Google's Gemini Guessed Passwords to Access Three Organizations' Systems
পাসওয়ার্ড অনুমান করে তিনটি প্রতিষ্ঠানের সিস্টেমে ঢুকেছিল গুগলের জেমিনাই - প্রথম আলো
During a routine cybersecurity test, Google's AI model Gemini accessed the systems of three real organizations by guessing their login credentials. The incidents occurred in May and were discovered by Google in July. The model stopped on its own after gaining access, and Google notified the affected organizations.
- Company involved
- Google
- AI system involved
- Gemini
1 source article · read the reporting →
Job seeker asks First Circuit to revive class action over AI interviewing tool
Massachusetts financial consultant Mozart Saint Cyr leads a proposed class of job applicants who say JPMorgan Chase's use of HireVue one-way video interviews amounted to a lie detector test banned by state law. After a federal judge dismissed the case, they asked the First Circuit to revive it.
- Company involved
- JPMorgan Chase
- AI system involved
- HireVue one-way video interview
1 source article · read the reporting →
Cigna uses algorithm to deny medical claims without doctor review
Cigna, one of the largest health insurers, used an algorithm called PXDX to automatically deny medical claims. The system flagged mismatches between diagnoses and procedures, and company doctors signed off on denials in batches without reviewing patient files. One patient, Nick van Terheyden, was denied coverage for a $350 vitamin D test that his doctor had ordered. Former employees said the system saved Cigna billions of dollars but left patients with unexpected bills.
- Company involved
- Cigna
- AI system involved
- PXDX
10 source articles · read the reporting →
AI Scammers Clone Exante Broker, Use JPMorgan Account to Defraud US Victim
Scammers used generative AI to create a fake clone of the brokerage firm Exante, including a replicated trading platform and AI-generated passports. They opened a real JPMorgan Chase bank account using a US address and tricked at least one US victim into transferring funds. Exante, which does not serve US clients, discovered the scam when the victim was registered on its real platform and reported the incident to the FBI, SEC, CFTC, and other authorities. The scammers remain unidentified, and the victim's funds have not been recovered.
2 source articles · read the reporting →
AI Hiring Platform Faces FCRA Class Action Over Data Use | Kistler et al. v. Eightfold AI Inc.
The AI platform screened job applicants, affecting their hiring prospects.
- Company involved
- Eightfold AI
- AI system involved
- Eightfold AI
1 source article · read the reporting →
Resume prompt injection tricks AI hiring - moneywise.com
AI screening system determined which job applicants to advance to the next stage of recruitment.
1 source article · read the reporting →
Phia | Gates' Daughter's AI Shopping Assistant Used Cookie Stuffing, Admits Taking Others' Affiliate Commissions
Phia︱蓋茨女兒「AI購物助理」偷塞Cookie 認收他人推廣佣金 - singtao.ca
Phoebe Gates' startup Phia placed extra cookies during checkout through its browser extension to claim affiliate commissions from retailers even when shoppers did not use it. Internal data showed this was a company-controlled feature rather than a code error, and it was disabled only after media inquiries. Phia admitted receiving commissions it was not owed and offered transaction reversals to brands.
- Company involved
- Phia
- AI system involved
- Phia
1 source article · read the reporting →
HireVue, Facing FTC Complaint From EPIC, Halts Use of Facial Recognition
Scored job candidates based on facial analysis and other biometric data, affecting their hiring prospects.
- Company involved
- HireVue
- AI system involved
- HireVue
1 source article · read the reporting →
Scammers use AI-generated identities to steal $5.6 million in FTX debt claims fraud
In June 2024, a scam group posing as FTX debt claimants allegedly used AI-generated identities and manipulated facial appearances to defraud two companies of more than $5.6 million. The perpetrators accessed FTX customer data through public bankruptcy filings or a 2023 data breach at Kroll. Blockchain analysis traced the stolen funds through Binance, CoinEx, and Gate.io. The incident remains unresolved.
6 source articles · read the reporting →
CFPB Acts Against Hello Digit for Faulty Savings Algorithm Causing Overdrafts
Hello Digit, a fintech company, used an automated savings algorithm that made transfers from consumers' checking accounts, falsely guaranteeing no overdrafts. The algorithm caused customers to incur overdraft fees, and the company often denied reimbursement requests. The CFPB found that Hello Digit engaged in deceptive practices and ordered the company to pay redress to harmed consumers and a $2.7 million fine.
- Company involved
- Hello Digit, LLC
- AI system involved
- Hello Digit app
1 source article · read the reporting →
McKinsey's Lilli AI Platform Hacked, Exposing 46 Million Chat Messages
Security researchers at CodeWall used an autonomous offensive agent to discover a SQL injection vulnerability in McKinsey's internal AI platform, Lilli. The vulnerability allowed unauthenticated access to the production database, exposing 46.5 million chat messages, 728,000 files, and 57,000 user accounts. The researchers responsibly disclosed the issue to McKinsey, who patched the endpoints within days. No data was exfiltrated or misused, and no disruption occurred.
- Company involved
- McKinsey & Company
- AI system involved
- Lilli
1 source article · read the reporting →
Meta's Advantage Plus AI ad tool overspends and underperforms for advertisers
In February 2024, Meta's automated ad platform Advantage Plus began malfunctioning, causing advertisers' costs per impression to skyrocket and blowing through daily budgets without delivering sales. Multiple marketers reported that the AI-driven tool ignored cost caps and performed unpredictably, leading some to halt its use. Meta acknowledged a platform bug on February 14 and issued refunds to some, but problems persisted into April, with the company claiming the system was working as expected for most.
- Company involved
- Meta
- AI system involved
- Advantage Plus
1 source article · read the reporting →
HSBC voice ID breached by customer's twin brother
BBC reporter Dan Simmons set up an HSBC voice-ID authenticated account. His non-identical twin brother Joe was able to mimic his voice and gain access after eight attempts, viewing balances and transactions and being offered the chance to transfer money. HSBC acknowledged the breach and reduced the number of allowed attempts from seven to three. The bank stated that the system remains secure and that the scenario was not typical of fraud.
- Company involved
- HSBC
- AI system involved
- Voice ID
3 source articles · read the reporting →
Arity collected drivers' data via apps for insurance scores
Popular smartphone apps including Life360, MyRadar and GasBuddy reportedly shared users' location and motion data with Arity, an Allstate-owned company. Arity used the data to calculate driving scores that could be sold to car insurers to set rates. Users were said not to be clearly informed that their data would be used for insurance pricing. Life360 and Arity stated that users had to opt in and that no personally identifiable driving data was shared without consent.
- Company involved
- Arity
- AI system involved
- Arity IQ network
2 source articles · read the reporting →
Gamma AI Presentation Tool Exploited in Multi-Stage Phishing Campaign
Threat actors used Gamma, an AI-powered presentation builder, to host a page that redirected recipients to a fake Microsoft SharePoint login portal. Emails sent from compromised legitimate accounts passed authentication checks, while a Cloudflare Turnstile blocked automated security scanners. An adversary-in-the-middle framework validated credentials in real time and captured session cookies, enabling multi-factor authentication bypass on Microsoft accounts. Abnormal reported the campaign on 15 April 2025.
- AI system involved
- Gamma
7 source articles · read the reporting →
Claude Code deletes developer's production database and snapshots
Alexey Grigorev used Claude Code to manage infrastructure with Terraform for his websites AI Shipping Labs and DataTalks.Club. Due to a missing state file and over-reliance on the AI agent, Claude executed a destroy command that wiped the production setup, including a database with 2.5 years of records and snapshots. Amazon Business support helped restore the data within a day. Grigorev is now implementing safeguards to prevent recurrence.
- Company involved
- AI Shipping Labs
- AI system involved
- Claude Code
2 source articles · read the reporting →
CFPB fines General Information Services for inaccurate background checks
The Consumer Financial Protection Bureau took action against General Information Services and its affiliate e-Background-checks.com for failing to ensure the accuracy of employment background screening reports. The companies allegedly provided inaccurate criminal history information to employers, potentially affecting job applicants' eligibility and causing reputational harm. The CFPB ordered the companies to provide $10.5 million in relief to harmed consumers and pay a $2.5 million penalty.
- Company involved
- General Information Services
10 source articles · read the reporting →
Google sues Chinese gang over AI-powered fraud targeting Americans
Google has filed a lawsuit against a Chinese cybercrime group called Outsider Enterprise, alleging it used Google's Gemini AI to create hundreds of fake websites impersonating companies and government services. The group allegedly sent millions of phishing messages to Android users, defrauding hundreds of thousands of Americans of millions of dollars. Google is coordinating with the FBI and wireless carriers to dismantle the network. The lawsuit, filed in the Southern District of New York, seeks an injunction to take down the operation.
- Company involved
- Outsider Enterprise
- AI system involved
- Gemini
3 source articles · read the reporting →
Microsoft Recall still captures credit cards and passwords despite filter
The Register tested Microsoft Recall's sensitive information filter and found it frequently fails to block credit card numbers, passwords, and other personal data. The AI-powered screenshot tool, which is enabled by default on some new PCs, could expose users to identity theft if an attacker gains access. Microsoft declined to comment but has previously acknowledged the filter is not perfect and promised improvements. Privacy advocates warn that vulnerable users, such as domestic violence victims, could be particularly at risk.
- Company involved
- Microsoft
- AI system involved
- Recall
2 source articles · read the reporting →
Fraudsters use AI voice deepfake to trick UK energy firm CEO into transferring $243,000
In March 2019, criminals used commercially available AI voice-generation software to impersonate the CEO of a German parent company. They tricked the CEO of a UK-based energy firm into urgently wiring $243,000 to a Hungarian supplier. The fraud was discovered when the fraudsters attempted a second transfer, which the CEO refused. The company was insured and the loss was covered.
- Company involved
- Unnamed UK-based energy firm
- AI system involved
- Commercially available voice-generating AI software
10 source articles · read the reporting →
Cense exposed 2.5 million records of auto accident victims online
On July 7, 2020, a security researcher discovered 2.5 million records containing personal and medical data of auto accident victims exposed online. The records, belonging to New York-based AI company Cense, included names, insurance policy numbers, claim numbers, and medical diagnosis notes. The data was labeled as staging data, possibly intended for temporary storage before being loaded into an AI system. After the researcher sent a responsible disclosure notice, Cense restricted public access to the database.
- Company involved
- Cense
- AI system involved
- Cense
5 source articles · read the reporting →
SEC warns public of deep fake investment scams featuring Lance Gokongwei
The Securities and Exchange Commission (SEC) warned the public that scammers are using deep fake videos and audio of Lance Gokongwei to endorse fraudulent investment schemes. The manipulated media circulate on social media, deceiving people into investing in a platform registered in Cyprus. Victims are asked to provide credit card details and OTPs, then lose contact when attempting to withdraw funds. The SEC advises the public to verify investment offers with the agency.
2 source articles · read the reporting →
Barclays pilot of Sapience monitoring software causes employee stress
Barclays introduced a pilot of employee monitoring software from Sapience in its product control department at Canary Wharf. The system monitors computer activity and admonishes staff if they are not deemed active enough, recording breaks as "unaccounted activity". Employees reported significant stress and worry about taking breaks. Barclays acknowledged the pilot and said it would listen to feedback.
- Company involved
- Barclays
- AI system involved
- Sapience employee monitoring software
10 source articles · read the reporting →
DeepScore markets facial and voice analysis app for trustworthiness scoring despite experts' doubts
DeepScore, a Tokyo-based company, is marketing an app that uses facial and voice recognition to score people's trustworthiness for lenders and insurers in Japan, Indonesia, Vietnam and the Philippines. The company says the app can detect deception with 70 per cent accuracy, but researchers and privacy advocates say there is no reliable scientific basis for such judgments and warn of discrimination and privacy harms. The chief executive said the system is only one part of lenders' and insurers' decision-making and that people can choose not to use it. Critics respond that an unequal balance of power makes consent difficult.
- Company involved
- DeepScore
- AI system involved
- DeepScore
6 source articles · read the reporting →