The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

97 incidents closest to “Security Center” · matched on meaning · public reporting

341 Malicious ClawHub Skills Found Stealing OpenClaw User Data

Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.

Company involved
OpenClaw
AI system involved
OpenClaw

4 source articles · read the reporting →

WF-WEREB71 Feb 2024

Amnesty International reveals Serbian spyware targeting journalists and activists

Amnesty International's Security Lab found that Serbian authorities used Cellebrite tools and a previously unknown spyware named 'NoviSpy' to covertly infect the phones of independent journalist Slaviša Milanov and several activists. The infections occurred while devices were unattended during police or BIA interviews. The report alleges this is part of a wider crackdown on civil society, violating rights to privacy and free expression.

Company involved
Serbian Security Information Agency (BIA)
AI system involved
NoviSpy

7 source articles · read the reporting →

U.S. Border Patrol uses AI and ALPR to target drivers for pretext stops and asset seizures

The U.S. Border Patrol has built a nationwide dragnet driver-surveillance system using automated license plate readers and AI to flag suspicious travel patterns. Local police then pull over targeted drivers on pretexts, interrogate them, and seize cash and vehicles through civil asset forfeiture. The program has been kept secret, with details hidden from court documents and the public. The ACLU report highlights the abuse of innocent drivers and calls for congressional action.

Company involved
U.S. Border Patrol (CBP)
AI system involved
Automated license plate reader (ALPR) system with AI analytics

6 source articles · read the reporting →

WF-JWRXGY7 Jul 2020

Cense exposed 2.5 million records of auto accident victims online

On July 7, 2020, a security researcher discovered 2.5 million records containing personal and medical data of auto accident victims exposed online. The records, belonging to New York-based AI company Cense, included names, insurance policy numbers, claim numbers, and medical diagnosis notes. The data was labeled as staging data, possibly intended for temporary storage before being loaded into an AI system. After the researcher sent a responsible disclosure notice, Cense restricted public access to the database.

Company involved
Cense
AI system involved
Cense

5 source articles · read the reporting →

WF-RCBADC22 Feb 2023

Tesla changed Sentry Mode after Dutch privacy investigation

Tesla's Sentry Mode security cameras recorded passersby without their consent, storing footage for long periods. The Dutch Data Protection Authority investigated and Tesla subsequently required owner approval and added headlight alerts. No fine was issued.

Company involved
Tesla
AI system involved
Sentry Mode

8 source articles · read the reporting →

WF-JH5L2X26 Mar 2021

Teleperformance plans AI webcam surveillance for home-working staff

Teleperformance, a global call centre company, told some staff it would install AI-powered webcams to monitor home-working infractions such as eating, phone use, or leaving desks. The system would randomly scan for breaches and send alerts to managers. After the Guardian inquired, the company said the remote scans would not be used in the UK, but the plan raised concerns from unions and MPs about invasive surveillance.

Company involved
Teleperformance

10 source articles · read the reporting →

WF-TX7ZJM8 Mar 2021

Verkada security breach exposes customer video and data

In March 2021, attackers compromised Verkada's platform and accessed video and image data from 97 customer organisations. The attackers used a misconfigured customer support server to gain access and viewed live video, accessed badge credentials for eight customers, and downloaded user lists. Verkada cut off access within hours and notified affected customers. The attacker, Tillie Kottmann, was later indicted by the U.S. Department of Justice.

Company involved
Verkada
AI system involved
Verkada Command platform with People Analytics

10 source articles · read the reporting →

Cleveland State University's room scan requirement ruled unconstitutional

A federal judge ruled that Cleveland State University's requirement for a student to undergo a 360-degree room scan before an online exam was an unreasonable search under the Fourth Amendment. The student, enrolled at the public university, was told shortly before the exam that he would need to scan his private space. The court found that the university's justifications did not outweigh the privacy protections of the home. No final judgment or injunction has been issued yet.

Company involved
Cleveland State University

10 source articles · read the reporting →

WF-SQJYDZ22 Oct 2020

CBSE introduces facial recognition system for students to access digital documents

The Central Board of Secondary Education (CBSE) has introduced a facial recognition system for Class 10 and 12 students to access their digital academic documents. A live image of the student is compared with the photograph on their CBSE admit card and, if the match succeeds, the certificate is emailed to them. The facility is available on Digi Locker for 2020 records and is expected to help foreign students and those unable to open a Digi Locker account.

Company involved
Central Board of Secondary Education (CBSE)
AI system involved
Facial Recognition System

10 source articles · read the reporting →

WF-OS1OYR8 Sep 2021

LAPD told officers to collect social media data on every civilian stopped

The Los Angeles Police Department directed officers to record the social media accounts of every civilian they interviewed, including those not arrested or accused of a crime, according to records obtained by the Brennan Center for Justice. The field interview cards, which also ask for social security numbers, have raised civil liberties concerns. Prosecutors have accused three officers of using the cards to falsely label civilians as gang members. The LAPD said the policy was being updated but did not respond to questions about its use of social media monitoring tools including Media Sonar and Geofeedia.

Company involved
Los Angeles Police Department (LAPD)
AI system involved
Field interview cards, Media Sonar, Geofeedia

10 source articles · read the reporting →

WF-BQBMHB4 Aug 2023

WorldCoin suspended in Kenya over data security concerns

WorldCoin, a digital identification protocol using iris scans, was suspended by Kenyan regulators (ODPC and Communications Authority) over concerns about data security, consent, and oversight. The system had issued digital IDs and cryptocurrency tokens to over 350,000 Kenyans. Reports of hacked orb operators and iris scans traded on the dark web have also emerged.

Company involved
Tools for Humanity GmbH
AI system involved
WorldCoin

10 source articles · read the reporting →

WF-L8981D29 Jan 2025

DeepSeek exposed user data via open ClickHouse database

Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

DeepSeek-R1 censors 85% of sensitive Chinese political prompts in tests

Promptfoo tested DeepSeek-R1 against a dataset of 1,360 politically sensitive prompts and found that about 85% of them were refused. The refusals followed a standard form aligned with Chinese Communist Party policy. The testing also demonstrated that the censorship could be trivially bypassed using simple jailbreak techniques, such as prompt injection or changing the context.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

WF-LEN91Y1 May 2021

US CBP deploys CBP One app using facial recognition for asylum seekers amid privacy concerns

The article reports that U.S. Customs and Border Protection quietly deployed the CBP One mobile app at the Mexico border. The app uses facial recognition and geolocation to collect and verify information on asylum seekers before they enter the United States. Privacy experts warn that the app poses risks of persistent surveillance and that the facial recognition algorithm is unreliable for people of colour. A previous CBP facial recognition pilot was hacked, exposing images. CBP says the app is voluntary and data is secure.

Company involved
U.S. Customs and Border Protection
AI system involved
CBP One

8 source articles · read the reporting →

WF-PS9FKF1 Dec 2020

Houston's ShotSpotter system delays police response and over-polices minority communities

Houston Police Department deployed ShotSpotter, a gunshot detection system, in Southeast and Northwest Houston starting in late 2020. The system alerts police to suspected gunfire, but over 80% of alerts are unfounded. This has led to longer response times for other calls and increased police presence in predominantly Black and brown neighborhoods, causing anxiety and concerns of over-policing. Critics argue the technology has not reduced gun violence and diverts resources from more effective strategies.

Company involved
Houston Police Department
AI system involved
ShotSpotter

7 source articles · read the reporting →

WF-2X3B7831 Jan 2024

Hong Kong privacy watchdog raids Worldcoin offices over iris scan data collection

Hong Kong's privacy commissioner's office raided six premises linked to Worldcoin, a cryptocurrency company that requires an eye scan from clients for identification. The watchdog is investigating whether the collection of iris scans could lead to sensitive information being compromised. The raids follow investigations into Worldcoin in other jurisdictions.

Company involved
Worldcoin

5 source articles · read the reporting →

WF-KBL3YD15 Oct 2019

Hive Box Facial-Recognition Lockers Hacked by Children Using Photos

Fourth-grade students in Jiaxing, China, demonstrated that Hive Box's facial-recognition smart lockers could be opened with a printed photo. The company, which operates a large network of delivery lockers, acknowledged the flaw and suspended the beta feature. The incident raised concerns about the security of facial recognition technology.

Company involved
Hive Box

1 source article · read the reporting →

WF-FB12K71 Jan 2016

Lahore safe city project stalls as facial recognition cameras fail

The Lahore safe city project in Punjab, Pakistan, has faced major challenges since 2016, with nearly 1,000 facial recognition cameras out of order. The Punjab Safe Cities Authority (PSCA) blames the contractor for failing to meet contractual clauses. Alternative measures, including reliance on privately-installed cameras, have been taken.

Company involved
Punjab Safe Cities Authority
AI system involved
Lahore safe city project

10 source articles · read the reporting →

Evolv weapon detection system falsely flags Chromebooks as weapons

Evolv's AI-based weapon detection system has been reported to falsely identify certain Chromebook laptops as weapons, causing false alarms at security checkpoints. The system is used in venues such as schools. The article discusses the flaw and user experiences. No official response from Evolv has been mentioned.

Company involved
Evolv
AI system involved
Evolv

5 source articles · read the reporting →

Manchester Arena's Evolv weapon scanners fail to detect some knives, report finds

ASM Global's use of Evolv Express AI weapon scanners at Manchester Arena has been questioned after a private report found the system failed to detect large knives in 42% of walkthroughs. The report, produced by NCS4 and obtained by IPVM, also suggested the scanners may miss some bombs and components. Evolv did not dispute the findings but said it communicates capabilities and limitations to customers. ASM Global declined to comment on security matters.

Company involved
ASM Global
AI system involved
Evolv Express

5 source articles · read the reporting →

WF-4N6UFD1 Mar 2021

Baltimore schools monitor student laptops for suicide signs using GoGuardian Beacon

Baltimore City Public Schools uses GoGuardian Beacon software to monitor student laptops for signs of suicide. Since March 2021, the system has flagged 786 alerts, with nine students taken to emergency rooms. Privacy advocates warn the monitoring could lead to disciplinary actions, outing of LGBTQ students, and disproportionately affect disadvantaged students. School officials defend the practice as a safeguard.

Company involved
Baltimore City Public Schools
AI system involved
GoGuardian Beacon

10 source articles · read the reporting →

DeepSeek's R1 chatbot failed to block any jailbreak prompts in security tests

Security researchers from Cisco and the University of Pennsylvania tested 50 well-known jailbreak prompts against DeepSeek's R1 reasoning model. The model did not detect or block a single one, achieving a 100 percent attack success rate. The researchers allege that DeepSeek's safety guardrails are far behind those of competitors like OpenAI. DeepSeek did not respond to requests for comment.

Company involved
DeepSeek
AI system involved
DeepSeek R1

3 source articles · read the reporting →

WF-8UTONQ22 Dec 2019

Delhi Police use facial recognition to screen PM Modi rally attendees

Delhi Police used an Automated Facial Recognition System (AFRS) to screen crowds at Prime Minister Narendra Modi's rally on December 22, 2019. The system, originally installed to find missing children, was used to identify possible disruptions. Privacy advocates called the move illegal and unconstitutional, saying it amounts to mass surveillance. Police defended the use, citing credible intelligence about possible disruptions.

Company involved
Delhi Police
AI system involved
Automated Facial Recognition System (AFRS)

6 source articles · read the reporting →

WF-2PVWQU31 May 2026

CBSE OnMark portal vulnerability exposed student data to Google Gemini

A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.

Company involved
Central Board of Secondary Education (CBSE)
AI system involved
OnMark

1 source article · read the reporting →

← Newerpage 3 of 5Older →