The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

44 incidents closest to “CMX Insights” · matched on meaning · public reporting

WF-G1FH7N1 Jun 2026Indonesian

Microsoft and xAI Sued by Residents Over Data Center Noise

Microsoft dan xAI Digugat Warga atas Kebisingan Data Center - Telset.id

Microsoft and xAI are facing lawsuits from residents over noise from data centers in Wisconsin and Mississippi. At least six similar cases have been filed in 2026, alleging nuisance and negligence. The lawsuits highlight issues with low-frequency noise measurement and pollution from gas turbines.

Company involved
Microsoft and xAI

1 source article · read the reporting →

WF-KG72NK8 Oct 2024

Data Breach Exposes Over 10 Million Conversations from Middle Eastern AI Call Center Platform

Resecurity discovered a dark web posting on 8 October 2024 offering data stolen from a major AI-powered cloud call center platform in the Middle East. The threat actor gained unauthorized access to the management dashboard, compromising over 10,210,800 conversations between consumers, operators, and AI chatbots. The exposed data included personally identifiable information and national ID documents, creating risks of fraud and identity theft. Resecurity alerted the affected organization and collaborated with law enforcement to mitigate the incident.

3 source articles · read the reporting →

WF-3B287P1 May 2026

Grok AI prompt-injected to drain $150,000 from crypto wallet

In May 2026, an attacker used a Morse code-encoded message to prompt-inject xAI's Grok AI, causing its linked Bankr trading bot to transfer 3 billion DRB tokens worth approximately $150,000 to the attacker's wallet. The attacker first sent an NFT that granted executive permissions, then posted a reply asking Grok to translate a Morse code message that contained a financial instruction. The agent executed the transaction without human oversight, and the funds were immediately liquidated, causing short-term price volatility. About 80% of the funds were later returned after the DRB community identified the attacker.

Company involved
xAI
AI system involved
Grok and Bankr

2 source articles · read the reporting →

xAI Data Center Noise Controversy, Explained - basenor.com

The xAI data center facility generated persistent noise, vibrations, and air quality issues from gas turbines, affecting nearby residents in Southaven, Mississippi.

Company involved
xAI

1 source article · read the reporting →

WF-JCS1A01 Jul 2025

Lieff Cabraser and Greer Injury Lawyers Announce Federal Class Action Lawsuit Against X.AI Corp and MZX Tech LLC for Nuisance,…

The data centers and gas turbines emitted constant noise, vibrations, and particulate matter, affecting residents' ability to use and enjoy their properties.

Company involved
X.AI Corp and MZX Tech LLC
AI system involved
Colossus I, Colossus II, MACROHARDRR, Minihard data centers and gas turbines

1 source article · read the reporting →

WF-WUEQTC4 Sep 2021

Meta Scraped User Photos for Secret Smart-Glasses Tech, Class Action Claims - The SOFX Report

Meta harvested user photographs and created biometric faceprints to enable a smart-glasses system that could identify strangers in public without consent.

Company involved
Meta Platforms, Inc.
AI system involved
NameTag

1 source article · read the reporting →

Meta criticised as AI fake profiles drive Swedish investment fraud

AI-generated fake profiles on Meta are being used to lure Swedish small savers into 'pump and dump' investment schemes. The Swedish Financial Supervisory Authority reports that more than 5,000 savers have lost a total of half a billion kronor. Journalist Gabriel Mellqvist, whose identity was used without consent, criticises Meta for not taking responsibility.

Company involved
Meta

4 source articles · read the reporting →

Moltbook Database Hacked, Exposing Thousands of Emails and Private Messages

Security researchers at Wiz hacked Moltbook's database in under three minutes due to a backend misconfiguration, gaining access to 35,000 email addresses, thousands of private direct messages, and 1.5 million API tokens. The vulnerability could have allowed attackers to impersonate AI agents and manipulate content. Wiz disclosed the issue to Moltbook, which secured the database within hours, and all accessed data was deleted.

Company involved
Moltbook
AI system involved
Moltbook

1 source article · read the reporting →

WF-7SKCJ430 Dec 2025

MeetingTV sues Palo Alto Networks' Koi Security over AI-hallucinated threat report

MeetingTV, a video conferencing startup, alleges that Koi Security used an AI system to generate a threat report that falsely linked it to a Chinese espionage operation. The report, published in December 2025, caused security providers to block MeetingTV's domains, severely impacting its business. MeetingTV contacted Palo Alto Networks, which had acquired Koi, but the blocks remained. The company has now filed a lawsuit alleging defamation and seeking to have the report retracted and the blocks removed.

Company involved
Koi Security
AI system involved
Wings

2 source articles · read the reporting →

WF-BABUXF28 Feb 2026

McKinsey's Lilli AI Platform Hacked, Exposing 46 Million Chat Messages

Security researchers at CodeWall used an autonomous offensive agent to discover a SQL injection vulnerability in McKinsey's internal AI platform, Lilli. The vulnerability allowed unauthenticated access to the production database, exposing 46.5 million chat messages, 728,000 files, and 57,000 user accounts. The researchers responsibly disclosed the issue to McKinsey, who patched the endpoints within days. No data was exfiltrated or misused, and no disruption occurred.

Company involved
McKinsey & Company
AI system involved
Lilli

1 source article · read the reporting →

WF-C6XDL514 Aug 2024

X's Grok AI Image Generator Lacks Guardrails, Users Create Offensive Images of Trademarked Characters

On August 14, 2024, X rolled out image generation capabilities for its Grok AI chatbot to Premium users. The feature lacked content moderation guardrails, allowing users to create offensive images of political figures and trademarked characters like Nintendo's Mario. The images, which included depictions of violence and drug use, appeared alongside advertisements for the affected brands, raising concerns about misinformation and reputational damage. X owner Elon Musk acknowledged the feature's launch and stated the team was training Grok to be 'truthful, but also kind and funny.'

Company involved
X
AI system involved
Grok-2

3 source articles · read the reporting →

WF-CA5PVX14 Feb 2024

Meta's Advantage Plus AI ad tool overspends and underperforms for advertisers

In February 2024, Meta's automated ad platform Advantage Plus began malfunctioning, causing advertisers' costs per impression to skyrocket and blowing through daily budgets without delivering sales. Multiple marketers reported that the AI-driven tool ignored cost caps and performed unpredictably, leading some to halt its use. Meta acknowledged a platform bug on February 14 and issued refunds to some, but problems persisted into April, with the company claiming the system was working as expected for most.

Company involved
Meta
AI system involved
Advantage Plus

1 source article · read the reporting →

LLMjacking Attack Leverages Stolen Credentials to Exploit Cloud LLMs

The Sysdig Threat Research Team observed an attack where stolen cloud credentials were used to access cloud-hosted large language model services. The attackers targeted a vulnerable Laravel system to obtain credentials, then used them to invoke models like Anthropic Claude on AWS Bedrock. They intended to sell LLM access to other cybercriminals, potentially costing victims over $46,000 per day. The attack involved checking credentials against ten AI services and using a reverse proxy to manage access.

AI system involved
Claude (v2/v3) on AWS Bedrock

2 source articles · read the reporting →

WF-HHAQBE4 Jul 2025

Microsoft Copilot Audit Log Flaw Left Customers Unaware

A vulnerability in Microsoft 365 Copilot allowed users to access files without the access being recorded in audit logs, potentially enabling malicious insiders to exfiltrate data undetected. The flaw, discovered by Pistachio's CTO, was reported to Microsoft in July 2025 and fixed in August, but Microsoft decided not to issue a CVE or notify customers. The vulnerability could be triggered accidentally, meaning many organisations' audit logs may be incomplete. Microsoft classified the issue as 'important' but faced criticism for its lack of transparency.

Company involved
Microsoft
AI system involved
M365 Copilot

1 source article · read the reporting →

Gamma AI Presentation Tool Exploited in Multi-Stage Phishing Campaign

Threat actors used Gamma, an AI-powered presentation builder, to host a page that redirected recipients to a fake Microsoft SharePoint login portal. Emails sent from compromised legitimate accounts passed authentication checks, while a Cloudflare Turnstile blocked automated security scanners. An adversary-in-the-middle framework validated credentials in real time and captured session cookies, enabling multi-factor authentication bypass on Microsoft accounts. Abnormal reported the campaign on 15 April 2025.

AI system involved
Gamma

7 source articles · read the reporting →

WF-PR7VW714 Jun 2025

Deepfake Zoom Call Steals Crypto Analyst's X Account

Mai Fujimoto's X account was compromised on 14 June 2025 after a Zoom call in which a deepfake impersonated an acquaintance. The attacker used the call to direct her to a malicious link, resulting in malware that also gave access to her Telegram and MetaMask accounts. Binance founder Changpeng Zhao warned that AI deepfakes make video-call verification unreliable.

1 source article · read the reporting →

WF-JEYRVU26 Dec 2024

Meta AI privacy flaw exposed users' private chats, fixed after hacker report

A security researcher discovered a vulnerability in Meta's AI chatbot that could have allowed unauthorized access to users' private prompts and responses. The flaw, caused by guessable IDs and lack of ownership verification, was reported to Meta on 26 December 2024. Meta fixed the issue on 24 January 2025 and awarded the researcher a $10,000 bug bounty. The company stated that no evidence of exploitation was found.

Company involved
Meta
AI system involved
Meta AI

2 source articles · read the reporting →

341 Malicious ClawHub Skills Found Stealing OpenClaw User Data

Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.

Company involved
OpenClaw
AI system involved
OpenClaw

4 source articles · read the reporting →

WF-JWRXGY7 Jul 2020

Cense exposed 2.5 million records of auto accident victims online

On July 7, 2020, a security researcher discovered 2.5 million records containing personal and medical data of auto accident victims exposed online. The records, belonging to New York-based AI company Cense, included names, insurance policy numbers, claim numbers, and medical diagnosis notes. The data was labeled as staging data, possibly intended for temporary storage before being loaded into an AI system. After the researcher sent a responsible disclosure notice, Cense restricted public access to the database.

Company involved
Cense
AI system involved
Cense

5 source articles · read the reporting →

SEC warns public of deep fake investment scams featuring Lance Gokongwei

The Securities and Exchange Commission (SEC) warned the public that scammers are using deep fake videos and audio of Lance Gokongwei to endorse fraudulent investment schemes. The manipulated media circulate on social media, deceiving people into investing in a platform registered in Cyprus. Victims are asked to provide credit card details and OTPs, then lose contact when attempting to withdraw funds. The SEC advises the public to verify investment offers with the agency.

2 source articles · read the reporting →

Finnish recruitment company Digital Minds used AI to analyze job applicants' messages, prompting data protection investigation

Digital Minds, a Finnish recruitment company founded by psychologists, used IBM Watson AI to analyze job applicants' social media and email messages for personality assessments. The company obtained written consent but the Finnish Data Protection Ombudsman launched an investigation, suspecting violations of data protection laws and the secrecy of correspondence. The service was used on fewer than ten applicants and has been paused pending the investigation.

Company involved
Digital Minds
AI system involved
IBM Watson

9 source articles · read the reporting →

WF-W8NDC11 Jul 2015

New York City's McKinsey-led jail violence program manipulated data, violence increased

New York City paid McKinsey & Company $27.5 million to reduce violence at Rikers Island jail complex. McKinsey designed a predictive algorithm called the Housing Unit Balancer and Restart housing units, but jail officials and McKinsey consultants stacked the units with compliant inmates to artificially lower violence numbers. Violence actually increased by nearly 50% during the project. The city eventually decided to close Rikers.

Company involved
New York City Department of Correction
AI system involved
Housing Unit Balancer (HUB)

10 source articles · read the reporting →

WF-DLCQWL4 Nov 2024

CanLII sues Caseway AI for scraping legal database

The Canadian Legal Information Institute (CanLII) has filed a lawsuit in British Columbia Supreme Court against Caseway AI, alleging that the company's AI chatbot scraped approximately 3.5 million records from CanLII's database in bulk, violating its terms of service and copyright. CanLII claims it adds value to public court records through hyperlinks and corrections, which it says constitute protected copyrighted work. Caseway AI argues the information is public and accessible elsewhere, and that it did not use CanLII's enhancements. The lawsuit was settled in March 2026, with terms undisclosed.

Company involved
Canadian Legal Information Institute (CanLII)
AI system involved
Caseway

5 source articles · read the reporting →

WF-Z58XVI1 May 2021

Meta's content moderation errors during May 2021 Israel-Palestine escalation

During the May 2021 escalation of violence in Israel and Palestine, Meta's automated content moderation systems temporarily restricted access to the al-Aqsa hashtag page and under-enforced rules against incitement to violence against Israelis and Jews. An independent due diligence report commissioned by Meta found that these systems had an unintentional impact on Palestinian and Arab communities' freedom of expression. Meta has committed to implementing several recommendations, including improving machine learning classifiers and keyword review processes.

Company involved
Meta
AI system involved
Facebook and Instagram content moderation systems

10 source articles · read the reporting →

page 1 of 2Older →