ООО «Точка опоры» v. ООО «ЦСС» (West Siberian District AC): AI-hallucinated content in court filing, Monetary Fine
The AI system generated fake legal citations that were submitted to the court, resulting in a fine for contempt.
- Company involved
- ООО «ЦСС»
1 source article · read the reporting →
DevTernity conference cancelled after fake women speakers exposed
The DevTernity software developer conference was cancelled after allegations that organiser Eduards Sizovs added fake women speakers to the lineup. Sizovs admitted at least one profile, 'Anna Boyko', was an auto-generated 'demo persona' that appeared on the site by mistake. The conference was scheduled to begin December 7 but was called off after several speakers withdrew. Sizovs denied wrongdoing and said he had fixed the code and written a test to prevent a recurrence.
- Company involved
- DevTernity
9 source articles · read the reporting →
Met Police accessed PimEyes facial recognition site 2,000 times
The Metropolitan Police accessed the controversial facial recognition search engine PimEyes over 2,000 times from its computers in the first three months of 2024. The force stated that the hits did not necessarily mean searches were conducted, but after being alerted by i and Liberty Investigates, it blocked access to the site and strengthened safeguards. Privacy campaigners and MPs have raised concerns that the unregulated tool could be used for stalking and surveillance.
- Company involved
- Metropolitan Police Service
- AI system involved
- PimEyes
3 source articles · read the reporting →
Serco Leisure issued enforcement notices for unlawful biometric monitoring of employees
Serco Leisure and associated trusts used facial recognition and fingerprint scanning to monitor employee attendance at 38 leisure facilities. The ICO found they unlawfully processed biometric data of over 2,000 employees. Enforcement notices were issued ordering them to stop.
- Company involved
- Serco Leisure Operating Limited
8 source articles · read the reporting →
Teething problems in Mater Dei's medicine robots addressed
The Malta Union for Midwives and Nurses claimed that a €23 million investment in two computerised drug administration robots, Mario and Sophia, at Mater Dei Hospital had resulted in a complete failure. However, sources within the Health Ministry said that most teething problems have been addressed and that the supplier has not been paid yet. They reported that out of over 1,700 medication rounds, only four required a contingency plan.
- Company involved
- Mater Dei Hospital
- AI system involved
- Mario and Sophia
6 source articles · read the reporting →
Hong Kong privacy watchdog raids Worldcoin offices over iris scan data collection
Hong Kong's privacy commissioner's office raided six premises linked to Worldcoin, a cryptocurrency company that requires an eye scan from clients for identification. The watchdog is investigating whether the collection of iris scans could lead to sensitive information being compromised. The raids follow investigations into Worldcoin in other jurisdictions.
- Company involved
- Worldcoin
5 source articles · read the reporting →
AEMPS withdraws AI medicines tool MeQA after detecting errors
AEMPS launched MeQA, an artificial intelligence tool for answering public questions about medicines, on 13 May 2025. Two days later it withdrew the tool after detecting that some responses contained errors. The agency said that most answers were correct but that the errors could affect patient safety, and that it would restore the service as soon as possible.
- Company involved
- Agencia Española de Medicamentos y Productos Sanitarios (AEMPS)
- AI system involved
- MeQA
4 source articles · read the reporting →
CJEU rules Dun & Bradstreet must explain automated credit decisions under GDPR
A customer was refused a mobile phone contract because of an automated credit assessment by Dun & Bradstreet Austria. The customer took the case to court, which found that Dun & Bradstreet had infringed the GDPR by failing to provide meaningful information about the logic involved. The CJEU ruled that data controllers must explain automated decisions and that trade secrets cannot automatically override the right of access.
- Company involved
- Dun & Bradstreet Austria GmbH
7 source articles · read the reporting →
Hacker tricks Freysa AI chatbot into transferring $47,000 prize pool
A hacker using the alias 'p0pular.eth' successfully manipulated the Freysa AI chatbot through a prompt injection attack, tricking it into transferring its entire balance of 13.19 ETH (approximately $47,000) from a prize pool. The chatbot was designed to never transfer money, but the hacker crafted a message that redefined the 'approveTransfer' function and announced a fake $100 deposit, causing the bot to release the funds. The incident occurred during a pay-to-play contest where participants paid escalating fees to attempt the hack, with the winner receiving the prize pool.
- Company involved
- Freysa.ai
- AI system involved
- Freysa
4 source articles · read the reporting →
Parking Enforcement Services wrongly fines parents due to faulty licence plate cameras
Dozens of parents at a Christchurch childcare centre were wrongly issued $85 parking fines by Parking Enforcement Services after its licence plate recognition cameras failed to accurately capture multiple short visits. The company acknowledged some misreads and waived fines on appeal, but parents described the process as stressful and time-consuming. An additional camera was installed to improve accuracy.
- Company involved
- Parking Enforcement Services
1 source article · read the reporting →
Chelmer Valley High School reprimanded for facial recognition DPIA failure
Chelmer Valley High School was issued a reprimand by the ICO for failing to complete a Data Protection Impact Assessment before introducing facial recognition technology for cashless catering. The reprimand was issued on 22 July 2024.
- Company involved
- Chelmer Valley High School
7 source articles · read the reporting →
DWP algorithm approved Kickstart gateways with no trading history or based abroad
An FE Week investigation found that the Department for Work and Pensions (DWP) approved dozens of companies as Kickstart gateways through automated due diligence checks using the Cabinet Office Spotlight Tool, although some had little or no trading history or were based abroad. The DWP said gateways were subject to stringent checks and later said human checks were also used. After the findings were shared with the Treasury and the DWP, the department stopped taking gateway applications and scrapped the requirement for small employers to use gateways from 3 February.
- Company involved
- Department for Work and Pensions
- AI system involved
- Cabinet Office Spotlight Tool
3 source articles · read the reporting →
Paper Werewolf uses AI-generated decoys and XLLs to target Russian organizations
The threat group Paper Werewolf (aka GOFFEE) is conducting a cyberespionage campaign targeting Russian defense and high-technology organizations. The campaign uses AI-generated decoy documents, such as invitations and official letters, to trick recipients into opening malicious Excel XLL add-ins that deliver a backdoor called EchoGather. The backdoor collects system information and communicates with a command-and-control server. The campaign is ongoing and was first detected in late October 2025.
- Company involved
- Paper Werewolf
- AI system involved
- EchoGather
2 source articles · read the reporting →
MAA, JBG to pay DC $9.3M total to settle RealPage case - Multifamily Dive
The system set rent prices for tenants, causing them to pay higher rents.
- Company involved
- MAA (Mid-America Apartments) and JBG Smith
- AI system involved
- RealPage Revenue Management Software
1 source article · read the reporting →
Greek Data Protection Authority fines Ministry of Migration and Asylum for AI surveillance systems
The Hellenic Data Protection Authority (HDPA) imposed an administrative fine of €175,000 on the Ministry of Migration and Asylum (MMA) for GDPR violations related to the 'Centaur' and 'Hyperion' programmes. These systems use AI behavioral analytics, CCTV, drones, and biometric data to monitor and control access to reception facilities for asylum seekers on Greek islands. The HDPA found that the MMA failed to conduct proper Data Protection Impact Assessments and did not cooperate with the authority. The MMA has been ordered to comply with GDPR within three months.
- Company involved
- Ministry of Migration and Asylum
- AI system involved
- Centaur and Hyperion programmes
10 source articles · read the reporting →
Kmart's facial recognition system for refund fraud found unlawful by Privacy Commissioner
Kmart Australia deployed facial recognition technology in 28 stores from June 2020 to July 2022, capturing biometric data of every customer entering the stores and those at returns counters to detect refund fraud. The system collected sensitive information without notifying customers or obtaining their consent. The Australian Privacy Commissioner found that Kmart breached the Privacy Act, as the exemption for unlawful activity did not justify the indiscriminate and disproportionate collection of biometric data from thousands of individuals. Kmart has ceased using the system and cooperated with the investigation.
- Company involved
- Kmart Australia Limited
7 source articles · read the reporting →
Deepfake scam articles impersonate Maltese ministers after budget day
After Malta's budget day on 27 October 2025, a series of scam articles featuring deepfake videos of ministers, including Economy Minister Silvio Schembri, appeared on social media. The articles, falsely branded as Times of Malta, promoted a fraudulent AI-powered trading platform called NethertoxAGENT, claiming a €215 investment would yield €850 weekly. The scam used fake testimonials and logos of reputable businesses to appear credible. Authorities have not reported any arrests for this specific scam, but a similar deepfake scam previously led to a woman losing her life savings and a money laundering charge against a Ukrainian national.
3 source articles · read the reporting →
Meta fails to block hate speech ads in Kenya test
Global Witness and Foxglove submitted test ads containing violent hate speech in English and Swahili to Facebook. The ads were approved for publication, demonstrating that Meta's content moderation systems failed to detect the hate speech. The groups had previously conducted similar tests in Myanmar and Ethiopia with the same result. Meta did not respond to the groups' outreach.
- Company involved
- Meta
- AI system involved
- Facebook's content moderation system
2 source articles · read the reporting →
US Secret Service bought access to cellphone location data
The US Secret Service signed a contract to access Locate X, a service that aggregates location data from phone apps and allows law enforcement to track devices without a warrant. The contract with Babel Street was worth about $36,000 and ran from 2017 to 2018. A former employee said the Secret Service used Locate X in 2018 to seize illegal credit card skimmers at petrol stations. Lawmakers and civil liberties advocates criticised the practice, and Senator Ron Wyden introduced a bill to ban such purchases.
- Company involved
- United States Secret Service
- AI system involved
- Locate X
1 source article · read the reporting →
Warner Bros. Sues Midjourney for Copyright Infringement
Warner Bros. has filed a lawsuit against Midjourney, alleging that the AI image generation platform willfully creates infringing images and videos of its copyrighted characters, including Superman, Batman, and Bugs Bunny. The lawsuit claims that Midjourney removed guardrails that blocked users from creating infringing videos. The suit seeks statutory damages and an injunction to stop the infringement.
- Company involved
- Midjourney
- AI system involved
- Midjourney
5 source articles · read the reporting →
Steak 'n Shake sued over facial recognition kiosks under BIPA
A class action lawsuit alleges that Steak 'n Shake illegally collects facial biometrics from customers using PopID-powered self-ordering kiosks without proper consent. Plaintiff Michael Massel claims the restaurant chain failed to provide notice and obtain written consent as required by Illinois' Biometric Information Privacy Act (BIPA). The suit seeks damages of up to $5,000 per violation for anyone whose biometric data was collected in Illinois in the past five years.
- Company involved
- Steak 'n Shake
- AI system involved
- PopID biometric kiosks
6 source articles · read the reporting →
Mumsnet takes legal action against OpenAI for scraping content
Mumsnet, a UK parenting forum, has initiated legal action against OpenAI for scraping its content without permission. The company alleges that OpenAI used over six billion words from Mumsnet to train its ChatGPT model, breaching its terms of use. Mumsnet approached OpenAI to license the content but was refused. The case is ongoing.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
6 source articles · read the reporting →
Moonwell loses $1.78M after AI-generated code from Claude Opus 4.6 causes oracle pricing error
DeFi lending protocol Moonwell lost $1.78 million after an oracle pricing error in smart contract code partially written by Anthropic's Claude Opus 4.6 model. The error valued cbETH at approximately $1.12 per token instead of its actual market price of nearly $2,200, triggering instant liquidations. Moonwell contained the issue by reducing the cbETH borrow cap, but users suffered catastrophic losses. The incident has sparked debate about the risks of AI-generated code in smart contracts.
- Company involved
- Moonwell
- AI system involved
- Claude Opus 4.6
4 source articles · read the reporting →
Italian bank (Fideuram / Intesa Sanpaolo) loses about 95 million euro to AI voice-clone scam
The AI-generated voice deceived the chairman into authorizing transfers of about 95 million euros.
1 source article · read the reporting →