disciplinary actions, outing of LGBTQ students, and disproportionately affect disadvantaged students. School officials defend the practice as a safeguard.
- Company involved
- Baltimore City Public Schools
- AI system involved
- GoGuardian Beacon
10 source articles · read the reporting →
OpenAI and Anthropic ignore robots.txt to scrape web content for training data
OpenAI and Anthropic have been found to be ignoring or circumventing the robots.txt rule that prevents automated scraping of websites, according to a person with knowledge of TollBit's analytics. The AI companies are bypassing blocks to their web crawlers GPTBot and ClaudeBot to retrieve all content from publishers' websites for model training. The practice undermines the long-standing web standard and raises concerns about copyright infringement.
- Company involved
- OpenAI, Anthropic
- AI system involved
- ChatGPT, Claude
10 source articles · read the reporting →
Prosecraft shut down after using authors' books without consent for AI analytics
Prosecraft, a fiction analytics site, used the full text of over 25,000 books without author consent to train its AI algorithms and provide writing statistics. Authors protested on social media, demanding removal of their works. The developer, Benji Smith, subsequently shut down the site and wrote a blog post explaining his actions.
- Company involved
- Prosecraft
- AI system involved
- Prosecraft
10 source articles · read the reporting →
Proctorio anti-cheating software failed to catch student cheaters in study
Researchers at the University of Twente in the Netherlands tested Proctorio, an anti-cheating software, by asking 30 computer science students to sit an exam while six of them cheated. Proctorio did not flag any of the cheaters and flagged some honest students for irregular behaviour. An independent human review caught only one of the six cheaters. Proctorio disputed the study's methodology and cited other research.
- Company involved
- Proctorio
- AI system involved
- Proctorio
5 source articles · read the reporting →
UCCS professor secretly photographed over 1,700 people for facial recognition research
A University of Colorado Colorado Springs professor, Terrance Boult, led a project that secretly photographed more than 1,700 students, faculty, and passers-by on campus in 2012-2013 to improve facial recognition technology. The photos were published as a public dataset from 2016 until April 2019. University officials defended the research, but a law professor questioned the ethics of the surveillance without consent.
- Company involved
- University of Colorado Colorado Springs
10 source articles · read the reporting →