$3.75M HireVue Illinois BIPA class action settlement - Top Class Actions
Collected voice and facial biometrics from job applicants during video interviews without consent
- Company involved
- HireVue Inc.
- AI system involved
- HireVue
1 source article · read the reporting →
Illinois job applicants may get about $150 from HireVue biometric privacy settlement - The Cool Down
Job applicants were subjected to biometric data collection during video interviews without proper consent.
- Company involved
- HireVue
- AI system involved
- HireVue
1 source article · read the reporting →
CVS settles lawsuit alleging it used AI 'lie detector' in interviews
CVS reached a tentative settlement of a proposed class action by a Massachusetts job applicant who said his 2021 HireVue video interview was analysed with Affectiva's AI to track facial expressions without notice, amounting to a lie detector test banned by state law. He could not opt out or challenge the assessment, and was not hired.
- Company involved
- CVS Health
- AI system involved
- HireVue video interview with Affectiva analysis
1 source article · read the reporting →
Cigna uses algorithm to deny medical claims without doctor review
Cigna, one of the largest health insurers, used an algorithm called PXDX to automatically deny medical claims. The system flagged mismatches between diagnoses and procedures, and company doctors signed off on denials in batches without reviewing patient files. One patient, Nick van Terheyden, was denied coverage for a $350 vitamin D test that his doctor had ordered. Former employees said the system saved Cigna billions of dollars but left patients with unexpected bills.
- Company involved
- Cigna
- AI system involved
- PXDX
10 source articles · read the reporting →
AI Hiring Platform Faces FCRA Class Action Over Data Use | Kistler et al. v. Eightfold AI Inc.
The AI platform screened job applicants, affecting their hiring prospects.
- Company involved
- Eightfold AI
- AI system involved
- Eightfold AI
1 source article · read the reporting →
Data Breach Exposes Over 10 Million Conversations from Middle Eastern AI Call Center Platform
Resecurity discovered a dark web posting on 8 October 2024 offering data stolen from a major AI-powered cloud call center platform in the Middle East. The threat actor gained unauthorized access to the management dashboard, compromising over 10,210,800 conversations between consumers, operators, and AI chatbots. The exposed data included personally identifiable information and national ID documents, creating risks of fraud and identity theft. Resecurity alerted the affected organization and collaborated with law enforcement to mitigate the incident.
3 source articles · read the reporting →
SafeRent Settles Class Action Over Tenant Screening for Voucher Holders
Mary Louis and Monica Douglas filed a class action lawsuit in 2022 alleging that SafeRent Solutions' SafeRent Score product discriminated against rental applicants in Massachusetts who held public housing vouchers, violating fair housing and consumer protection laws. SafeRent denied wrongdoing. The court approved a settlement in November 2024, and payments were distributed to eligible class members in 2025 and 2026.
- Company involved
- SafeRent Solutions, LLC
- AI system involved
- SafeRent Score
5 source articles · read the reporting →
Court orders suspension of facial recognition in São Paulo metro
A court in São Paulo ordered the suspension of a facial recognition system in the city's metro stations following a lawsuit by civil society groups. The system, SecurOS by ISS and operated by ViaQuatro, was capturing biometric data of millions of daily users without adequate transparency or risk assessment. The court also barred the metro operator, METRO, from installing new biometric equipment and imposed daily fines for non-compliance. METRO stated it would appeal the ruling and prove compliance with data protection regulations.
- Company involved
- Companhia do Metropolitano de São Paulo (METRO)
- AI system involved
- SecurOS
3 source articles · read the reporting →
Truck drivers sue Motive over AI dash cam mass surveillance
Truck drivers Adam Dean and Christian Erickson filed a class action lawsuit against Motive Technologies Inc., alleging that the company's AI-powered dash cams with automatic license plate readers collected license plate data and tracked drivers' movements without consent. The lawsuit, filed in California federal court, claims violations of California's ALPR Law and seeks damages of $2,500 per class member. The drivers allege privacy invasion and emotional distress from the surreptitious surveillance.
- Company involved
- Motive Technologies Inc.
1 source article · read the reporting →
CFPB fines General Information Services for inaccurate background checks
The Consumer Financial Protection Bureau took action against General Information Services and its affiliate e-Background-checks.com for failing to ensure the accuracy of employment background screening reports. The companies allegedly provided inaccurate criminal history information to employers, potentially affecting job applicants' eligibility and causing reputational harm. The CFPB ordered the companies to provide $10.5 million in relief to harmed consumers and pay a $2.5 million penalty.
- Company involved
- General Information Services
10 source articles · read the reporting →
Global Entry revoked after ICE agent used facial recognition on observer
Nicole Cleland, a Minnesota resident and volunteer ICE observer, had her Global Entry and TSA PreCheck privileges revoked three days after an ICE agent used facial recognition to identify her while she was following agents. She alleges the revocation is retaliation and intimidation. She filed a declaration in a lawsuit against DHS and ICE. The incident highlights the use of facial recognition by federal agents to identify protesters.
- Company involved
- U.S. Customs and Border Protection
1 source article · read the reporting →
Outback Steakhouse franchise tests Presto Vision to monitor staff and guests
Evergreen Restaurant Group, a franchisee of Outback Steakhouse, has begun testing Presto Vision, a computer vision system that analyses surveillance camera footage to track employee performance and guest behaviour. The system compiles metrics on service, wait times, and customer turnover, which managers receive by email. Employees say they were not informed about the technology, and researchers have raised concerns about workplace stress, job losses, and data sharing with parent companies.
- Company involved
- Evergreen Restaurant Group
- AI system involved
- Presto Vision
8 source articles · read the reporting →
Cense exposed 2.5 million records of auto accident victims online
On July 7, 2020, a security researcher discovered 2.5 million records containing personal and medical data of auto accident victims exposed online. The records, belonging to New York-based AI company Cense, included names, insurance policy numbers, claim numbers, and medical diagnosis notes. The data was labeled as staging data, possibly intended for temporary storage before being loaded into an AI system. After the researcher sent a responsible disclosure notice, Cense restricted public access to the database.
- Company involved
- Cense
- AI system involved
- Cense
5 source articles · read the reporting →
OAIC finds 7-Eleven breached privacy with facial recognition surveys
The Australian Information Commissioner found that 7-Eleven interfered with customers' privacy by collecting facial images and creating faceprints through in-store surveys without adequate notice or consent. The system was used to exclude non-genuine responses and profile demographics. The OAIC ordered 7-Eleven to destroy the collected data and cease the practice.
- Company involved
- 7-Eleven
9 source articles · read the reporting →
Proctortrack data breach exposed student data from online proctoring
Proctortrack, an online proctoring service used by universities, suffered a data breach in September 2020 when its source code was leaked online. An analysis by Consumer Reports found that the code contained hard-coded passwords and exposed the names and email addresses of over 150 students. The company acknowledged the leak but said no harm resulted. Students had been required to use the software, which performed facial recognition and recorded video during exams.
- Company involved
- Proctortrack
- AI system involved
- Proctortrack
10 source articles · read the reporting →
Clearview AI tested facial recognition surveillance cameras with UFT and Rudin
Clearview AI, the facial recognition company that scraped billions of photos from social media, developed a surveillance camera system under the name Insight Camera. The system was tested by the United Federation of Teachers and Rudin Management in New York City. The UFT used it to identify individuals who had made threats and prevent them from entering its offices. Clearview did not respond to requests for comment.
- Company involved
- Clearview AI
- AI system involved
- Insight Camera
9 source articles · read the reporting →
Study finds Italian car insurers charge more based on birthplace
A study by the Universities of Padua, Udine and Carnegie Mellon found that Italian car insurers, including Genertel, Mps, Quixa and Con.Te, use birthplace and citizenship in pricing algorithms, charging some drivers over €1,000 more. The practice was ruled against in a 2018 decree involving Linear, but the study says it continues. The companies contacted denied or explained the findings.
- Company involved
- Genertel, Mps, Quixa, Con.Te
8 source articles · read the reporting →
Verkada security breach exposes customer video and data
In March 2021, attackers compromised Verkada's platform and accessed video and image data from 97 customer organisations. The attackers used a misconfigured customer support server to gain access and viewed live video, accessed badge credentials for eight customers, and downloaded user lists. Verkada cut off access within hours and notified affected customers. The attacker, Tillie Kottmann, was later indicted by the U.S. Department of Justice.
- Company involved
- Verkada
- AI system involved
- Verkada Command platform with People Analytics
10 source articles · read the reporting →
Jacobs files BIPA class action against Walgreen Company over fingerprint scanning
A class action lawsuit alleges that Walgreen Company (Walgreens) collected and stored employees' fingerprint data without obtaining informed consent, in violation of the Illinois Biometric Information Privacy Act (BIPA). The plaintiff, Jacobs, claims the company used fingerprint scanners for employee timekeeping without providing required disclosures or obtaining written consent. The case is pending in Illinois state court.
- Company involved
- Walgreen Company
- AI system involved
- Fingerprint time clock
7 source articles · read the reporting →
ViaQuatro's facial recognition system in São Paulo metro challenged in court
In April 2018, ViaQuatro installed the Digital Interactive Doors System, developed by AdMobilize, on the São Paulo metro's yellow line. The system used cameras to detect passengers' faces and claimed to infer their emotion, age, and gender in order to target advertisements. The Brazilian Institute of Consumer Protection (IDEC) filed a public civil action alleging that the system violated consumer and data protection laws by processing biometric data without consent and making pseudoscientific and discriminatory inferences. A judge ordered the cameras removed in August 2018, and the case is pending a final ruling.
- Company involved
- ViaQuatro
- AI system involved
- Digital Interactive Doors System (DID system)
10 source articles · read the reporting →
PwC develops facial recognition tool to monitor employees working from home
Accounting giant PwC has developed a facial recognition tool that logs when employees are absent from their computer screens while working from home. The tool, intended for financial institutions, requires workers to provide written reasons for any absences, including toilet breaks. Commentators have criticised the tool as a huge invasion of privacy, with concerns about damage to trust and increased stress. PwC stated that the technology is designed to help regulated institutions meet compliance obligations and that voluntary consent of traders is essential.
- Company involved
- PwC
8 source articles · read the reporting →
EPIC lawsuit challenges USPS secret surveillance program using facial recognition
The United States Postal Service's law enforcement wing, the Postal Inspection Service, ran a secret surveillance program called the Internet Covert Operations Program (iCOP) that used facial recognition from Clearview AI and social media monitoring tools to infiltrate online communities and monitor protests. The Electronic Privacy Information Center (EPIC) sued the USPS for failing to conduct and publish a privacy impact assessment as required by the E-Government Act. A federal district court dismissed the lawsuit on standing grounds, ruling that EPIC did not suffer a cognizable injury from the agency's refusal to disclose information about the program.
- Company involved
- United States Postal Service
- AI system involved
- Internet Covert Operations Program (iCOP)
10 source articles · read the reporting →
FTC settles with IntelliVision over deceptive facial recognition claims
The Federal Trade Commission (FTC) took action against IntelliVision Technologies Corp. for making false, misleading, or unsubstantiated claims about its AI-powered facial recognition software. The company allegedly claimed its software had one of the highest accuracy rates on the market and was free of gender or racial bias, without supporting evidence. The FTC also alleged that IntelliVision did not train its software on millions of faces as claimed, but on images of approximately 100,000 individuals. Under a proposed consent order, IntelliVision is prohibited from making such misrepresentations without competent and reliable testing.
- Company involved
- IntelliVision Technologies Corp.
- AI system involved
- IntelliVision facial recognition software
9 source articles · read the reporting →
WorldCoin suspended in Kenya over data security concerns
WorldCoin, a digital identification protocol using iris scans, was suspended by Kenyan regulators (ODPC and Communications Authority) over concerns about data security, consent, and oversight. The system had issued digital IDs and cryptocurrency tokens to over 350,000 Kenyans. Reports of hacked orb operators and iris scans traded on the dark web have also emerged.
- Company involved
- Tools for Humanity GmbH
- AI system involved
- WorldCoin
10 source articles · read the reporting →