Intellexa Predator spyware used to surveil human rights lawyer in Pakistan
In summer 2025, a human rights lawyer from Pakistan's Balochistan province was targeted via WhatsApp with Intellexa's Predator spyware, according to Amnesty International's Security Lab. The attack is part of a broader pattern of unlawful surveillance of activists, journalists and human rights defenders. The Intellexa Leaks investigation exposed internal operations of the spyware company, raising concerns about human rights due diligence.
- AI system involved
- Predator spyware
10 source articles · read the reporting →
LAPD told officers to collect social media data on every civilian stopped
The Los Angeles Police Department directed officers to record the social media accounts of every civilian they interviewed, including those not arrested or accused of a crime, according to records obtained by the Brennan Center for Justice. The field interview cards, which also ask for social security numbers, have raised civil liberties concerns. Prosecutors have accused three officers of using the cards to falsely label civilians as gang members. The LAPD said the policy was being updated but did not respond to questions about its use of social media monitoring tools including Media Sonar and Geofeedia.
- Company involved
- Los Angeles Police Department (LAPD)
- AI system involved
- Field interview cards, Media Sonar, Geofeedia
10 source articles · read the reporting →
FTC settles with IntelliVision over deceptive facial recognition claims
The Federal Trade Commission (FTC) took action against IntelliVision Technologies Corp. for making false, misleading, or unsubstantiated claims about its AI-powered facial recognition software. The company allegedly claimed its software had one of the highest accuracy rates on the market and was free of gender or racial bias, without supporting evidence. The FTC also alleged that IntelliVision did not train its software on millions of faces as claimed, but on images of approximately 100,000 individuals. Under a proposed consent order, IntelliVision is prohibited from making such misrepresentations without competent and reliable testing.
- Company involved
- IntelliVision Technologies Corp.
- AI system involved
- IntelliVision facial recognition software
9 source articles · read the reporting →
New Jersey court rules police must disclose facial recognition algorithms used to identify defendant
Francisco Arteaga was charged with armed robbery after a facial recognition search by the New York Police Department identified him as a possible match. The New Jersey police used this match to obtain witness identifications. Arteaga requested information about the facial recognition software, including its source code and error rate, but the trial court denied his request. The New Jersey appellate court ruled that the prosecution must disclose the algorithms, citing due process and the Brady rule.
- Company involved
- New Jersey Police
7 source articles · read the reporting →
St. Louis police arrest man after facial recognition match without corroboration
Christopher Gatlin was arrested and jailed for an assault on a security guard after police used facial recognition software to identify him from a blurry surveillance image. The lead detective built a case against Gatlin despite the city's policy that AI results are nonscientific and should not be the sole basis for a decision. A witness was steered by officers to select Gatlin from a photo lineup, and the case was later dismissed after more than two years. Gatlin alleges wrongful arrest and has filed a lawsuit.
- Company involved
- St. Louis County Police Department
- AI system involved
- Unnamed facial recognition program
4 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
Bavarian police test Palantir data mining with real personal data
The Bavarian State Criminal Police Office (LKA) has been testing Palantir's data mining software, called VeRa, with real personal data for months. The Bavarian data protection commissioner only learned of the test through a media inquiry and has announced a review. The Interior Ministry claims the test is lawful under current law, but critics argue a legal basis is missing.
- Company involved
- Bayerisches Landeskriminalamt
- AI system involved
- VeRa
7 source articles · read the reporting →
PimEyes scraped Ancestry.com for photos of dead people without permission.
PimEyes, a facial recognition search engine, scraped images from Ancestry.com and other websites without authorization, including photos of deceased individuals. The company's algorithms indexed the images to create biometric faceprints, potentially allowing identification of living relatives. Cher Scarlett discovered the scraping after finding photos of her deceased sister on the platform. PimEyes has since blocked Ancestry's domain and is removing the indexes, but privacy concerns remain.
- Company involved
- PimEyes
- AI system involved
- PimEyes
7 source articles · read the reporting →
Met Police accessed PimEyes facial recognition site 2,000 times
The Metropolitan Police accessed the controversial facial recognition search engine PimEyes over 2,000 times from its computers in the first three months of 2024. The force stated that the hits did not necessarily mean searches were conducted, but after being alerted by i and Liberty Investigates, it blocked access to the site and strengthened safeguards. Privacy campaigners and MPs have raised concerns that the unregulated tool could be used for stalking and surveillance.
- Company involved
- Metropolitan Police Service
- AI system involved
- PimEyes
3 source articles · read the reporting →
PimEyes faces fine proceedings over biometric facial recognition in Baden-Württemberg
PimEyes, a facial recognition search engine, is accused of scraping images from the internet and processing biometric data without a valid legal basis under the GDPR. The data protection authority of Baden-Württemberg (LfDI) opened fine proceedings after it found PimEyes's response to its questions inadequate. PimEyes argues that the images it processes are publicly available and not personal data. The LfDI says the processing endangers citizens' rights and freedoms and is not covered by the GDPR exceptions.
- Company involved
- PimEyes
- AI system involved
- PimEyes
9 source articles · read the reporting →
Audit of RisCanvi finds biases and reliability issues in criminal justice system
Eticas conducted an adversarial audit of RisCanvi, an AI risk assessment tool used in Catalonia's criminal justice system. The audit uncovered biases in risk classifications against specific demographics and significant reliability issues. The findings call for fairer practices in criminal justice AI.
- Company involved
- Catalonia's criminal justice system
- AI system involved
- RisCanvi
4 source articles · read the reporting →
Microsoft Bing Copilot falsely accuses German journalist of crimes
Martin Bernklau, a German court reporter, asked Microsoft's Bing Copilot about himself and found that the AI chatbot had falsely accused him of crimes he had covered. The false information persisted despite Microsoft's promises to delete it. Bernklau's lawyer sent a cease-and-desist demand, and the case has been reported to data protection authorities. The incident highlights the problem of AI hallucinations and defamation.
- Company involved
- Microsoft
- AI system involved
- Bing Copilot
8 source articles · read the reporting →
Buenos Aires city government uses live facial recognition to track minors in criminal database
The Buenos Aires city government deployed a live facial recognition system in April 2019 that scans subway passengers and matches them against CONARC, a national database of alleged offenders. Human Rights Watch found that the database includes at least 166 children, some as young as one to three years old, and that the system has led to numerous false arrests. The system was implemented without public consultation, and there is no mechanism to correct mistakes. A civil rights organization filed a lawsuit, and the government is pushing a bill to legalize the technology.
- Company involved
- Buenos Aires city government
1 source article · read the reporting →
TransUnion AI tenant screening denied 75-year-old man apartment due to mistaken littering conviction
Chris Robinson, then 75, applied for a senior living apartment in California. The property manager used an AI screening program from TransUnion, which assigned him a low score based on a mistaken conviction for littering that belonged to a different person with the same name in Texas. Robinson lost the apartment and his application fee. A federal class-action lawsuit against TransUnion moved toward a $11.5 million settlement in 2023.
10 source articles · read the reporting →
Palantir secretly tested predictive policing in New Orleans
Beginning in 2012, Palantir Technologies secretly partnered with the New Orleans Police Department to deploy a predictive policing system. The programme analysed gang affiliations, social media and criminal histories to forecast individuals’ likelihood of committing or becoming victims of violence, operating without public knowledge or city council oversight. Researchers and law enforcement officials raised concerns about systemic bias and civil liberties. As of 2018, the city and Palantir had not disclosed the programme’s status.
- Company involved
- New Orleans Police Department
1 source article · read the reporting →
Pasco Sheriff's Office used algorithm to target potential future criminals and schoolchildren
The Pasco Sheriff's Office operates an intelligence-led policing programme that uses an algorithm to identify people who might break the law based on criminal histories and social networks. Deputies are sent to the homes of those flagged, even without evidence of a crime, and former deputies allege they were ordered to make targets' lives miserable. The agency also keeps a list of more than 400 schoolchildren predicted to 'fall into a life of crime', built from data such as grades and child welfare records, without informing the children or their parents. Civil liberties groups are considering lawsuits and public advocacy campaigns, and experts have called the programmes 'morally repugnant'.
- Company involved
- Pasco Sheriff's Office
10 source articles · read the reporting →
FBI and ICE use state driver's license photos for facial recognition without consent
The FBI and ICE have been scanning millions of Americans' driver's license photos using facial recognition technology without their knowledge or consent, according to newly released documents. The agencies accessed state DMV databases, turning them into a facial-recognition gold mine. This practice raises significant privacy concerns as it was done without public awareness or legal oversight.
- Company involved
- FBI and ICE
1 source article · read the reporting →
Clearview AI facial recognition app scrapes billions of images and is used by police
Clearview AI, a secretive start-up, built a facial recognition app that matches photos to a database of more than three billion images scraped from social media and websites. More than 600 law enforcement agencies, including the FBI and Department of Homeland Security, have used the tool to identify suspects in crimes such as shoplifting, identity theft and murder. The company monitored officers who ran a reporter's photo through the app, and its founder acknowledged designing an augmented-reality prototype but said there were no plans to release it. Critics warned the tool could end anonymity and enable misuse.
- Company involved
- Clearview AI
- AI system involved
- Clearview AI facial recognition app
2 source articles · read the reporting →
US Secret Service bought access to cellphone location data
The US Secret Service signed a contract to access Locate X, a service that aggregates location data from phone apps and allows law enforcement to track devices without a warrant. The contract with Babel Street was worth about $36,000 and ran from 2017 to 2018. A former employee said the Secret Service used Locate X in 2018 to seize illegal credit card skimmers at petrol stations. Lawmakers and civil liberties advocates criticised the practice, and Senator Ron Wyden introduced a bill to ban such purchases.
- Company involved
- United States Secret Service
- AI system involved
- Locate X
1 source article · read the reporting →
San Francisco Police Wrongfully Stop Woman at Gunpoint After License Plate Reader Error
On March 30, 2009, Denise Green, a 47-year-old African-American woman, was driving in San Francisco when an automatic license plate reader misread her plate as stolen. Despite discrepancies between the vehicle description and the stolen plate, officers conducted a felony stop, ordering her out at gunpoint and handcuffing her for nearly 20 minutes. Green filed a civil rights lawsuit alleging Fourth Amendment violations. The Ninth Circuit Court of Appeals reinstated her case, finding that the officers lacked reasonable suspicion for the stop.
- Company involved
- San Francisco Police Department
1 source article · read the reporting →
Las Vegas police used unsuitable facial recognition images in nearly half of searches
The Las Vegas Metropolitan Police Department (LVMPD) used 'non-suitable' probe images in 451 of 924 facial recognition searches in 2019, greatly increasing the risk of false identifications. The system, supplied by Vigilant Solutions, returned likely matches in only 18% of those searches, yet led to arrests in at least 73 cases. Critics and researchers warn this practice heightens the chance of wrongful arrests, and one defence attorney said he was never informed facial recognition was used to identify his client.
- Company involved
- Las Vegas Metropolitan Police Department
- AI system involved
- Vigilant Solutions facial recognition system
1 source article · read the reporting →
California AG declares out-of-state ALPR data sharing unlawful
California Attorney General Rob Bonta issued guidance confirming that sharing automated license plate reader (ALPR) data with out-of-state or federal agencies violates state law SB 34. The decision follows years of advocacy by EFF and the ACLU, who demonstrated through public records that many California law enforcement agencies were sharing data with hundreds of external agencies, including ICE and CBP. The guidance mandates that all California agencies review their data sharing and cut off access to out-of-state and federal entities.
- Company involved
- California law enforcement agencies
- AI system involved
- Automated license plate readers (ALPRs)
1 source article · read the reporting →
NYPD Used Facial Recognition to Target Black Lives Matter Activist Derrick Ingram
The NYPD used facial recognition technology to identify Derrick Ingram, a 28-year-old Black Lives Matter activist, leading to a raid on his Hell's Kitchen apartment by over 50 officers on 7 August 2020. The NYPD's Facial Identification Section generated a lead from a photo taken from Ingram's Instagram page, despite the department's policy of using only surveillance video or arrest photos. Ingram's attorney alleges the five-hour siege was an intimidation campaign that interfered with his constitutional rights. The NYPD acknowledged using facial recognition as a limited investigative tool.
- Company involved
- NYPD
- AI system involved
- Facial Identification Section
3 source articles · read the reporting →
Clearview AI settles with ACLU over facial recognition database sales
Clearview AI has agreed to stop selling its facial recognition database to most private US companies as part of a proposed settlement with the ACLU. The company scraped billions of images from social media without consent to build its database, violating Illinois' Biometric Information Privacy Act. The settlement requires Clearview to delete old facial vectors and allow Illinois residents to opt out. The company can still sell its technology to law enforcement and government agencies.
- Company involved
- Clearview AI
- AI system involved
- Clearview AI facial recognition database
8 source articles · read the reporting →