Hive Box Facial-Recognition Lockers Hacked by Children Using Photos
Fourth-grade students in Jiaxing, China, demonstrated that Hive Box's facial-recognition smart lockers could be opened with a printed photo. The company, which operates a large network of delivery lockers, acknowledged the flaw and suspended the beta feature. The incident raised concerns about the security of facial recognition technology.
- Company involved
- Hive Box
1 source article · read the reporting →
iBorderCtrl lie detector falsely flagged honest reporter as liar
A journalist testing Europe's iBorderCtrl virtual policeman at the Serbian-Hungarian border gave honest answers but was deemed a liar by the system, scoring 48 out of 100 with four false answers flagged. The Hungarian policeman said the result suggested further checks, though none were carried out. The reporter only learned of the result after filing a data access request under European privacy laws. Experts and transparency activists have criticised the technology as pseudoscientific and potentially discriminatory.
- Company involved
- iBorderCtrl consortium
- AI system involved
- Silent Talker / iBorderCtrl virtual policeman
10 source articles · read the reporting →
AI detectors falsely flag non-native English speakers' essays as AI-generated
A study by Stanford researchers found that seven popular AI text detectors wrongly flagged over half of essays written by non-native English speakers as AI-generated. The detectors assess text perplexity, and non-native speakers' simpler word choices lead to false positives. The researchers warn that this bias could have serious implications for students and job applicants, potentially leading to discrimination.
9 source articles · read the reporting →
CJEU rules Dun & Bradstreet must explain automated credit decisions under GDPR
A customer was refused a mobile phone contract because of an automated credit assessment by Dun & Bradstreet Austria. The customer took the case to court, which found that Dun & Bradstreet had infringed the GDPR by failing to provide meaningful information about the logic involved. The CJEU ruled that data controllers must explain automated decisions and that trade secrets cannot automatically override the right of access.
- Company involved
- Dun & Bradstreet Austria GmbH
7 source articles · read the reporting →
PimEyes faces fine proceedings over biometric facial recognition in Baden-Württemberg
PimEyes, a facial recognition search engine, is accused of scraping images from the internet and processing biometric data without a valid legal basis under the GDPR. The data protection authority of Baden-Württemberg (LfDI) opened fine proceedings after it found PimEyes's response to its questions inadequate. PimEyes argues that the images it processes are publicly available and not personal data. The LfDI says the processing endangers citizens' rights and freedoms and is not covered by the GDPR exceptions.
- Company involved
- PimEyes
- AI system involved
- PimEyes
9 source articles · read the reporting →
Delta uses AI from Fetcherr for domestic ticket pricing
Delta Air Lines is using generative AI from Fetcherr to determine some domestic flight prices, currently covering 3% of its network with plans to reach 20% by end of 2025. Democratic senators expressed concern that the AI could be used for individualized pricing based on personal data, leading to higher fares. Delta denies using personal data in pricing and states it complies with regulations. No actual harm has been reported.
- Company involved
- Delta Air Lines
- AI system involved
- Fetcherr
8 source articles · read the reporting →
DeepSeek's R1 chatbot failed to block any jailbreak prompts in security tests
Security researchers from Cisco and the University of Pennsylvania tested 50 well-known jailbreak prompts against DeepSeek's R1 reasoning model. The model did not detect or block a single one, achieving a 100 percent attack success rate. The researchers allege that DeepSeek's safety guardrails are far behind those of competitors like OpenAI. DeepSeek did not respond to requests for comment.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek R1
3 source articles · read the reporting →
Audit of RisCanvi finds biases and reliability issues in criminal justice system
Eticas conducted an adversarial audit of RisCanvi, an AI risk assessment tool used in Catalonia's criminal justice system. The audit uncovered biases in risk classifications against specific demographics and significant reliability issues. The findings call for fairer practices in criminal justice AI.
- Company involved
- Catalonia's criminal justice system
- AI system involved
- RisCanvi
4 source articles · read the reporting →
Vumacam's AI CCTV system flagged 28 black people as suspicious in Johannesburg suburbs
In Johannesburg suburbs, Vumacam's AI-powered CCTV network using iSentry software flagged 28 black individuals as 'suspicious' in a shift report, according to a 2019 article. The system, deployed by private security firms, uses video analytics to detect abnormal behavior and alerts security guards. The article alleges that the system disproportionately targets people of color, reflecting racial bias in a racially divided country.
- Company involved
- Vumacam
- AI system involved
- iSentry
6 source articles · read the reporting →
Microsoft Dynamics 365 Field Service AI singles out workers in performance predictions
A report by Cracked Labs found that Microsoft's Dynamics 365 Field Service software uses AI to generate performance metrics and predict task durations, singling out individual workers. The AI predictions can be influenced by the worker's identity, such as increasing or decreasing estimated duration. Microsoft stated the system is not intended for employment decisions and is not a surveillance tool, but the report raises concerns about potential misuse for worker monitoring.
- Company involved
- Microsoft
- AI system involved
- Dynamics 365 Field Service
6 source articles · read the reporting →
UK universities detect deepfake applicants in automated interviews
Some UK universities use Enroly's automated online interviews to screen international student applicants. Enroly detected about 30 cases of deepfake attempts out of 20,000 interviews during the January 2025 intake. The deepfakes used AI-generated images and audio to replace applicants' faces and voices. Enroly stated it caught the attempts using real-time detection methods.
- Company involved
- UK universities
- AI system involved
- Enroly
5 source articles · read the reporting →
Dutch probation service's OXREC algorithm flawed, leading to incorrect recidivism risk assessments
The Dutch Inspectorate of Justice and Security (Inspectie JenV) published a report finding that the probation service's (Reclassering) OXREC algorithm contains serious flaws, including swapped formulas and incorrect numbers, causing about a quarter of risk assessments to be wrong. The algorithm, used since 2018 for about 44,000 cases per year, also uses variables that can lead to discrimination, such as neighborhood score and income. The Inspectorate recommended immediate correction or temporary suspension. The probation service announced it would temporarily stop using OXREC.
- Company involved
- Reclassering Nederland
- AI system involved
- OXREC
4 source articles · read the reporting →
42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE
SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.
- AI system involved
- OpenClaw
5 source articles · read the reporting →
Singapore Firm Defrauded of $499K in Deepfake CEO Video Call Scam
In March 2025, a finance director at a multinational firm in Singapore authorised a US$499,000 payment during a Zoom call that appeared to include the company's CFO and other executives. The call was a deepfake, with AI-generated likenesses and voices. The fraudsters used the impersonation to request an urgent fund transfer for a purported acquisition. The company later discovered the deception and reported it to Singapore police.
2 source articles · read the reporting →
Pasco Sheriff's Office used algorithm to target potential future criminals and schoolchildren
The Pasco Sheriff's Office operates an intelligence-led policing programme that uses an algorithm to identify people who might break the law based on criminal histories and social networks. Deputies are sent to the homes of those flagged, even without evidence of a crime, and former deputies allege they were ordered to make targets' lives miserable. The agency also keeps a list of more than 400 schoolchildren predicted to 'fall into a life of crime', built from data such as grades and child welfare records, without informing the children or their parents. Civil liberties groups are considering lawsuits and public advocacy campaigns, and experts have called the programmes 'morally repugnant'.
- Company involved
- Pasco Sheriff's Office
10 source articles · read the reporting →
Adobe Firefly trained on thousands of Midjourney images, Bloomberg reports
Bloomberg has reported that Adobe's Firefly image generator was trained using thousands of images from competitor Midjourney. Adobe says these made up about 5% of the training data and were part of the Adobe Stock library. The company has marketed Firefly as ethically trained and offered enterprise customers indemnity against copyright claims. Adobe responded that all Adobe Stock images undergo moderation, but the report has raised questions about Firefly's copyright safety.
- Company involved
- Adobe
- AI system involved
- Firefly
7 source articles · read the reporting →
Manchester City to Trial Facial Recognition at Etihad Stadium
Manchester City are set to trial facial recognition software supplied by Blink Identity at the Etihad Stadium. The system would scan fans' faces to check whether they have bought tickets and allow entry, with the aim of reducing matchday queues. Fans would need to sign up using a picture of their face. The article notes concerns about the potential security of users, but the club and vendor say they are committed to protecting fans.
- Company involved
- Manchester City
1 source article · read the reporting →
AI-generated voice impersonates Liz Bonnin to deceive Incognito
Scammers used an AI-generated voice to impersonate BBC presenter Liz Bonnin, convincing Incognito CEO Howard Carter to pay £20,000 for an endorsement. Bonnin's likeness was used in insect repellant ads without her consent. The AI-generated voice note exhibited inconsistent accent and cadence, as assessed by experts. Incognito reported the incident to police and its bank.
6 source articles · read the reporting →
PredictiveHire builds AI to predict job hopping from interviews
PredictiveHire, an AI hiring firm, developed a machine-learning model that analyses candidates' open-ended interview responses to predict their likelihood of 'job hopping'. The company used data from 45,899 applicants to build the 'flight risk' assessment, which it advertises as coming soon. Scholars warn that such tools can suppress wages by screening out workers who might seek better pay or conditions, continuing a historical trend of using personality tests to identify potential labour organisers.
- Company involved
- PredictiveHire
- AI system involved
- Phai
1 source article · read the reporting →
SEC charges YouPlus and CEO with defrauding investors
The SEC charged machine-learning startup YouPlus and its CEO Shaukat Shamim with defrauding investors. Shamim allegedly made false statements about the company's revenue and customer numbers, including providing falsified bank statements. The scheme unravelled when Shamim confessed to investors that the company had earned less than $500,000 and had only four paying customers since 2013. The SEC is seeking permanent injunctions, civil penalties, and an officer-and-director bar.
- Company involved
- YouPlus
- AI system involved
- YouPlus machine-learning tool
1 source article · read the reporting →
AI-powered scam compound in Myanmar uses ChatGPT and Gemini to defraud thousands globally
Safeer Mohammed Koorimannil, trafficked to a scam compound in Tai Chang, Myanmar, was forced to use AI-powered software to impersonate a woman and deceive victims into sending money. The software, Kongtian Intelligent Customer Acquisition and Global Social Traffic Navigation, used OpenAI's ChatGPT and Google's Gemini to generate messages and translate in over 100 languages. Koorimannil targeted 50,000 victims in a month, while the tools enabled scammers to rake in tens of millions of dollars. U.S. authorities have created a strike force to disrupt such operations, and OpenAI has banned accounts linked to the scams.
- Company involved
- Tai Chang
- AI system involved
- Kongtian Intelligent Customer Acquisition (KT) and Global Social Traffic Navigation (007TG)
2 source articles · read the reporting →
Bank of America Customer Targeted by AI Voice Deepfake Scam
Clive Kabatznik, a Florida investor, was targeted by scammers who used AI-generated voice deepfakes to impersonate him in calls to his Bank of America representative. The fraudsters attempted to trick the banker into transferring money, but the banker became suspicious and hung up. The bank reported the incident to its security team, and it took about 10 days for Mr. Kabatznik to re-establish contact with his banker. The incident highlights the growing threat of voice deepfakes in financial scams.
- Company involved
- Bank of America
2 source articles · read the reporting →
Brainwash cafe customers unknowingly put in AI surveillance dataset
In 2014, customers at the Brainwash Cafe in San Francisco were recorded by a publicly available webcam. The images were compiled into a dataset containing 11,917 photos for training surveillance-related object and head detection algorithms. The dataset was later removed from access following an investigation revealing use by researchers affiliated with the National University of Defense Technology in China. The dataset's creators are accused of collecting the images without the cafe customers' knowledge or consent.
- Company involved
- Stanford University
- AI system involved
- Brainwash dataset
1 source article · read the reporting →
Arizona Unemployment Applicants Required to Submit Facial Recognition
People applying for unemployment benefits in Arizona must verify their identity via facial recognition software provided by ID.me. If the system fails to match a selfie to a photo ID, applicants can be denied benefits unless they successfully complete a video chat with a referee. A class-action lawsuit filed in June 2021 alleges that the practice violates due process rights and discriminates against people of colour.
- Company involved
- Arizona Department of Economic Security
- AI system involved
- ID.me
1 source article · read the reporting →