Outabox hack exposes biometric data of patrons at bars, clubs and casinos
Hackers claiming to be former employees published a website allowing searches of Outabox's facial recognition database, exposing biometric and other sensitive data of patrons used for age verification at bars, clubs and casinos. The Surveillance Technology Oversight Project warns that the breach demonstrates the danger of facial recognition for age verification. S.T.O.P. has launched a campaign to ban facial recognition in public accommodations.
- Company involved
- Outabox
8 source articles · read the reporting →
Vumacam's AI CCTV system flagged 28 black people as suspicious in Johannesburg suburbs
In Johannesburg suburbs, Vumacam's AI-powered CCTV network using iSentry software flagged 28 black individuals as 'suspicious' in a shift report, according to a 2019 article. The system, deployed by private security firms, uses video analytics to detect abnormal behavior and alerts security guards. The article alleges that the system disproportionately targets people of color, reflecting racial bias in a racially divided country.
- Company involved
- Vumacam
- AI system involved
- iSentry
6 source articles · read the reporting →
Tennessee's TennCare Connect algorithm illegally denied thousands Medicaid benefits
A U.S. District Court judge ruled that Tennessee's TennCare Connect system, built by Deloitte for over $400 million, illegally denied thousands of low-income residents and people with disabilities Medicaid and disability benefits due to programming and data errors. The system automatically terminated coverage without properly considering eligibility for all available programs. A class action lawsuit filed in 2020 resulted in the ruling.
- Company involved
- TennCare (Tennessee Medicaid)
- AI system involved
- TennCare Connect
10 source articles · read the reporting →
Deloitte software glitches wrongly remove Texans from Medicaid
Advocacy groups filed a complaint with the Federal Trade Commission alleging that Deloitte's eligibility software, TIERS, used by Texas Medicaid, wrongly disenrolled qualified recipients due to glitches. Nearly 1.8 million Texans lost coverage after the pandemic pause ended, with many errors attributed to procedural issues but some linked to system malfunctions. Deloitte denies the claims, while the state says it restored care for at least 90,000 people. The FTC has not yet responded to the complaint.
- Company involved
- Texas Health and Human Services Commission
- AI system involved
- TIERS
6 source articles · read the reporting →
42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE
SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.
- AI system involved
- OpenClaw
5 source articles · read the reporting →
NHTSA investigation PE24016: Unexpected ADS behavior
Waymo's automated driving system exhibited unexpected behavior during driving.
- Company involved
- Waymo
1 source article · read the reporting →
TransUnion AI tenant screening denied 75-year-old man apartment due to mistaken littering conviction
Chris Robinson, then 75, applied for a senior living apartment in California. The property manager used an AI screening program from TransUnion, which assigned him a low score based on a mistaken conviction for littering that belonged to a different person with the same name in Texas. Robinson lost the apartment and his application fee. A federal class-action lawsuit against TransUnion moved toward a $11.5 million settlement in 2023.
10 source articles · read the reporting →
Bahia Facial Recognition System Misidentifies Black Man as Wanted Criminal
Davi, a black administrative assistant, was tracked across 15 metro stations and approached by police after Bahia's facial recognition system falsely matched him to a wanted person. He was released after officers verified his identity. The system, supplied by Iecisa and Huawei, has a low accuracy rate and disproportionately affects black people. The government plans to expand it despite concerns over racial bias and errors.
- Company involved
- Secretaria de Segurança Pública da Bahia
2 source articles · read the reporting →
Security Health Plan used AI to cut off nursing home care for 85-year-old woman
Frances Walter, an 85-year-old woman with a shattered shoulder, had her nursing home care payment cut off by Security Health Plan after an algorithm predicted she would recover in 16.6 days. The algorithm, nH Predict from NaviHealth, did not account for her severe pain and allergy to pain medicine. She was forced to spend her life savings and enroll in Medicaid while fighting the denial. A federal judge later ruled the denial was speculative and she was owed thousands of dollars.
- Company involved
- Security Health Plan
- AI system involved
- nH Predict
1 source article · read the reporting →
Senators demand review of VA's AI-driven contract cancellations
The Department of Veterans Affairs used an AI tool created by a Department of Government Efficiency employee to identify hundreds of contracts for cancellation. Senators Richard Blumenthal and Angus King have called for the VA Inspector General to investigate the use of AI in these decisions, alleging that the tool used flawed formulas and that the cancellations are harming veterans by cutting services. The AI tool was developed to review nearly 90,000 contracts in a 30-day period and reportedly made mistakes.
- Company involved
- Department of Veterans Affairs
8 source articles · read the reporting →
Kmart's facial recognition system for refund fraud found unlawful by Privacy Commissioner
Kmart Australia deployed facial recognition technology in 28 stores from June 2020 to July 2022, capturing biometric data of every customer entering the stores and those at returns counters to detect refund fraud. The system collected sensitive information without notifying customers or obtaining their consent. The Australian Privacy Commissioner found that Kmart breached the Privacy Act, as the exemption for unlawful activity did not justify the indiscriminate and disproportionate collection of biometric data from thousands of individuals. Kmart has ceased using the system and cooperated with the investigation.
- Company involved
- Kmart Australia Limited
7 source articles · read the reporting →
Privacy International challenges Clearview AI's facial recognition database in Europe
Privacy International filed complaints against Clearview AI with five European data protection authorities in May 2021, alleging that the company's scraping of facial images from the web and building a biometric database without consent violates data protection laws. The regulators in the UK, France, Italy, Greece, and Austria have since found Clearview's practices unlawful, imposed fines, and ordered deletion of data. Clearview has appealed the UK fine, and the case is ongoing.
- Company involved
- Clearview AI
- AI system involved
- Clearview
10 source articles · read the reporting →
US Secret Service bought access to cellphone location data
The US Secret Service signed a contract to access Locate X, a service that aggregates location data from phone apps and allows law enforcement to track devices without a warrant. The contract with Babel Street was worth about $36,000 and ran from 2017 to 2018. A former employee said the Secret Service used Locate X in 2018 to seize illegal credit card skimmers at petrol stations. Lawmakers and civil liberties advocates criticised the practice, and Senator Ron Wyden introduced a bill to ban such purchases.
- Company involved
- United States Secret Service
- AI system involved
- Locate X
1 source article · read the reporting →
San Francisco Police Wrongfully Stop Woman at Gunpoint After License Plate Reader Error
On March 30, 2009, Denise Green, a 47-year-old African-American woman, was driving in San Francisco when an automatic license plate reader misread her plate as stolen. Despite discrepancies between the vehicle description and the stolen plate, officers conducted a felony stop, ordering her out at gunpoint and handcuffing her for nearly 20 minutes. Green filed a civil rights lawsuit alleging Fourth Amendment violations. The Ninth Circuit Court of Appeals reinstated her case, finding that the officers lacked reasonable suspicion for the stop.
- Company involved
- San Francisco Police Department
1 source article · read the reporting →
Las Vegas police used unsuitable facial recognition images in nearly half of searches
The Las Vegas Metropolitan Police Department (LVMPD) used 'non-suitable' probe images in 451 of 924 facial recognition searches in 2019, greatly increasing the risk of false identifications. The system, supplied by Vigilant Solutions, returned likely matches in only 18% of those searches, yet led to arrests in at least 73 cases. Critics and researchers warn this practice heightens the chance of wrongful arrests, and one defence attorney said he was never informed facial recognition was used to identify his client.
- Company involved
- Las Vegas Metropolitan Police Department
- AI system involved
- Vigilant Solutions facial recognition system
1 source article · read the reporting →
Arizona Unemployment Applicants Required to Submit Facial Recognition
People applying for unemployment benefits in Arizona must verify their identity via facial recognition software provided by ID.me. If the system fails to match a selfie to a photo ID, applicants can be denied benefits unless they successfully complete a video chat with a referee. A class-action lawsuit filed in June 2021 alleges that the practice violates due process rights and discriminates against people of colour.
- Company involved
- Arizona Department of Economic Security
- AI system involved
- ID.me
1 source article · read the reporting →
Clearview AI settles with ACLU over facial recognition database sales
Clearview AI has agreed to stop selling its facial recognition database to most private US companies as part of a proposed settlement with the ACLU. The company scraped billions of images from social media without consent to build its database, violating Illinois' Biometric Information Privacy Act. The settlement requires Clearview to delete old facial vectors and allow Illinois residents to opt out. The company can still sell its technology to law enforcement and government agencies.
- Company involved
- Clearview AI
- AI system involved
- Clearview AI facial recognition database
8 source articles · read the reporting →
Steak 'n Shake sued over facial recognition kiosks under BIPA
A class action lawsuit alleges that Steak 'n Shake illegally collects facial biometrics from customers using PopID-powered self-ordering kiosks without proper consent. Plaintiff Michael Massel claims the restaurant chain failed to provide notice and obtain written consent as required by Illinois' Biometric Information Privacy Act (BIPA). The suit seeks damages of up to $5,000 per violation for anyone whose biometric data was collected in Illinois in the past five years.
- Company involved
- Steak 'n Shake
- AI system involved
- PopID biometric kiosks
6 source articles · read the reporting →
Macy's and Sunglass Hut facial recognition misidentifies man, leading to wrongful jailing
Harvey Eugene Murphy Jr was misidentified by facial recognition software used by Sunglass Hut and Macy's as the perpetrator of an armed robbery. He was arrested and jailed, where he alleges he was beaten and raped. His alibi was later confirmed and charges were dropped. He is suing the companies for $10 million in damages.
- Company involved
- Macy's and EssilorLuxottica
3 source articles · read the reporting →
NHTSA investigation PE25012: Traffic safety violations while Full Self Driving ("FSD") is engaged
The system made driving decisions that violated traffic safety laws, affecting other road users.
- Company involved
- Tesla, Inc.
- AI system involved
- Full Self Driving (FSD)
1 source article · read the reporting →
Thailand halts iris-scan crypto scheme and deletes 1.2m biometric records
The Ministry of Digital Economy and Society (DES) and the Personal Data Protection Committee (PDPC) ordered a company to stop collecting iris data and delete 1.2 million citizen records. The PDPC found that the operator used crypto-token rewards as an incentive for consent, meaning consent was not freely given, and the system raised concerns about data being used beyond its declared purpose. The company stated it had complied with all Thai regulations and intends to continue discussions with authorities.
- Company involved
- The company behind the iris-scan system (not named)
- AI system involved
- Iris-scan system
4 source articles · read the reporting →
Sainsbury's ejects man misidentified by facial recognition software
Warren Rajah was told to leave a Sainsbury's supermarket in Elephant and Castle, London, after staff incorrectly identified him as an offender flagged by Facewatch facial recognition software. The error occurred at the human verification stage, not the technology itself. Sainsbury's apologised and offered a £75 shopping voucher, and Facewatch confirmed Rajah was not on its database. Rajah criticised the lack of explanation and recourse, and expressed concern for vulnerable customers.
- Company involved
- Sainsbury's
- AI system involved
- Facewatch
5 source articles · read the reporting →
CommNV vs Uprise (Nevada DC): AI-hallucinated content in court filing, Monetary Penalty OR Order to volunteer and teach about AI…
The AI system generated fabricated legal citations that were included in a court filing, misleading the court and opposing counsel.
- Company involved
- Christopher Day
1 source article · read the reporting →
DOJ, Pinnacle reach settlement in RealPage case - Yahoo Finance
The system recommended rent prices to landlords, affecting renters' housing costs.
- Company involved
- Pinnacle Property Management Services
- AI system involved
- RealPage
1 source article · read the reporting →