Outabox hack exposes biometric data of patrons at bars, clubs and casinos
Hackers claiming to be former employees published a website allowing searches of Outabox's facial recognition database, exposing biometric and other sensitive data of patrons used for age verification at bars, clubs and casinos. The Surveillance Technology Oversight Project warns that the breach demonstrates the danger of facial recognition for age verification. S.T.O.P. has launched a campaign to ban facial recognition in public accommodations.
- Company involved
- Outabox
8 source articles · read the reporting →
Uber driver locked out of app after shaving head, facial recognition failure alleged
Neradi Srikanth, a 23-year-old Uber driver in Hyderabad, was locked out of the app on 27 February 2021 after shaving his head for a religious pilgrimage. He alleges that Uber's facial recognition system failed to recognise him, preventing him from working and causing him to miss a car loan payment. Uber denies this, stating the account was blocked for repeated community guideline violations, and says its system can handle appearance changes. The driver's union reports similar issues among other drivers, highlighting the lack of accountability for platform technology failures.
- Company involved
- Uber
- AI system involved
- Uber facial recognition system
3 source articles · read the reporting →
Dutch DPA fines Clearview AI €30.5 million for GDPR violations
The Dutch Data Protection Authority fined Clearview AI €30.5 million for creating an illegal database of biometric codes scraped from social media without consent. The regulator accused the company of failing to inform individuals about how their data is used and continuing violations after investigation. Clearview AI denies the allegations, stating it has no presence in the Netherlands or EU and that the fine is unenforceable.
- Company involved
- Clearview AI
- AI system involved
- Clearview AI facial recognition database
7 source articles · read the reporting →
UK universities detect deepfake applicants in automated interviews
Some UK universities use Enroly's automated online interviews to screen international student applicants. Enroly detected about 30 cases of deepfake attempts out of 20,000 interviews during the January 2025 intake. The deepfakes used AI-generated images and audio to replace applicants' faces and voices. Enroly stated it caught the attempts using real-time detection methods.
- Company involved
- UK universities
- AI system involved
- Enroly
5 source articles · read the reporting →
PimEyes facial recognition search engine identifies individuals from public photos
PimEyes, a Polish facial recognition search engine, allows users to upload a photo and find matching images from across the internet. The system scrapes billions of photos and creates biometric profiles without consent. A banker named Dylan (pseudonym) discovered that an old party photo of him was found by the system, potentially outing his private life. Privacy advocates and platforms like Instagram and YouTube are taking action against PimEyes, alleging violations of the GDPR.
- Company involved
- PimEyes
- AI system involved
- PimEyes
6 source articles · read the reporting →
Tencent launches Zero-Point Cruise facial recognition to enforce night-time game curfew
Tencent has introduced a feature called Zero-Point Cruise in its games, which subjects accounts registered as adults that play at night beyond a set time to facial recognition. Anyone who refuses or fails the verification is treated as a minor and logged out. Tencent says this is intended to stop children using adult identities to evade the game curfew, and that adults who mistakenly refuse can wait for the next authentication.
- Company involved
- Tencent
- AI system involved
- 零点巡航 (Zero-Point Cruise)
10 source articles · read the reporting →
Singapore Firm Defrauded of $499K in Deepfake CEO Video Call Scam
In March 2025, a finance director at a multinational firm in Singapore authorised a US$499,000 payment during a Zoom call that appeared to include the company's CFO and other executives. The call was a deepfake, with AI-generated likenesses and voices. The fraudsters used the impersonation to request an urgent fund transfer for a purported acquisition. The company later discovered the deception and reported it to Singapore police.
2 source articles · read the reporting →
Ukrainian Hacker Pleads Guilty to Operating OnlyFake AI ID Scam Site
Yurii Nazarenko, a Ukrainian national, pleaded guilty to running OnlyFake, an AI-powered website that generated and sold over 10,000 counterfeit identification documents globally. The site allowed users to create realistic fake IDs, including driver's licenses and passports, to bypass identity verification at banks and cryptocurrency exchanges. Nazarenko faces up to 15 years in prison and agreed to forfeit $1.2 million. Sentencing is scheduled for June 2026.
- Company involved
- OnlyFake
- AI system involved
- OnlyFake
3 source articles · read the reporting →
Telangana Police facial recognition error leads to wrongful arrest and custodial death
Mohammed Khadeer, a 35-year-old man from Medak, was arrested by Telangana Police after a facial recognition system falsely matched his face to a suspect in a chain-snatching case. He was allegedly subjected to custodial torture and later died in hospital on 18 February 2023. The police acknowledged the error and released him after verifying his innocence, but he had already suffered severe injuries. The incident has raised concerns about the lack of transparency and accountability in the use of facial recognition technology by the police.
- Company involved
- Telangana Police
- AI system involved
- Telangana Police Facial Recognition System
1 source article · read the reporting →
Man uses AI face-swap to steal 15,996 yuan from financial accounts, sentenced to 4.5 years
A man in Jiangsu, China, illegally purchased 1.95 million personal records and used AI face-swapping software to bypass facial recognition on financial platforms. He accessed 23 victims' accounts, changed five passwords, and used one account to buy two phones worth 15,996 yuan. He was convicted of infringing citizens' personal information and credit card fraud, sentenced to four years and six months in prison, and ordered to pay damages and delete the data.
3 source articles · read the reporting →
Bahia Facial Recognition System Misidentifies Black Man as Wanted Criminal
Davi, a black administrative assistant, was tracked across 15 metro stations and approached by police after Bahia's facial recognition system falsely matched him to a wanted person. He was released after officers verified his identity. The system, supplied by Iecisa and Huawei, has a low accuracy rate and disproportionately affects black people. The government plans to expand it despite concerns over racial bias and errors.
- Company involved
- Secretaria de Segurança Pública da Bahia
2 source articles · read the reporting →
Manchester City to Trial Facial Recognition at Etihad Stadium
Manchester City are set to trial facial recognition software supplied by Blink Identity at the Etihad Stadium. The system would scan fans' faces to check whether they have bought tickets and allow entry, with the aim of reducing matchday queues. Fans would need to sign up using a picture of their face. The article notes concerns about the potential security of users, but the club and vendor say they are committed to protecting fans.
- Company involved
- Manchester City
1 source article · read the reporting →
AI-generated voice impersonates Liz Bonnin to deceive Incognito
Scammers used an AI-generated voice to impersonate BBC presenter Liz Bonnin, convincing Incognito CEO Howard Carter to pay £20,000 for an endorsement. Bonnin's likeness was used in insect repellant ads without her consent. The AI-generated voice note exhibited inconsistent accent and cadence, as assessed by experts. Incognito reported the incident to police and its bank.
6 source articles · read the reporting →
FBI and ICE use state driver's license photos for facial recognition without consent
The FBI and ICE have been scanning millions of Americans' driver's license photos using facial recognition technology without their knowledge or consent, according to newly released documents. The agencies accessed state DMV databases, turning them into a facial-recognition gold mine. This practice raises significant privacy concerns as it was done without public awareness or legal oversight.
- Company involved
- FBI and ICE
1 source article · read the reporting →
Clearview AI facial recognition app scrapes billions of images and is used by police
Clearview AI, a secretive start-up, built a facial recognition app that matches photos to a database of more than three billion images scraped from social media and websites. More than 600 law enforcement agencies, including the FBI and Department of Homeland Security, have used the tool to identify suspects in crimes such as shoplifting, identity theft and murder. The company monitored officers who ran a reporter's photo through the app, and its founder acknowledged designing an augmented-reality prototype but said there were no plans to release it. Critics warned the tool could end anonymity and enable misuse.
- Company involved
- Clearview AI
- AI system involved
- Clearview AI facial recognition app
2 source articles · read the reporting →
SEC charges YouPlus and CEO with defrauding investors
The SEC charged machine-learning startup YouPlus and its CEO Shaukat Shamim with defrauding investors. Shamim allegedly made false statements about the company's revenue and customer numbers, including providing falsified bank statements. The scheme unravelled when Shamim confessed to investors that the company had earned less than $500,000 and had only four paying customers since 2013. The SEC is seeking permanent injunctions, civil penalties, and an officer-and-director bar.
- Company involved
- YouPlus
- AI system involved
- YouPlus machine-learning tool
1 source article · read the reporting →
Kmart's facial recognition system for refund fraud found unlawful by Privacy Commissioner
Kmart Australia deployed facial recognition technology in 28 stores from June 2020 to July 2022, capturing biometric data of every customer entering the stores and those at returns counters to detect refund fraud. The system collected sensitive information without notifying customers or obtaining their consent. The Australian Privacy Commissioner found that Kmart breached the Privacy Act, as the exemption for unlawful activity did not justify the indiscriminate and disproportionate collection of biometric data from thousands of individuals. Kmart has ceased using the system and cooperated with the investigation.
- Company involved
- Kmart Australia Limited
7 source articles · read the reporting →
Bank of America Customer Targeted by AI Voice Deepfake Scam
Clive Kabatznik, a Florida investor, was targeted by scammers who used AI-generated voice deepfakes to impersonate him in calls to his Bank of America representative. The fraudsters attempted to trick the banker into transferring money, but the banker became suspicious and hung up. The bank reported the incident to its security team, and it took about 10 days for Mr. Kabatznik to re-establish contact with his banker. The incident highlights the growing threat of voice deepfakes in financial scams.
- Company involved
- Bank of America
2 source articles · read the reporting →
NYPD Facial Recognition Leads to Wrongful Arrest of Trevis Williams
In April 2025, Trevis Williams was arrested by the NYPD after a facial recognition program matched his mug shot to a suspect in a February flashing incident, despite an eight-inch height difference and alibi evidence. The victim identified him from the AI-suggested photo array. Mr. Williams spent over two days in jail before the case was dismissed in July. The incident highlights the risks of using facial recognition on low-quality surveillance images.
- Company involved
- New York Police Department
2 source articles · read the reporting →
LinkedIn Used by Foreign Spies with AI-Generated Photos to Target US Officials
Foreign intelligence operations created fake LinkedIn profiles with AI-generated photos to connect with US politicians, lobbyists, and government officials. The fake accounts, such as 'Katie Jones,' sent connection requests to gain credibility and access. LinkedIn removed the account after being contacted by the Associated Press, but the platform remains vulnerable to such espionage tactics.
- Company involved
- LinkedIn
1 source article · read the reporting →
Privacy International challenges Clearview AI's facial recognition database in Europe
Privacy International filed complaints against Clearview AI with five European data protection authorities in May 2021, alleging that the company's scraping of facial images from the web and building a biometric database without consent violates data protection laws. The regulators in the UK, France, Italy, Greece, and Austria have since found Clearview's practices unlawful, imposed fines, and ordered deletion of data. Clearview has appealed the UK fine, and the case is ongoing.
- Company involved
- Clearview AI
- AI system involved
- Clearview
10 source articles · read the reporting →
Father Finds Murdered Daughter Impersonated by Character.ai Chatbot
Drew Crecente discovered that a chatbot on Character.ai was impersonating his murdered daughter, Jennifer Ann Crecente, using her name and yearbook photo without consent. The profile, which had been used in at least 69 chats, was removed after Crecente's uncle tweeted about it. Character.ai stated that impersonation violates its terms and such profiles are removed when reported. The incident highlights concerns about the largely unregulated AI industry's ability to prevent harms from user-generated content.
- Company involved
- Character.ai
- AI system involved
- Character.ai
9 source articles · read the reporting →
Las Vegas police used unsuitable facial recognition images in nearly half of searches
The Las Vegas Metropolitan Police Department (LVMPD) used 'non-suitable' probe images in 451 of 924 facial recognition searches in 2019, greatly increasing the risk of false identifications. The system, supplied by Vigilant Solutions, returned likely matches in only 18% of those searches, yet led to arrests in at least 73 cases. Critics and researchers warn this practice heightens the chance of wrongful arrests, and one defence attorney said he was never informed facial recognition was used to identify his client.
- Company involved
- Las Vegas Metropolitan Police Department
- AI system involved
- Vigilant Solutions facial recognition system
1 source article · read the reporting →
Arizona Unemployment Applicants Required to Submit Facial Recognition
People applying for unemployment benefits in Arizona must verify their identity via facial recognition software provided by ID.me. If the system fails to match a selfie to a photo ID, applicants can be denied benefits unless they successfully complete a video chat with a referee. A class-action lawsuit filed in June 2021 alleges that the practice violates due process rights and discriminates against people of colour.
- Company involved
- Arizona Department of Economic Security
- AI system involved
- ID.me
1 source article · read the reporting →