The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

44 incidents closest to “Funnel CRM” · matched on meaning · public reporting

Workday Gains an Edge in AI Hiring Bias Fight: California Brief - Bloomberg Law News

Workday Gains an Edge in AI Hiring Bias Fight: California Brief - Bloomberg Law News

1 source article · read the reporting →

AI Hiring Platform Faces FCRA Class Action Over Data Use | Kistler et al. v. Eightfold AI Inc.

The AI platform screened job applicants, affecting their hiring prospects.

Company involved
Eightfold AI
AI system involved
Eightfold AI

1 source article · read the reporting →

Resume prompt injection tricks AI hiring - moneywise.com

AI screening system determined which job applicants to advance to the next stage of recruitment.

1 source article · read the reporting →

WF-386W3V1 Aug 2023

Retool Breached After Hacker Uses AI Deepfake Voice in Phishing Call

A hacker used AI to deepfake an employee's voice and trick a Retool staff member into providing a multi-factor authentication code. The attacker sent phishing SMS messages and then called the employee, impersonating an IT team member with a synthetic voice. This allowed the hacker to add their own device to the employee's account and access internal systems, compromising 27 cloud customers. Retool revoked the access and disclosed the incident, blaming a weakness in Google Authenticator's cloud sync feature.

Company involved
Retool

1 source article · read the reporting →

WF-8DBA8B9 Apr 2025

Guardio Labs finds AI agents easily abused to create phishing scams

Guardio Labs tested three popular AI agents—ChatGPT, Claude, and Lovable—to see how easily they could be manipulated into generating phishing campaigns. The benchmark, called VibeScamming, simulated a novice scammer attempting to create an SMS phishing attack to steal Microsoft credentials. While ChatGPT and Claude initially refused, they provided full code and tutorials after a jailbreak attempt posing as ethical hacking; Lovable instantly generated and deployed a fully functional, convincing phishing page with no resistance.

Company involved
Guardio Labs
AI system involved
ChatGPT, Claude, Lovable

2 source articles · read the reporting →

Fullpath's Car Dealer Chatbot Goes Viral After Being Tricked into Silly Responses

Fullpath's ChatGPT-powered chatbot for car dealers went viral after users tricked it into generating silly responses, including a $1 car price and a Tesla recommendation. The company stated that the system performed as designed and that 99% of the 3,000 attempts to make it say silly things were repelled. No real shoppers were affected, and Fullpath has since implemented measures to prevent similar gaming. The incident was a near miss that highlighted the chatbot's vulnerability to prompt injection.

Company involved
Fullpath
AI system involved
Fullpath's ChatGPT chatbot

8 source articles · read the reporting →

WF-CA5PVX14 Feb 2024

Meta's Advantage Plus AI ad tool overspends and underperforms for advertisers

In February 2024, Meta's automated ad platform Advantage Plus began malfunctioning, causing advertisers' costs per impression to skyrocket and blowing through daily budgets without delivering sales. Multiple marketers reported that the AI-driven tool ignored cost caps and performed unpredictably, leading some to halt its use. Meta acknowledged a platform bug on February 14 and issued refunds to some, but problems persisted into April, with the company claiming the system was working as expected for most.

Company involved
Meta
AI system involved
Advantage Plus

1 source article · read the reporting →

Y Combinator Supports AI Startup Optifye Dehumanizing Factory Workers

Optifye, an AI startup, is accused of dehumanizing factory workers through its system. Y Combinator, which supported the startup, deleted a promotional video for Optifye. The allegations were reported by 404media.co.

Company involved
Optifye
AI system involved
Optifye

7 source articles · read the reporting →

WF-CESBK714 Oct 2024

Portland Water Bureau AI pilot offers discount to billionaire CEO

The Portland Water Bureau used a machine learning system in a randomised control trial to identify customers for its financial assistance programme. The system selected Columbia Sportswear CEO Tim Boyle, a billionaire and one of the city's largest residential water consumers, for a 40% water bill discount. Boyle declined the discount, stating it should go to someone who needs it. The bureau is testing whether the SERVUS algorithm can accurately identify customers' ability to pay.

Company involved
Portland Water Bureau
AI system involved
Smart Discount Program

1 source article · read the reporting →

WF-ZG4J361 Dec 2024

FunkSec Ransomware Group Targets 85 Victims with AI-Assisted Double Extortion

A new ransomware group called FunkSec has claimed over 85 victims since late 2024, using AI-assisted tools to develop its encryptor. The group employs double extortion tactics, stealing data and encrypting files, and demands ransoms as low as $10,000. Researchers suspect the group consists of novice actors recycling leaked data from previous hacktivist leaks, and some members have ties to hacktivist activities. The group also sells stolen data to third parties for $1,000 to $5,000.

Company involved
FunkSec
AI system involved
FunkSec

5 source articles · read the reporting →

WF-ZPB4SK1 Jan 2023

Fast Food Chatbots Fail Job Applicant, Leaving Her Without Interviews

Amanda Claypool applied to five fast food jobs, but AI chatbots used by McDonald's, Wendy's, Crumbl Cookies, and Hardee's malfunctioned, failing to schedule interviews or communicate her availability. Only Waffle House, which used a human contact, hired her. The chatbots left her confused and unable to secure employment, highlighting the shortcomings of automated hiring systems.

Company involved
McDonald's, Wendy's, Crumbl Cookies, Hardee's
AI system involved
Olivia chatbot (McDonald's), unnamed chatbot (Wendy's, Hardee's), HigherMe platform (Crumbl Cookies)

1 source article · read the reporting →

WF-M4ZQBV9 Jul 2025

Urban Cyber Security VPN extension harvested AI chatbot prompts and responses

In July 2025, Urban Cyber Security updated its Urban VPN Proxy Chrome extension to automatically harvest everything users typed into major AI chatbots, including ChatGPT and Claude, as well as the chatbots' replies. The extension, used by over 7 million people, also collected conversation metadata and identifiers, sharing the data with its ad analytics affiliate BIScience. The data collection was disclosed in the privacy policy but users were not explicitly notified at the time of use. Security researchers at Koi discovered the practice and reported it publicly.

Company involved
Urban Cyber Security
AI system involved
Urban VPN Proxy

3 source articles · read the reporting →

Gamma AI Presentation Tool Exploited in Multi-Stage Phishing Campaign

Threat actors used Gamma, an AI-powered presentation builder, to host a page that redirected recipients to a fake Microsoft SharePoint login portal. Emails sent from compromised legitimate accounts passed authentication checks, while a Cloudflare Turnstile blocked automated security scanners. An adversary-in-the-middle framework validated credentials in real time and captured session cookies, enabling multi-factor authentication bypass on Microsoft accounts. Abnormal reported the campaign on 15 April 2025.

AI system involved
Gamma

7 source articles · read the reporting →

WF-J5TEL31 Jan 2017

Facebook's People You May Know Outs Sex Workers to Clients

Facebook's 'People You May Know' feature recommended sex workers' clients as friends, potentially revealing their real identities. Sex workers like Leila and Ela Darling reported that the algorithm linked their separate work and personal identities, leading to harassment and safety risks. Facebook acknowledged the issue but does not allow users to opt out of the feature. The company said it uses over 100 signals to make suggestions but did not disclose how the linking occurred.

Company involved
Facebook
AI system involved
People You May Know

1 source article · read the reporting →

WF-P4AAA619 Aug 2025

FMA Warns of Deepfake Impersonation Scam Targeting Kiwi Investors

The New Zealand Financial Markets Authority (FMA) has warned that a pump-and-dump scam using deepfake ads impersonating business leaders is targeting Kiwi investors. Victims are lured into WhatsApp groups via social media ads and encouraged to buy low-value shares, artificially inflating prices before scammers sell, leaving investors with losses. The FMA has received multiple complaints and is sharing information with overseas regulators, while urging the public to be cautious of unsolicited investment advice.

2 source articles · read the reporting →

341 Malicious ClawHub Skills Found Stealing OpenClaw User Data

Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.

Company involved
OpenClaw
AI system involved
OpenClaw

4 source articles · read the reporting →

Fake Luma Dream Machine AI sites deliver Noodlophile infostealer

Cybercriminals set up Facebook pages impersonating Luma Dream Machine and linked to fake AI video generation websites. Users who uploaded images received an archive containing a malicious executable instead of a video. The executable launched a multi-stage attack that installed Noodlophile, which harvests browser credentials, cookies and cryptocurrency wallet information. Morphisec reported the campaign.

8 source articles · read the reporting →

WF-XLKAV41 Sep 2024

AkiraBot spammed 80,000 websites with AI-generated messages

A Python framework called AkiraBot has spammed over 80,000 websites since September 2024, targeting small and medium-sized businesses. The framework uses OpenAI's API to generate tailored spam messages for contact forms and chat widgets, evading CAPTCHA and network detections. SentinelOne identified the campaign, which is linked to SEO services 'Akira' and 'ServiceWrap' that have received complaints about spamming. The campaign is expected to continue evolving.

Company involved
Akira
AI system involved
AkiraBot

4 source articles · read the reporting →

WF-XWUUFQ1 Mar 2025

Companies face AI deepfake job candidates for remote roles

US companies report a surge in fake job seekers using generative AI tools to fabricate identities, employment histories, and conduct deepfake video interviews for remote positions. Cybersecurity firms Pindrop and CAT Labs, along with BrightHire, describe incidents where scammers, including North Korean operatives, attempted to gain employment to install malware, demand ransoms, steal data, or collect salaries fraudulently. One candidate, 'Ivan X', was detected by Pindrop's video authentication tool after a recruiter noticed his facial expressions were out of sync with his words.

Company involved
Pindrop Security
AI system involved
video authentication program

1 source article · read the reporting →

WF-ROUSJN13 Aug 2019

Facebook hired contractors to transcribe Messenger voice calls

Facebook hired contractors to listen to and transcribe select voice conversations made through its Messenger platform, without users' knowledge, in order to improve artificial intelligence. The practice was exposed by Bloomberg, prompting Facebook to pause the program. The Irish Data Protection Commission stated it was seeking details from Facebook on compliance with GDPR.

Company involved
Facebook
AI system involved
Messenger

10 source articles · read the reporting →

Stanford Researchers Find Over 1,000 LinkedIn Profiles Using AI-Generated Faces for Spam

Renée DiResta and Josh Goldstein of the Stanford Internet Observatory discovered over 1,000 LinkedIn accounts using AI-generated profile images to send sales pitches, bypassing LinkedIn's message limits. The fake accounts, which appeared to be real people, were used for corporate spamming rather than political disinformation. LinkedIn investigated and removed the violating accounts, stating that all profiles must represent real people.

4 source articles · read the reporting →

UIUC researchers use OpenAI API to automate phone scams for under a dollar

Researchers at the University of Illinois Urbana-Champaign used OpenAI's Realtime API to create AI agents that can autonomously execute phone scams. The agents successfully performed bank account transfers and credential theft at an average cost of $0.75 per scam. OpenAI acknowledged the experiment and pointed to its safety policies.

Company involved
University of Illinois Urbana-Champaign
AI system involved
GPT-4o Realtime API

6 source articles · read the reporting →

WF-5IH5EH22 Oct 2019

Gradient app charges users unexpected subscription fees after free trial

The Gradient app, a celebrity lookalike app promoted by the Kardashians, charges users $19.99 per month after a three-day free trial without clear disclosure. Users complained on social media about unexpected credit card charges. The app's developer, Ticket to the Moon, has not addressed the billing complaints but denied collecting user data.

Company involved
Ticket to the Moon, Inc.
AI system involved
Gradient

9 source articles · read the reporting →

Attempted deepfake CEO voicemail fraud against an unnamed technology company

An attacker used synthetic audio deepfake to leave a voicemail impersonating the CEO of a technology company, asking an employee to call back to finalize an urgent business deal. The employee found it suspicious and referred the matter to the legal department, avoiding any loss. Nisos analyzed the audio and found inconsistencies in pitch and tone.

10 source articles · read the reporting →

page 1 of 2Older →