‘I Did Nothing, Yet My Payment and AI Tokens Were Completely Drained’ — Unauthorized Use of Anthropic Claude Accounts Sparks…
"가만히 있었는데 결제·AI 토큰 100% 소진"…앤트로픽 클로드 계정 무단 도용 파문 - AI포스트
Anthropic Claude accounts were reportedly accessed without authorization, leading to the full consumption of payment methods and AI tokens. The incident has caused a controversy.
- Company involved
- Anthropic
- AI system involved
- Claude
1 source article · read the reporting →
How Your Shadow Credit Score Could Decide Whether You Get an Apartment - ProPublica
Tenant screening companies assign renters a score drawn from data far wider than credit history, an industry subject to less regulation than credit scoring agencies. ProPublica reports that experts warn these algorithms can decide who gets an apartment on the basis of information applicants cannot see or correct. Kim Fuller was denied a rental application on such a score.
- Company involved
- Habitat America
- AI system involved
- RentGrow
1 source article · read the reporting →
Privacy Commissioner criticizes facial recognition trial at Wellington Airport
The Civil Aviation Authority trialled facial recognition technology at Wellington Airport to count passengers and measure queue wait times. The Privacy Commissioner expressed serious concerns, calling the use of facial recognition unnecessary and a privacy risk. The Authority stated it has strict measures to protect privacy.
- Company involved
- Civil Aviation Authority
8 source articles · read the reporting →
Goldman Sachs Apple Card Algorithm Accused of Gender Bias in Credit Limits
In late 2019, David Heinemeier Hansson alleged on Twitter that the Apple Card underwriting algorithm, operated by Goldman Sachs, gave him a higher credit limit than his wife despite similar financial profiles. The New York Department of Financial Services investigated and found no violation of fair lending laws, but critics argue the audit methodology was outdated and failed to detect proxy discrimination. Apple later updated its credit policy to allow spouses to combine credit files, acknowledging a lack of fairness in industry credit scoring.
- Company involved
- Goldman Sachs
- AI system involved
- Apple Card
6 source articles · read the reporting →
Cadillac Fairview malls use facial recognition without consent
At least two Calgary malls owned by Cadillac Fairview, Chinook Centre and Market Mall, deployed facial recognition software in their directories to estimate shoppers' ages and genders without notifying them or obtaining consent. The software, provided by MappedIn, counts users and predicts demographics but does not store images, which the company claims makes consent unnecessary. Privacy advocates expressed concern that the data could be combined with other information to profile individuals, and noted that under Alberta's PIPA, notification is required for collection of personal information. The malls did not offer an opt-out, and the practice was ongoing as of July 2018.
- Company involved
- Cadillac Fairview
- AI system involved
- MappedIn
1 source article · read the reporting →
Krungthai Bank's Pao Tang app facial recognition fails, causing queues at branches
Users of the Thai government's Chim Chop Chai stimulus program reported being unable to verify their identity through the Pao Tang app's facial recognition system. Many had to queue at Krungthai Bank branches, with some using shoes to hold their place, to get assistance. The bank provided tips for successful scanning and advised those with persistent issues to visit a branch. The system was not down, but mismatches between appearance and ID photos caused failures.
- Company involved
- Krungthai Bank
- AI system involved
- Pao Tang
3 source articles · read the reporting →
BP licence plate system falsely accuses Auckland man of fuel theft
Buddhika Rajapakse received multiple letters from BP demanding payment for fuel theft at a Whanganui station, despite his car being a different colour, make and model. BP's licence plate recognition system misread the number plate and failed to cross-check the vehicle details. He contacted BP to explain, and they acknowledged the error but the system has not been fixed, leaving him at risk of further false accusations.
- Company involved
- BP
- AI system involved
- Licence plate recognition system
1 source article · read the reporting →
PayPal's AI chatbot falsely reports a declined transaction
A PayPal user engaged the company's generative AI chatbot, which proactively claimed a recent transaction of $23.64 was declined. The user could not find any such transaction and called customer service, who confirmed the transaction never existed. The chatbot had fabricated the alert. Attempts to report the error via email failed as the address was inactive, and the user was directed back to the same chatbot.
- Company involved
- PayPal
- AI system involved
- PayPal Assistant
1 source article · read the reporting →
CFPB Acts Against Hello Digit for Faulty Savings Algorithm Causing Overdrafts
Hello Digit, a fintech company, used an automated savings algorithm that made transfers from consumers' checking accounts, falsely guaranteeing no overdrafts. The algorithm caused customers to incur overdraft fees, and the company often denied reimbursement requests. The CFPB found that Hello Digit engaged in deceptive practices and ordered the company to pay redress to harmed consumers and a $2.7 million fine.
- Company involved
- Hello Digit, LLC
- AI system involved
- Hello Digit app
1 source article · read the reporting →
Schufa's Black-Box Scoring Unfairly Penalises Consumers with Positive Credit Data
An investigation by SPIEGEL and BR Data reveals that Schufa's credit scoring algorithm often assigns poor risk scores to consumers with only positive credit information. One consumer, Sven Drewert, was denied a credit card limit increase despite having no negative entries. The algorithm uses limited data, and its secret formula can lead to arbitrary categorisations, affecting access to loans, phone contracts, and housing. The system's opacity and potential biases raise concerns about fairness and accountability.
- Company involved
- Schufa Holding AG
- AI system involved
- Schufa Score
2 source articles · read the reporting →
LLMjacking Attack Leverages Stolen Credentials to Exploit Cloud LLMs
The Sysdig Threat Research Team observed an attack where stolen cloud credentials were used to access cloud-hosted large language model services. The attackers targeted a vulnerable Laravel system to obtain credentials, then used them to invoke models like Anthropic Claude on AWS Bedrock. They intended to sell LLM access to other cybercriminals, potentially costing victims over $46,000 per day. The attack involved checking credentials against ten AI services and using a reverse proxy to manage access.
- AI system involved
- Claude (v2/v3) on AWS Bedrock
2 source articles · read the reporting →
Ahmedabad cyber police bust deepfake Aadhaar fraud racket, four arrested
Four men were arrested in Ahmedabad for allegedly using AI-generated deepfake videos to bypass Aadhaar's facial authentication system. They changed a victim's registered mobile number, accessed his DigiLocker, and applied for loans in his name. The accused, including Common Service Centre operators, used unauthorised Aadhaar update kits. Police are investigating whether more victims were targeted.
- Company involved
- Unique Identification Authority of India (UIDAI)
- AI system involved
- Aadhaar facial authentication system
1 source article · read the reporting →
HSBC voice ID breached by customer's twin brother
BBC reporter Dan Simmons set up an HSBC voice-ID authenticated account. His non-identical twin brother Joe was able to mimic his voice and gain access after eight attempts, viewing balances and transactions and being offered the chance to transfer money. HSBC acknowledged the breach and reduced the number of allowed attempts from seven to three. The bank stated that the system remains secure and that the scenario was not typical of fraud.
- Company involved
- HSBC
- AI system involved
- Voice ID
3 source articles · read the reporting →
Ryanair requires facial recognition for customers booking via online travel agents
noyb filed a complaint against Ryanair with the Spanish Data Protection Authority (AEPD) on 27 July 2023. A customer who booked a Ryanair flight through online travel agency eDreams was required to undergo a facial recognition verification process or go to the check-in counter more than two hours before departure. The customer was charged a small fee for the verification. Ryanair outsources the facial recognition to GetID. noyb alleges that the process violates GDPR because consent is not valid and the purpose is to discourage bookings through third-party agents.
- Company involved
- Ryanair
- AI system involved
- GetID
10 source articles · read the reporting →
Journalist Bypasses Lloyds Bank Voice ID with AI-Generated Voice Clone
A journalist used an AI-generated clone of his own voice to bypass the voice authentication system of Lloyds Bank, gaining access to his account. The experiment, conducted using ElevenLabs' free voice synthesis service, demonstrated that voice biometrics can be fooled by synthetic voices. Lloyds Bank stated it is aware of the threat and is deploying countermeasures, but has not seen real-world fraud using this method. The incident raises concerns about the security of voice verification used by many banks.
- Company involved
- Lloyds Bank
- AI system involved
- Voice ID
1 source article · read the reporting →
Claude Code deletes developer's production database and snapshots
Alexey Grigorev used Claude Code to manage infrastructure with Terraform for his websites AI Shipping Labs and DataTalks.Club. Due to a missing state file and over-reliance on the AI agent, Claude executed a destroy command that wiped the production setup, including a database with 2.5 years of records and snapshots. Amazon Business support helped restore the data within a day. Grigorev is now implementing safeguards to prevent recurrence.
- Company involved
- AI Shipping Labs
- AI system involved
- Claude Code
2 source articles · read the reporting →
China's social credit system blocks millions from travel
The Chinese government's social credit system blocked 17.5 million people from buying plane tickets and 5.5 million from train tickets in 2018 as punishment for unpaid fines and other offenses. 128 people were also barred from leaving China due to unpaid taxes. The system, which the ruling Communist Party says improves public behavior, operates automatically and has been criticized by human rights activists and U.S. Vice President Mike Pence as being too rigid and Orwellian.
- Company involved
- Chinese government
- AI system involved
- social credit
10 source articles · read the reporting →
CFPB fines General Information Services for inaccurate background checks
The Consumer Financial Protection Bureau took action against General Information Services and its affiliate e-Background-checks.com for failing to ensure the accuracy of employment background screening reports. The companies allegedly provided inaccurate criminal history information to employers, potentially affecting job applicants' eligibility and causing reputational harm. The CFPB ordered the companies to provide $10.5 million in relief to harmed consumers and pay a $2.5 million penalty.
- Company involved
- General Information Services
10 source articles · read the reporting →
Microsoft Recall still captures credit cards and passwords despite filter
The Register tested Microsoft Recall's sensitive information filter and found it frequently fails to block credit card numbers, passwords, and other personal data. The AI-powered screenshot tool, which is enabled by default on some new PCs, could expose users to identity theft if an attacker gains access. Microsoft declined to comment but has previously acknowledged the filter is not perfect and promised improvements. Privacy advocates warn that vulnerable users, such as domestic violence victims, could be particularly at risk.
- Company involved
- Microsoft
- AI system involved
- Recall
2 source articles · read the reporting →
Home Office passport photo checker biased against dark-skinned women
A BBC investigation found the UK Home Office's online passport photo checker was biased against people with darker skin, particularly women. Dark-skinned women were more than twice as likely to be told their photos failed rules compared to lighter-skinned men. One black student, Elaine Owusu, was repeatedly told her mouth looked open despite it being closed. The Home Office said the tool helps users submit correct photos and that systems are improving.
- Company involved
- Home Office
1 source article · read the reporting →
Gradient app charges users unexpected subscription fees after free trial
The Gradient app, a celebrity lookalike app promoted by the Kardashians, charges users $19.99 per month after a three-day free trial without clear disclosure. Users complained on social media about unexpected credit card charges. The app's developer, Ticket to the Moon, has not addressed the billing complaints but denied collecting user data.
- Company involved
- Ticket to the Moon, Inc.
- AI system involved
- Gradient
9 source articles · read the reporting →
Proctortrack data breach exposed student data from online proctoring
Proctortrack, an online proctoring service used by universities, suffered a data breach in September 2020 when its source code was leaked online. An analysis by Consumer Reports found that the code contained hard-coded passwords and exposed the names and email addresses of over 150 students. The company acknowledged the leak but said no harm resulted. Students had been required to use the software, which performed facial recognition and recorded video during exams.
- Company involved
- Proctortrack
- AI system involved
- Proctortrack
10 source articles · read the reporting →
Study finds Italian car insurers charge more based on birthplace
A study by the Universities of Padua, Udine and Carnegie Mellon found that Italian car insurers, including Genertel, Mps, Quixa and Con.Te, use birthplace and citizenship in pricing algorithms, charging some drivers over €1,000 more. The practice was ruled against in a 2018 decree involving Linear, but the study says it continues. The companies contacted denied or explained the findings.
- Company involved
- Genertel, Mps, Quixa, Con.Te
8 source articles · read the reporting →
Serbia's Social Card law could harm marginalized groups
Serbia's Social Card law, which entered into force on 1 March 2022, establishes a centralized government database to assess eligibility for social security support. Amnesty International and seven other rights organizations submitted a legal opinion to the Constitutional Court, alleging that the automated system is an intrusive surveillance system that could discriminate against Roma communities and people with disabilities. The system processes 130 categories of personal data and lacks transparency, potentially leading to errors and denial of benefits.
- Company involved
- Serbian government
- AI system involved
- Social Card system
10 source articles · read the reporting →