The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

164 incidents closest to “Credit Passport” · matched on meaning · public reporting

Outabox hack exposes biometric data of patrons at bars, clubs and casinos

Hackers claiming to be former employees published a website allowing searches of Outabox's facial recognition database, exposing biometric and other sensitive data of patrons used for age verification at bars, clubs and casinos. The Surveillance Technology Oversight Project warns that the breach demonstrates the danger of facial recognition for age verification. S.T.O.P. has launched a campaign to ban facial recognition in public accommodations.

Company involved
Outabox

8 source articles · read the reporting →

ChatGPT 4o image generator used to create fake receipts

ChatGPT's new image generator, part of the 4o model, can generate realistic fake restaurant receipts. Social media users demonstrated the capability, raising concerns about potential fraud. OpenAI stated that images include metadata and that it takes action against policy violations. The company defended the feature as allowing creative freedom.

Company involved
OpenAI
AI system involved
ChatGPT 4o image generator

5 source articles · read the reporting →

Tencent launches Zero-Point Cruise facial recognition to enforce night-time game curfew

Tencent has introduced a feature called Zero-Point Cruise in its games, which subjects accounts registered as adults that play at night beyond a set time to facial recognition. Anyone who refuses or fails the verification is treated as a minor and logged out. Tencent says this is intended to stop children using adult identities to evade the game curfew, and that adults who mistakenly refuse can wait for the next authentication.

Company involved
Tencent
AI system involved
零点巡航 (Zero-Point Cruise)

10 source articles · read the reporting →

WF-Y1WBTU22 Mar 2022

Citizens Advice finds ethnicity penalty in car insurance pricing

Citizens Advice conducted exploratory research into car insurance pricing and found that people of colour may be paying £250 more per year than White people. The research suggests that areas with large communities of colour may be identified as more risky by algorithms, even when objective risk factors are controlled. Citizens Advice has called on the Financial Conduct Authority to investigate the issue.

9 source articles · read the reporting →

WF-UF6BMA1 Jan 2018

TransUnion AI tenant screening denied 75-year-old man apartment due to mistaken littering conviction

Chris Robinson, then 75, applied for a senior living apartment in California. The property manager used an AI screening program from TransUnion, which assigned him a low score based on a mistaken conviction for littering that belonged to a different person with the same name in Texas. Robinson lost the apartment and his application fee. A federal class-action lawsuit against TransUnion moved toward a $11.5 million settlement in 2023.

10 source articles · read the reporting →

WF-3RBX5G1 Jan 2021

Ukrainian Hacker Pleads Guilty to Operating OnlyFake AI ID Scam Site

Yurii Nazarenko, a Ukrainian national, pleaded guilty to running OnlyFake, an AI-powered website that generated and sold over 10,000 counterfeit identification documents globally. The site allowed users to create realistic fake IDs, including driver's licenses and passports, to bypass identity verification at banks and cryptocurrency exchanges. Nazarenko faces up to 15 years in prison and agreed to forfeit $1.2 million. Sentencing is scheduled for June 2026.

Company involved
OnlyFake
AI system involved
OnlyFake

3 source articles · read the reporting →

WF-QKEZP51 Jan 2025

Scammers Use AI to Create Fake Joann Fabrics Websites to Steal Credit Card Data

After Joann Fabrics filed for bankruptcy in January 2025, scammers used AI to create impostor websites mimicking the retailer's site. These fake sites offered deep discounts to trick shoppers into providing credit-card information and personal data. Customers who placed orders never received products and had their payment information compromised. The incident highlights the growing use of AI by cybercriminals to create convincing fake websites.

2 source articles · read the reporting →

Man uses AI face-swap to steal 15,996 yuan from financial accounts, sentenced to 4.5 years

A man in Jiangsu, China, illegally purchased 1.95 million personal records and used AI face-swapping software to bypass facial recognition on financial platforms. He accessed 23 victims' accounts, changed five passwords, and used one account to buy two phones worth 15,996 yuan. He was convicted of infringing citizens' personal information and credit card fraud, sentenced to four years and six months in prison, and ordered to pay damages and delete the data.

3 source articles · read the reporting →

WF-YUFSC71 Jul 2021

Didi fined for over-collecting personal data of users

The Cyberspace Administration of China fined Didi Global Inc. for violating data protection laws. The investigation found that Didi had over-collected personal data from passengers and drivers, including facial recognition, location, and clipboard information, totaling billions of records. The violations began in 2015 and continued until the investigation in 2021. Didi was ordered to pay a penalty and correct its practices.

Company involved
滴滴全球股份有限公司 (Didi Global Inc.)
AI system involved
Didi ride-hailing apps

8 source articles · read the reporting →

WF-ZGAC7222 Apr 2024

AI-generated voice impersonates Liz Bonnin to deceive Incognito

Scammers used an AI-generated voice to impersonate BBC presenter Liz Bonnin, convincing Incognito CEO Howard Carter to pay £20,000 for an endorsement. Bonnin's likeness was used in insect repellant ads without her consent. The AI-generated voice note exhibited inconsistent accent and cadence, as assessed by experts. Incognito reported the incident to police and its bank.

6 source articles · read the reporting →

WF-04DJR81 Jun 2020

Kmart's facial recognition system for refund fraud found unlawful by Privacy Commissioner

Kmart Australia deployed facial recognition technology in 28 stores from June 2020 to July 2022, capturing biometric data of every customer entering the stores and those at returns counters to detect refund fraud. The system collected sensitive information without notifying customers or obtaining their consent. The Australian Privacy Commissioner found that Kmart breached the Privacy Act, as the exemption for unlawful activity did not justify the indiscriminate and disproportionate collection of biometric data from thousands of individuals. Kmart has ceased using the system and cooperated with the investigation.

Company involved
Kmart Australia Limited

7 source articles · read the reporting →

WF-IWL4TH1 Jan 2018

US Secret Service bought access to cellphone location data

The US Secret Service signed a contract to access Locate X, a service that aggregates location data from phone apps and allows law enforcement to track devices without a warrant. The contract with Babel Street was worth about $36,000 and ran from 2017 to 2018. A former employee said the Secret Service used Locate X in 2018 to seize illegal credit card skimmers at petrol stations. Lawmakers and civil liberties advocates criticised the practice, and Senator Ron Wyden introduced a bill to ban such purchases.

Company involved
United States Secret Service
AI system involved
Locate X

1 source article · read the reporting →

Facebook exempted Trump and other high-profile users from content enforcement rules.

An internal Facebook program called XCheck granted special treatment to millions of high-profile users, including former President Donald Trump and Senator Elizabeth Warren, exempting them from content enforcement rules. The program, initially for quality control, was expanded to whitelist users deemed newsworthy or PR-risky, with the system failing to enforce rules against them. Internal documents revealed that the program made mistakes, often wrongly taking action against high-profile users. Facebook has attempted to phase out the practice but has struggled.

Company involved
Facebook
AI system involved
XCheck

10 source articles · read the reporting →

WF-452L9H1 Jan 2024

Steak 'n Shake sued over facial recognition kiosks under BIPA

A class action lawsuit alleges that Steak 'n Shake illegally collects facial biometrics from customers using PopID-powered self-ordering kiosks without proper consent. Plaintiff Michael Massel claims the restaurant chain failed to provide notice and obtain written consent as required by Illinois' Biometric Information Privacy Act (BIPA). The suit seeks damages of up to $5,000 per violation for anyone whose biometric data was collected in Illinois in the past five years.

Company involved
Steak 'n Shake
AI system involved
PopID biometric kiosks

6 source articles · read the reporting →

WF-4H0F955 Feb 2026

Sainsbury's ejects man misidentified by facial recognition software

Warren Rajah was told to leave a Sainsbury's supermarket in Elephant and Castle, London, after staff incorrectly identified him as an offender flagged by Facewatch facial recognition software. The error occurred at the human verification stage, not the technology itself. Sainsbury's apologised and offered a £75 shopping voucher, and Facewatch confirmed Rajah was not on its database. Rajah criticised the lack of explanation and recourse, and expressed concern for vulnerable customers.

Company involved
Sainsbury's
AI system involved
Facewatch

5 source articles · read the reporting →

WF-R7J8F924 Sep 2026

OpenAI Agent Hacked Australian Government Medicare Portal in World’s First Rogue AI Breach - cybersecuritynews.com

An OpenAI agent accessed the Australian Government Medicare portal without authorization

Company involved
Australian Government
AI system involved
Medicare Portal

1 source article · read the reporting →

WF-0ZQI8S4 Oct 2016

$30M Equifax hard inquiry dispute class action settlement - Top Class Actions

A class action, settled for $30 million, alleged that Equifax automatically rejected consumers' disputes of hard inquiries on their credit reports, sending a form letter instead of investigating.

Company involved
Equifax Information Services LLC

1 source article · read the reporting →

Mr Craig Hadley wrongly accused of fraud at Sports Direct shop using Facewatch facial recognition.

Mr Craig Hadley was wrongly accused of being a fraudster at a Rotherham Sports Direct shop using facial recognition technology supplied by Facewatch. The system flagged him as a known fraudster, but the alert was later attributed to human error. Big Brother Watch, a privacy campaign group, has raised concerns about the lack of due process in such systems.

Company involved
Sports Direct
AI system involved
Facewatch

2 source articles · read the reporting →

WF-EEFSL81 Oct 2021

Airbnb bans users in Australia using trustworthiness algorithm

Airbnb is accused of using an algorithm acquired from Trooly to score users' trustworthiness based on publicly available data, including social media and occupation. Several users in Australia, including a real estate worker and sex workers, report being banned from the platform without explanation or meaningful appeal. The company has not clarified how the algorithm is applied in Australia, and experts have raised concerns about discrimination and lack of transparency.

Company involved
Airbnb
AI system involved
Trooly

4 source articles · read the reporting →

WF-9D8L0R21 Aug 2026

Capital Standard, LLC v. U.S. Bank National Association (CA Florida (2d)): AI-hallucinated content in court filing, Monetary Sanction; Adverse Costs…

The AI generated false legal citations that were included in a court filing, misleading the court.

1 source article · read the reporting →

WF-H8WURM6 Jan 2026

Indore Play School Owner Loses Savings in AI Voice Cloning Fraud

A middle-aged woman in Indore, India, lost her entire savings of Rs 97,500 after a fraudster used AI voice cloning to impersonate her cousin, a police officer. The caller claimed a friend needed urgent cardiac surgery and requested money transfers via QR codes. The victim's teenage daughter made four transactions before they realised the money had not been credited. Police are investigating the incident as the first AI-driven voice cloning fraud in Madhya Pradesh.

3 source articles · read the reporting →

WF-Q4U8TB1 Jun 2016

NADRA biometric system strips citizenship from thousands of Pakistanis

Pakistan's National Database and Registration Authority (NADRA) operates a biometric identification system that underpins citizenship. In 2016, a reverification campaign led to the blocking of hundreds of thousands of national ID cards, disproportionately affecting Pashtuns. Gulzar Bibi, a 53-year-old widow, had her card suspended after her brother's lost ID was misused, causing her to lose access to welfare, mobile service, and effectively rendering her stateless. Despite visiting NADRA, she was told to provide decades-old documentation to prove her citizenship, with no resolution reported.

Company involved
National Database and Registration Authority (NADRA)
AI system involved
NADRA biometric identification system

5 source articles · read the reporting →

WF-VDYW5W1 Jan 2017

FTC charges Ring with illegal surveillance and security failures

The Federal Trade Commission charged Ring, a home security camera company, with compromising customer privacy by allowing employees to access private videos and failing to prevent hackers from taking control of cameras. Hackers accessed approximately 55,000 U.S. customers' accounts, harassing individuals including children and the elderly. The proposed order requires Ring to pay $5.8 million in refunds and implement security measures.

Company involved
Ring LLC
AI system involved
Ring cameras

10 source articles · read the reporting →

WF-V449AT28 Apr 2021

Ningbo fines property developers for using facial recognition without consent

In Ningbo, China, property developers were fined for using facial recognition technology to identify customers without their consent. The enforcement followed China's annual Consumer Protection Gala that highlighted misuse of facial recognition. The fines were imposed by the local government and the developers were accused of violating privacy regulations.

Company involved
Multiple property developers in Ningbo
AI system involved
Facial recognition technology

6 source articles · read the reporting →

← Newerpage 6 of 7Older →