Zhengzhou officials punished for red health codes on depositors
Five officials in Zhengzhou were punished for ordering red health codes to be assigned to 1,317 depositors of four village banks, restricting their movement and preventing them from withdrawing savings. The officials acted without authorization, and the codes were later turned green after media coverage. Legal experts say the liability for privacy invasion remains unresolved, and the banks may face breach of contract claims.
- Company involved
- Zhengzhou municipal government
- AI system involved
- Health code system
10 source articles · read the reporting →
WorldCoin suspended in Kenya over data security concerns
WorldCoin, a digital identification protocol using iris scans, was suspended by Kenyan regulators (ODPC and Communications Authority) over concerns about data security, consent, and oversight. The system had issued digital IDs and cryptocurrency tokens to over 350,000 Kenyans. Reports of hacked orb operators and iris scans traded on the dark web have also emerged.
- Company involved
- Tools for Humanity GmbH
- AI system involved
- WorldCoin
10 source articles · read the reporting →
California DMV suspends Cruise LLC driverless and deployment permits
The California Department of Motor Vehicles suspended Cruise LLC's autonomous vehicle deployment and driverless testing permits, saying the vehicles were not safe for public operation and that Cruise had misrepresented safety information. The suspension took effect immediately under California regulations. Cruise may apply to reinstate the permits once it satisfies the department's requirements. Its permit for testing with a safety driver was not affected.
- Company involved
- Cruise LLC
10 source articles · read the reporting →
IRCC uses AI triage for Temporary Resident Visa applications
Immigration, Refugees and Citizenship Canada (IRCC) uses an AI system called Advanced Analytics to triage Temporary Resident Visa applications from India and China. The system categorizes applications into tiers, with Tier 1 approved automatically and others sent to human officers. Critics allege the system lacks transparency and may introduce bias, leading to visa refusals without clear rationale. The author, a Canadian immigration lawyer, is filing Federal Court cases on behalf of clients affected by refusals.
- Company involved
- Immigration, Refugees and Citizenship Canada (IRCC)
- AI system involved
- Advanced Analytics Triage of Overseas Temporary Resident Visa Applications
10 source articles · read the reporting →
US CBP deploys CBP One app using facial recognition for asylum seekers amid privacy concerns
The article reports that U.S. Customs and Border Protection quietly deployed the CBP One mobile app at the Mexico border. The app uses facial recognition and geolocation to collect and verify information on asylum seekers before they enter the United States. Privacy experts warn that the app poses risks of persistent surveillance and that the facial recognition algorithm is unreliable for people of colour. A previous CBP facial recognition pilot was hacked, exposing images. CBP says the app is voluntary and data is secure.
- Company involved
- U.S. Customs and Border Protection
- AI system involved
- CBP One
8 source articles · read the reporting →
California EDD's automated fraud detection wrongly suspended 600,000 legitimate unemployment claims
In January 2021, the California Employment Development Department used Thompson Reuters automated batch review software to flag 1.1 million unemployment claims as potentially fraudulent. EDD stopped payments on those claims without prior notice. Later, over 600,000 were confirmed as legitimate after claimants used ID.me to verify their identity. The incident highlights the trade-off between fraud prevention and timely benefit access.
- Company involved
- California Employment Development Department (EDD)
- AI system involved
- Thompson Reuters Automated Batch Review
7 source articles · read the reporting →
N-Tech.lab's FindFace used to identify St Petersburg metro passengers without consent
Egor Tsvetkov photographed passengers on the St Petersburg metro without their permission and used N-Tech.lab's facial recognition service FindFace to match their faces to public Vkontakte profiles. He published the results in an art project called 'Your Face is Big Data', saying he wanted to show how 'digital narcissism' can lead to stalking. Privacy advocates said the project was ethically problematic because the subjects had not consented and their identities were exposed. FindFace had been launched by N-Tech.lab in February 2016.
- Company involved
- N-Tech.lab
- AI system involved
- FindFace
8 source articles · read the reporting →
OnlyFake site uses neural networks to generate fake IDs, bypasses OKX verification
An underground website called OnlyFake uses neural networks to generate realistic photos of fake IDs for $15. The journalist tested the service and obtained a convincing California driver's license. They then used another fake ID to successfully bypass the identity verification process on OKX, a cryptocurrency exchange. The article alleges that this technology could streamline bank fraud and money laundering, but reports no actual financial loss.
- Company involved
- OKX
- AI system involved
- OnlyFake
10 source articles · read the reporting →
Worldcoin collected biometric data from poor villagers in Indonesia without informed consent
Worldcoin, a cryptocurrency startup, recruited users in developing countries by offering free cash in exchange for iris scans. The company used deceptive marketing, collected more personal data than acknowledged, and failed to obtain meaningful informed consent. Many users received worthless tokens instead of promised money. The company acknowledged some friction but continued its operations.
- Company involved
- Worldcoin
- AI system involved
- chrome orb
5 source articles · read the reporting →
Northeast Ohio man scammed out of $20,000 by deepfake Elton John video
A 71-year-old man in Northeast Ohio was scammed out of $20,000 after watching a deepfake video of Elton John on Instagram that falsely promised easy money through an online store. He was guided by two individuals posing as company representatives to open bank accounts and credit cards, which they then used to charge his cards. The victim, who was working part-time and seeking extra income, is now in debt and has returned to full-time work. One credit card company has credited $9,400, and he is working to recover the remaining funds.
1 source article · read the reporting →
CJEU rules Dun & Bradstreet must explain automated credit decisions under GDPR
A customer was refused a mobile phone contract because of an automated credit assessment by Dun & Bradstreet Austria. The customer took the case to court, which found that Dun & Bradstreet had infringed the GDPR by failing to provide meaningful information about the logic involved. The CJEU ruled that data controllers must explain automated decisions and that trade secrets cannot automatically override the right of access.
- Company involved
- Dun & Bradstreet Austria GmbH
7 source articles · read the reporting →
Woman denied state welfare card groceries after face scan fails
A grandmother rode her motorcycle several kilometres to a shop in Sapphaya district, Chai Nat province, to use her state welfare card to buy groceries for her family. After selecting items, she failed repeated facial recognition scans because her ID card photo was years old and no longer matched her appearance. She left the shop empty-handed and in tears.
- Company involved
- Government of Thailand (state welfare card system)
2 source articles · read the reporting →
Parking Enforcement Services wrongly fines parents due to faulty licence plate cameras
Dozens of parents at a Christchurch childcare centre were wrongly issued $85 parking fines by Parking Enforcement Services after its licence plate recognition cameras failed to accurately capture multiple short visits. The company acknowledged some misreads and waived fines on appeal, but parents described the process as stressful and time-consuming. An additional camera was installed to improve accuracy.
- Company involved
- Parking Enforcement Services
1 source article · read the reporting →
DWP algorithm approved Kickstart gateways with no trading history or based abroad
An FE Week investigation found that the Department for Work and Pensions (DWP) approved dozens of companies as Kickstart gateways through automated due diligence checks using the Cabinet Office Spotlight Tool, although some had little or no trading history or were based abroad. The DWP said gateways were subject to stringent checks and later said human checks were also used. After the findings were shared with the Treasury and the DWP, the department stopped taking gateway applications and scrapped the requirement for small employers to use gateways from 3 February.
- Company involved
- Department for Work and Pensions
- AI system involved
- Cabinet Office Spotlight Tool
3 source articles · read the reporting →
CBSE OnMark portal vulnerability exposed student data to Google Gemini
A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.
- Company involved
- Central Board of Secondary Education (CBSE)
- AI system involved
- OnMark
1 source article · read the reporting →
CBP One app strands migrants in Mexico, aids organised crime, says HRW
The US Customs and Border Protection's CBP One app, which is mandatory for asylum seekers, offers only 1,450 appointments per day while border arrivals average 7,240. Human Rights Watch reports that this digital metering leaves migrants stranded in Mexico, vulnerable to kidnapping and extortion by organised crime groups. The report alleges that the app enriches criminal cartels and that exceptions for imminent threats are often ignored.
- Company involved
- US Customs and Border Protection
- AI system involved
- CBP One
10 source articles · read the reporting →
Outabox hack exposes biometric data of patrons at bars, clubs and casinos
Hackers claiming to be former employees published a website allowing searches of Outabox's facial recognition database, exposing biometric and other sensitive data of patrons used for age verification at bars, clubs and casinos. The Surveillance Technology Oversight Project warns that the breach demonstrates the danger of facial recognition for age verification. S.T.O.P. has launched a campaign to ban facial recognition in public accommodations.
- Company involved
- Outabox
8 source articles · read the reporting →
ChatGPT 4o image generator used to create fake receipts
ChatGPT's new image generator, part of the 4o model, can generate realistic fake restaurant receipts. Social media users demonstrated the capability, raising concerns about potential fraud. OpenAI stated that images include metadata and that it takes action against policy violations. The company defended the feature as allowing creative freedom.
- Company involved
- OpenAI
- AI system involved
- ChatGPT 4o image generator
5 source articles · read the reporting →
Tencent launches Zero-Point Cruise facial recognition to enforce night-time game curfew
Tencent has introduced a feature called Zero-Point Cruise in its games, which subjects accounts registered as adults that play at night beyond a set time to facial recognition. Anyone who refuses or fails the verification is treated as a minor and logged out. Tencent says this is intended to stop children using adult identities to evade the game curfew, and that adults who mistakenly refuse can wait for the next authentication.
- Company involved
- Tencent
- AI system involved
- 零点巡航 (Zero-Point Cruise)
10 source articles · read the reporting →
Citizens Advice finds ethnicity penalty in car insurance pricing
Citizens Advice conducted exploratory research into car insurance pricing and found that people of colour may be paying £250 more per year than White people. The research suggests that areas with large communities of colour may be identified as more risky by algorithms, even when objective risk factors are controlled. Citizens Advice has called on the Financial Conduct Authority to investigate the issue.
9 source articles · read the reporting →
Ukrainian Hacker Pleads Guilty to Operating OnlyFake AI ID Scam Site
Yurii Nazarenko, a Ukrainian national, pleaded guilty to running OnlyFake, an AI-powered website that generated and sold over 10,000 counterfeit identification documents globally. The site allowed users to create realistic fake IDs, including driver's licenses and passports, to bypass identity verification at banks and cryptocurrency exchanges. Nazarenko faces up to 15 years in prison and agreed to forfeit $1.2 million. Sentencing is scheduled for June 2026.
- Company involved
- OnlyFake
- AI system involved
- OnlyFake
3 source articles · read the reporting →
Scammers Use AI to Create Fake Joann Fabrics Websites to Steal Credit Card Data
After Joann Fabrics filed for bankruptcy in January 2025, scammers used AI to create impostor websites mimicking the retailer's site. These fake sites offered deep discounts to trick shoppers into providing credit-card information and personal data. Customers who placed orders never received products and had their payment information compromised. The incident highlights the growing use of AI by cybercriminals to create convincing fake websites.
2 source articles · read the reporting →
Man uses AI face-swap to steal 15,996 yuan from financial accounts, sentenced to 4.5 years
A man in Jiangsu, China, illegally purchased 1.95 million personal records and used AI face-swapping software to bypass facial recognition on financial platforms. He accessed 23 victims' accounts, changed five passwords, and used one account to buy two phones worth 15,996 yuan. He was convicted of infringing citizens' personal information and credit card fraud, sentenced to four years and six months in prison, and ordered to pay damages and delete the data.
3 source articles · read the reporting →
Didi fined for over-collecting personal data of users
The Cyberspace Administration of China fined Didi Global Inc. for violating data protection laws. The investigation found that Didi had over-collected personal data from passengers and drivers, including facial recognition, location, and clipboard information, totaling billions of records. The violations began in 2015 and continued until the investigation in 2021. Didi was ordered to pay a penalty and correct its practices.
- Company involved
- 滴滴全球股份有限公司 (Didi Global Inc.)
- AI system involved
- Didi ride-hailing apps
8 source articles · read the reporting →