US CBP deploys CBP One app using facial recognition for asylum seekers amid privacy concerns
The article reports that U.S. Customs and Border Protection quietly deployed the CBP One mobile app at the Mexico border. The app uses facial recognition and geolocation to collect and verify information on asylum seekers before they enter the United States. Privacy experts warn that the app poses risks of persistent surveillance and that the facial recognition algorithm is unreliable for people of colour. A previous CBP facial recognition pilot was hacked, exposing images. CBP says the app is voluntary and data is secure.
- Company involved
- U.S. Customs and Border Protection
- AI system involved
- CBP One
8 source articles · read the reporting →
Five Illinois residents sue facial recognition company Pimeyes under BIPA
Five Illinois residents are suing Pimeyes, a facial recognition search engine, alleging that the company violated the Illinois Biometric Information Privacy Act by collecting and using their facial data without consent. The lawsuit claims that Pimeyes made the residents' photos and information available in search results, enabling unauthorized access. The company has not yet been served with the lawsuit, and its CEO stated he had no prior knowledge of the case.
- Company involved
- Pimeyes
- AI system involved
- Pimeyes
7 source articles · read the reporting →
California EDD's automated fraud detection wrongly suspended 600,000 legitimate unemployment claims
In January 2021, the California Employment Development Department used Thompson Reuters automated batch review software to flag 1.1 million unemployment claims as potentially fraudulent. EDD stopped payments on those claims without prior notice. Later, over 600,000 were confirmed as legitimate after claimants used ID.me to verify their identity. The incident highlights the trade-off between fraud prevention and timely benefit access.
- Company involved
- California Employment Development Department (EDD)
- AI system involved
- Thompson Reuters Automated Batch Review
7 source articles · read the reporting →
PimEyes scraped Ancestry.com for photos of dead people without permission.
PimEyes, a facial recognition search engine, scraped images from Ancestry.com and other websites without authorization, including photos of deceased individuals. The company's algorithms indexed the images to create biometric faceprints, potentially allowing identification of living relatives. Cher Scarlett discovered the scraping after finding photos of her deceased sister on the platform. PimEyes has since blocked Ancestry's domain and is removing the indexes, but privacy concerns remain.
- Company involved
- PimEyes
- AI system involved
- PimEyes
7 source articles · read the reporting →
PimEyes facial recognition used to unmask porn actors and Facebook friends
A man used the facial recognition site PimEyes to identify porn actors and women from his Facebook friends by uploading their photos and finding matching images online. The system had no controls to prevent searching for others without consent. The article alleges that this invasion of privacy could lead to discrimination and harassment, and that PimEyes offered a paid service to remove photos but did not prevent the searches.
- Company involved
- PimEyes
- AI system involved
- PimEyes
3 source articles · read the reporting →
N-Tech.lab's FindFace used to identify St Petersburg metro passengers without consent
Egor Tsvetkov photographed passengers on the St Petersburg metro without their permission and used N-Tech.lab's facial recognition service FindFace to match their faces to public Vkontakte profiles. He published the results in an art project called 'Your Face is Big Data', saying he wanted to show how 'digital narcissism' can lead to stalking. Privacy advocates said the project was ethically problematic because the subjects had not consented and their identities were exposed. FindFace had been launched by N-Tech.lab in February 2016.
- Company involved
- N-Tech.lab
- AI system involved
- FindFace
8 source articles · read the reporting →
OnlyFake site uses neural networks to generate fake IDs, bypasses OKX verification
An underground website called OnlyFake uses neural networks to generate realistic photos of fake IDs for $15. The journalist tested the service and obtained a convincing California driver's license. They then used another fake ID to successfully bypass the identity verification process on OKX, a cryptocurrency exchange. The article alleges that this technology could streamline bank fraud and money laundering, but reports no actual financial loss.
- Company involved
- OKX
- AI system involved
- OnlyFake
10 source articles · read the reporting →
Hong Kong police arrest eight over deepfake bank account scam
Hong Kong police arrested eight people accused of running a scam ring that used deepfake images to bypass bank verification checks and open accounts. The deepfakes were created by merging scammers' faces with those on lost identity cards using artificial intelligence. The arrests were announced on 19 April 2025.
2 source articles · read the reporting →
South Korea investigates Worldcoin over biometric data collection
South Korea's Personal Information Protection Committee has launched an investigation into Worldcoin, a project that uses iris scanning technology to create a global digital identity. The investigation follows complaints alleging that Worldcoin collected sensitive biometric data from individuals at ten locations across the country without proper consent. The regulator is examining whether Worldcoin violated privacy laws in its data handling practices.
- Company involved
- Worldcoin
- AI system involved
- Worldcoin
8 source articles · read the reporting →
iBorderCtrl lie detector falsely flagged honest reporter as liar
A journalist testing Europe's iBorderCtrl virtual policeman at the Serbian-Hungarian border gave honest answers but was deemed a liar by the system, scoring 48 out of 100 with four false answers flagged. The Hungarian policeman said the result suggested further checks, though none were carried out. The reporter only learned of the result after filing a data access request under European privacy laws. Experts and transparency activists have criticised the technology as pseudoscientific and potentially discriminatory.
- Company involved
- iBorderCtrl consortium
- AI system involved
- Silent Talker / iBorderCtrl virtual policeman
10 source articles · read the reporting →
Worldcoin halts ID verification in Indonesia after regulatory freeze
Worldcoin, the digital identity project developed by Tools for Humanity, voluntarily paused its identity verification services in Indonesia on May 5, 2025, following a regulatory freeze by the Ministry of Communication and Digital Application. The ministry acted after preliminary investigations found that operating companies lacked required electronic system provider licenses. Worldcoin uses its Orb device to scan faces and irises to create unique digital identities. The company said it is committed to addressing any regulatory shortcomings and awaits clearer guidance.
- Company involved
- Worldcoin
- AI system involved
- World ID
3 source articles · read the reporting →
Woman denied state welfare card groceries after face scan fails
A grandmother rode her motorcycle several kilometres to a shop in Sapphaya district, Chai Nat province, to use her state welfare card to buy groceries for her family. After selecting items, she failed repeated facial recognition scans because her ID card photo was years old and no longer matched her appearance. She left the shop empty-handed and in tears.
- Company involved
- Government of Thailand (state welfare card system)
2 source articles · read the reporting →
PimEyes faces fine proceedings over biometric facial recognition in Baden-Württemberg
PimEyes, a facial recognition search engine, is accused of scraping images from the internet and processing biometric data without a valid legal basis under the GDPR. The data protection authority of Baden-Württemberg (LfDI) opened fine proceedings after it found PimEyes's response to its questions inadequate. PimEyes argues that the images it processes are publicly available and not personal data. The LfDI says the processing endangers citizens' rights and freedoms and is not covered by the GDPR exceptions.
- Company involved
- PimEyes
- AI system involved
- PimEyes
9 source articles · read the reporting →
DWP algorithm approved Kickstart gateways with no trading history or based abroad
An FE Week investigation found that the Department for Work and Pensions (DWP) approved dozens of companies as Kickstart gateways through automated due diligence checks using the Cabinet Office Spotlight Tool, although some had little or no trading history or were based abroad. The DWP said gateways were subject to stringent checks and later said human checks were also used. After the findings were shared with the Treasury and the DWP, the department stopped taking gateway applications and scrapped the requirement for small employers to use gateways from 3 February.
- Company involved
- Department for Work and Pensions
- AI system involved
- Cabinet Office Spotlight Tool
3 source articles · read the reporting →
Delhi Police use facial recognition to screen PM Modi rally attendees
Delhi Police used an Automated Facial Recognition System (AFRS) to screen crowds at Prime Minister Narendra Modi's rally on December 22, 2019. The system, originally installed to find missing children, was used to identify possible disruptions. Privacy advocates called the move illegal and unconstitutional, saying it amounts to mass surveillance. Police defended the use, citing credible intelligence about possible disruptions.
- Company involved
- Delhi Police
- AI system involved
- Automated Facial Recognition System (AFRS)
6 source articles · read the reporting →
Outabox hack exposes biometric data of patrons at bars, clubs and casinos
Hackers claiming to be former employees published a website allowing searches of Outabox's facial recognition database, exposing biometric and other sensitive data of patrons used for age verification at bars, clubs and casinos. The Surveillance Technology Oversight Project warns that the breach demonstrates the danger of facial recognition for age verification. S.T.O.P. has launched a campaign to ban facial recognition in public accommodations.
- Company involved
- Outabox
8 source articles · read the reporting →
Dutch DPA fines Clearview AI €30.5 million for GDPR violations
The Dutch Data Protection Authority fined Clearview AI €30.5 million for creating an illegal database of biometric codes scraped from social media without consent. The regulator accused the company of failing to inform individuals about how their data is used and continuing violations after investigation. Clearview AI denies the allegations, stating it has no presence in the Netherlands or EU and that the fine is unenforceable.
- Company involved
- Clearview AI
- AI system involved
- Clearview AI facial recognition database
7 source articles · read the reporting →
PimEyes facial recognition search engine identifies individuals from public photos
PimEyes, a Polish facial recognition search engine, allows users to upload a photo and find matching images from across the internet. The system scrapes billions of photos and creates biometric profiles without consent. A banker named Dylan (pseudonym) discovered that an old party photo of him was found by the system, potentially outing his private life. Privacy advocates and platforms like Instagram and YouTube are taking action against PimEyes, alleging violations of the GDPR.
- Company involved
- PimEyes
- AI system involved
- PimEyes
6 source articles · read the reporting →
Singapore Firm Defrauded of $499K in Deepfake CEO Video Call Scam
In March 2025, a finance director at a multinational firm in Singapore authorised a US$499,000 payment during a Zoom call that appeared to include the company's CFO and other executives. The call was a deepfake, with AI-generated likenesses and voices. The fraudsters used the impersonation to request an urgent fund transfer for a purported acquisition. The company later discovered the deception and reported it to Singapore police.
2 source articles · read the reporting →
TransUnion AI tenant screening denied 75-year-old man apartment due to mistaken littering conviction
Chris Robinson, then 75, applied for a senior living apartment in California. The property manager used an AI screening program from TransUnion, which assigned him a low score based on a mistaken conviction for littering that belonged to a different person with the same name in Texas. Robinson lost the apartment and his application fee. A federal class-action lawsuit against TransUnion moved toward a $11.5 million settlement in 2023.
10 source articles · read the reporting →
Ukrainian Hacker Pleads Guilty to Operating OnlyFake AI ID Scam Site
Yurii Nazarenko, a Ukrainian national, pleaded guilty to running OnlyFake, an AI-powered website that generated and sold over 10,000 counterfeit identification documents globally. The site allowed users to create realistic fake IDs, including driver's licenses and passports, to bypass identity verification at banks and cryptocurrency exchanges. Nazarenko faces up to 15 years in prison and agreed to forfeit $1.2 million. Sentencing is scheduled for June 2026.
- Company involved
- OnlyFake
- AI system involved
- OnlyFake
3 source articles · read the reporting →
Man uses AI face-swap to steal 15,996 yuan from financial accounts, sentenced to 4.5 years
A man in Jiangsu, China, illegally purchased 1.95 million personal records and used AI face-swapping software to bypass facial recognition on financial platforms. He accessed 23 victims' accounts, changed five passwords, and used one account to buy two phones worth 15,996 yuan. He was convicted of infringing citizens' personal information and credit card fraud, sentenced to four years and six months in prison, and ordered to pay damages and delete the data.
3 source articles · read the reporting →
Bahia Facial Recognition System Misidentifies Black Man as Wanted Criminal
Davi, a black administrative assistant, was tracked across 15 metro stations and approached by police after Bahia's facial recognition system falsely matched him to a wanted person. He was released after officers verified his identity. The system, supplied by Iecisa and Huawei, has a low accuracy rate and disproportionately affects black people. The government plans to expand it despite concerns over racial bias and errors.
- Company involved
- Secretaria de Segurança Pública da Bahia
2 source articles · read the reporting →
Clearview AI facial recognition app scrapes billions of images and is used by police
Clearview AI, a secretive start-up, built a facial recognition app that matches photos to a database of more than three billion images scraped from social media and websites. More than 600 law enforcement agencies, including the FBI and Department of Homeland Security, have used the tool to identify suspects in crimes such as shoplifting, identity theft and murder. The company monitored officers who ran a reporter's photo through the app, and its founder acknowledged designing an augmented-reality prototype but said there were no plans to release it. Critics warned the tool could end anonymity and enable misuse.
- Company involved
- Clearview AI
- AI system involved
- Clearview AI facial recognition app
2 source articles · read the reporting →