The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

44 incidents closest to “Experian Ascend Platform” · matched on meaning · public reporting

WF-NHFAIT28 Jul 2026EN

Job seeker asks First Circuit to revive class action over AI interviewing tool

Massachusetts financial consultant Mozart Saint Cyr leads a proposed class of job applicants who say JPMorgan Chase's use of HireVue one-way video interviews amounted to a lie detector test banned by state law. After a federal judge dismissed the case, they asked the First Circuit to revive it.

Company involved
JPMorgan Chase
AI system involved
HireVue one-way video interview

1 source article · read the reporting →

AI Scammers Clone Exante Broker, Use JPMorgan Account to Defraud US Victim

Scammers used generative AI to create a fake clone of the brokerage firm Exante, including a replicated trading platform and AI-generated passports. They opened a real JPMorgan Chase bank account using a US address and tricked at least one US victim into transferring funds. Exante, which does not serve US clients, discovered the scam when the victim was registered on its real platform and reported the incident to the FBI, SEC, CFTC, and other authorities. The scammers remain unidentified, and the victim's funds have not been recovered.

2 source articles · read the reporting →

AI Hiring Platform Faces FCRA Class Action Over Data Use | Kistler et al. v. Eightfold AI Inc.

The AI platform screened job applicants, affecting their hiring prospects.

Company involved
Eightfold AI
AI system involved
Eightfold AI

1 source article · read the reporting →

WF-KG72NK8 Oct 2024

Data Breach Exposes Over 10 Million Conversations from Middle Eastern AI Call Center Platform

Resecurity discovered a dark web posting on 8 October 2024 offering data stolen from a major AI-powered cloud call center platform in the Middle East. The threat actor gained unauthorized access to the management dashboard, compromising over 10,210,800 conversations between consumers, operators, and AI chatbots. The exposed data included personally identifiable information and national ID documents, creating risks of fraud and identity theft. Resecurity alerted the affected organization and collaborated with law enforcement to mitigate the incident.

3 source articles · read the reporting →

Resume prompt injection tricks AI hiring - moneywise.com

AI screening system determined which job applicants to advance to the next stage of recruitment.

1 source article · read the reporting →

AI-Generated Fake Investment Websites Target Australian Fraud Analyst

A fraud analyst, Leon, was targeted by scammers who used AI to create convincing fake websites for non-existent investment firms. The scammers posed as employees of Assent Advisory and directed him to elaborate sites for APPC Capital Singapore and Thackeray Mines and Minerals Inc., complete with AI-generated images and fake details. Leon recognised the scam, but the sophistication of the AI-generated content made him second-guess his own judgment. The incident highlights how AI is enabling more convincing investment scams.

1 source article · read the reporting →

WF-B332QL1 Jan 2017

CFPB Acts Against Hello Digit for Faulty Savings Algorithm Causing Overdrafts

Hello Digit, a fintech company, used an automated savings algorithm that made transfers from consumers' checking accounts, falsely guaranteeing no overdrafts. The algorithm caused customers to incur overdraft fees, and the company often denied reimbursement requests. The CFPB found that Hello Digit engaged in deceptive practices and ordered the company to pay redress to harmed consumers and a $2.7 million fine.

Company involved
Hello Digit, LLC
AI system involved
Hello Digit app

1 source article · read the reporting →

WF-8DBA8B9 Apr 2025

Guardio Labs finds AI agents easily abused to create phishing scams

Guardio Labs tested three popular AI agents—ChatGPT, Claude, and Lovable—to see how easily they could be manipulated into generating phishing campaigns. The benchmark, called VibeScamming, simulated a novice scammer attempting to create an SMS phishing attack to steal Microsoft credentials. While ChatGPT and Claude initially refused, they provided full code and tutorials after a jailbreak attempt posing as ethical hacking; Lovable instantly generated and deployed a fully functional, convincing phishing page with no resistance.

Company involved
Guardio Labs
AI system involved
ChatGPT, Claude, Lovable

2 source articles · read the reporting →

WF-BABUXF28 Feb 2026

McKinsey's Lilli AI Platform Hacked, Exposing 46 Million Chat Messages

Security researchers at CodeWall used an autonomous offensive agent to discover a SQL injection vulnerability in McKinsey's internal AI platform, Lilli. The vulnerability allowed unauthenticated access to the production database, exposing 46.5 million chat messages, 728,000 files, and 57,000 user accounts. The researchers responsibly disclosed the issue to McKinsey, who patched the endpoints within days. No data was exfiltrated or misused, and no disruption occurred.

Company involved
McKinsey & Company
AI system involved
Lilli

1 source article · read the reporting →

WF-AYFJ2A1 Jan 2018

Schufa's Black-Box Scoring Unfairly Penalises Consumers with Positive Credit Data

An investigation by SPIEGEL and BR Data reveals that Schufa's credit scoring algorithm often assigns poor risk scores to consumers with only positive credit information. One consumer, Sven Drewert, was denied a credit card limit increase despite having no negative entries. The algorithm uses limited data, and its secret formula can lead to arbitrary categorisations, affecting access to loans, phone contracts, and housing. The system's opacity and potential biases raise concerns about fairness and accountability.

Company involved
Schufa Holding AG
AI system involved
Schufa Score

2 source articles · read the reporting →

WF-CA5PVX14 Feb 2024

Meta's Advantage Plus AI ad tool overspends and underperforms for advertisers

In February 2024, Meta's automated ad platform Advantage Plus began malfunctioning, causing advertisers' costs per impression to skyrocket and blowing through daily budgets without delivering sales. Multiple marketers reported that the AI-driven tool ignored cost caps and performed unpredictably, leading some to halt its use. Meta acknowledged a platform bug on February 14 and issued refunds to some, but problems persisted into April, with the company claiming the system was working as expected for most.

Company involved
Meta
AI system involved
Advantage Plus

1 source article · read the reporting →

AI chatbots found giving inaccurate financial advice to UK consumers

A Which? study tested AI chatbots including ChatGPT, Copilot, Gemini, Meta AI, and Perplexity on financial questions and found many inaccuracies and misleading statements. The chatbots gave incorrect tax advice, suggested breaking ISA limits, and wrongly claimed travel insurance was mandatory. The Financial Conduct Authority warned that such advice is not covered by ombudsman services. The companies responded by acknowledging limitations and encouraging users to verify information.

Company involved
Meta, OpenAI, Microsoft, Google, Perplexity
AI system involved
Meta AI, ChatGPT, Copilot, Gemini, Perplexity

1 source article · read the reporting →

Blind people and advocates criticise AccessiBe for worsening website access

Blind users and disability advocates say AccessiBe, an automated web accessibility overlay, disrupts screen readers on websites, making some sites unnavigable and preventing users from paying rent, shopping or teaching. More than 400 people signed an open letter asking companies to stop using automated overlays. Some blind users have brought ADA lawsuits against companies that use AccessiBe; one case was referred to mediation and another was settled. AccessiBe denies that it was at fault, saying critics do not give specific examples.

Company involved
AccessiBe
AI system involved
AccessiBe

10 source articles · read the reporting →

WF-NAHAEK19 Aug 2022

Oracle faces US privacy class action over alleged surveillance of five billion people

Oracle is facing a class action lawsuit in California, alleging that its adtech and advertising subsidiaries collected vast amounts of data from internet users without consent, creating detailed profiles on approximately five billion people. The suit, filed by privacy advocates including Dr Johnny Ryan, claims Oracle's practices violate multiple federal and state laws. Oracle declined to comment on the litigation, which remains pending.

Company involved
Oracle

1 source article · read the reporting →

Gamma AI Presentation Tool Exploited in Multi-Stage Phishing Campaign

Threat actors used Gamma, an AI-powered presentation builder, to host a page that redirected recipients to a fake Microsoft SharePoint login portal. Emails sent from compromised legitimate accounts passed authentication checks, while a Cloudflare Turnstile blocked automated security scanners. An adversary-in-the-middle framework validated credentials in real time and captured session cookies, enabling multi-factor authentication bypass on Microsoft accounts. Abnormal reported the campaign on 15 April 2025.

AI system involved
Gamma

7 source articles · read the reporting →

WF-FSUUWV6 Apr 2018

Durham Police uses Experian Mosaic data in HART AI risk tool

Durham Constabulary developed the Harm Assessment Risk Tool (HART), a machine learning algorithm that assesses the recidivism risk of offenders. The tool uses 34 data categories including criminal history, age, gender and two types of postcode, one sourced from Experian's Mosaic marketing segmentation system. Big Brother Watch alleges that using such commercial consumer behaviour data to inform custody decisions risks prejudice and disproportionate targeting of deprived neighbourhoods. The force has stated it is refreshing the model with an aim to remove one of the postcode predictors.

Company involved
Durham Constabulary
AI system involved
Harm Assessment Risk Tool (HART)

9 source articles · read the reporting →

WF-YFC2FF29 Oct 2015

CFPB fines General Information Services for inaccurate background checks

The Consumer Financial Protection Bureau took action against General Information Services and its affiliate e-Background-checks.com for failing to ensure the accuracy of employment background screening reports. The companies allegedly provided inaccurate criminal history information to employers, potentially affecting job applicants' eligibility and causing reputational harm. The CFPB ordered the companies to provide $10.5 million in relief to harmed consumers and pay a $2.5 million penalty.

Company involved
General Information Services

10 source articles · read the reporting →

WF-U5X4EM1 May 2026

Google sues Chinese gang over AI-powered fraud targeting Americans

Google has filed a lawsuit against a Chinese cybercrime group called Outsider Enterprise, alleging it used Google's Gemini AI to create hundreds of fake websites impersonating companies and government services. The group allegedly sent millions of phishing messages to Android users, defrauding hundreds of thousands of Americans of millions of dollars. Google is coordinating with the FBI and wireless carriers to dismantle the network. The lawsuit, filed in the Southern District of New York, seeks an injunction to take down the operation.

Company involved
Outsider Enterprise
AI system involved
Gemini

3 source articles · read the reporting →

Stanford Researchers Find Over 1,000 LinkedIn Profiles Using AI-Generated Faces for Spam

Renée DiResta and Josh Goldstein of the Stanford Internet Observatory discovered over 1,000 LinkedIn accounts using AI-generated profile images to send sales pitches, bypassing LinkedIn's message limits. The fake accounts, which appeared to be real people, were used for corporate spamming rather than political disinformation. LinkedIn investigated and removed the violating accounts, stating that all profiles must represent real people.

4 source articles · read the reporting →

UIUC researchers use OpenAI API to automate phone scams for under a dollar

Researchers at the University of Illinois Urbana-Champaign used OpenAI's Realtime API to create AI agents that can autonomously execute phone scams. The agents successfully performed bank account transfers and credential theft at an average cost of $0.75 per scam. OpenAI acknowledged the experiment and pointed to its safety policies.

Company involved
University of Illinois Urbana-Champaign
AI system involved
GPT-4o Realtime API

6 source articles · read the reporting →

WF-JWRXGY7 Jul 2020

Cense exposed 2.5 million records of auto accident victims online

On July 7, 2020, a security researcher discovered 2.5 million records containing personal and medical data of auto accident victims exposed online. The records, belonging to New York-based AI company Cense, included names, insurance policy numbers, claim numbers, and medical diagnosis notes. The data was labeled as staging data, possibly intended for temporary storage before being loaded into an AI system. After the researcher sent a responsible disclosure notice, Cense restricted public access to the database.

Company involved
Cense
AI system involved
Cense

5 source articles · read the reporting →

UK councils use Covid OneView AI to harvest personal data for risk scoring

UK local authorities are using a system called Covid OneView, developed by data analytics firm Xantura, to harvest millions of personal details from council records. The system uses predictive analytics and AI to assign risk scores to households and individuals, aiming to identify those vulnerable to Covid or likely to break lockdown rules. Privacy campaigners and MPs have criticised the lack of transparency and the extent of data collection, which includes sensitive information such as debt levels, living arrangements, and even notes on unfaithful sex. Xantura and Barking and Dagenham Council have defended the system as compliant with data protection rules and focused on providing support.

Company involved
UK local authorities
AI system involved
Covid OneView

6 source articles · read the reporting →

Finnish recruitment company Digital Minds used AI to analyze job applicants' messages, prompting data protection investigation

Digital Minds, a Finnish recruitment company founded by psychologists, used IBM Watson AI to analyze job applicants' social media and email messages for personality assessments. The company obtained written consent but the Finnish Data Protection Ombudsman launched an investigation, suspecting violations of data protection laws and the secrecy of correspondence. The service was used on fewer than ten applicants and has been paused pending the investigation.

Company involved
Digital Minds
AI system involved
IBM Watson

9 source articles · read the reporting →

WF-6D5AJ41 Jan 2023

ChatGPT falsely tells users OpenCage offers phone lookup service

OpenCage, a geocoding API provider, says ChatGPT has been telling people it offers a reverse phone number lookup service, which it does not. Users who followed the advice signed up for a free trial and found it did not work, and the company says it now receives daily support requests. OpenCage wrote a blog post to correct the record and warn users not to trust ChatGPT's output.

AI system involved
ChatGPT

7 source articles · read the reporting →

page 1 of 2Older →