The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

51 incidents closest to “Identity Verification” · matched on meaning · public reporting

WF-YRL6VW4 May 2025

Worldcoin halts ID verification in Indonesia after regulatory freeze

Worldcoin, the digital identity project developed by Tools for Humanity, voluntarily paused its identity verification services in Indonesia on May 5, 2025, following a regulatory freeze by the Ministry of Communication and Digital Application. The ministry acted after preliminary investigations found that operating companies lacked required electronic system provider licenses. Worldcoin uses its Orb device to scan faces and irises to create unique digital identities. The company said it is committed to addressing any regulatory shortcomings and awaits clearer guidance.

Company involved
Worldcoin
AI system involved
World ID

3 source articles · read the reporting →

WF-ROMQCH5 Feb 2024

OnlyFake site uses neural networks to generate fake IDs, bypasses OKX verification

An underground website called OnlyFake uses neural networks to generate realistic photos of fake IDs for $15. The journalist tested the service and obtained a convincing California driver's license. They then used another fake ID to successfully bypass the identity verification process on OKX, a cryptocurrency exchange. The article alleges that this technology could streamline bank fraud and money laundering, but reports no actual financial loss.

Company involved
OKX
AI system involved
OnlyFake

10 source articles · read the reporting →

Hong Kong police arrest eight over deepfake bank account scam

Hong Kong police arrested eight people accused of running a scam ring that used deepfake images to bypass bank verification checks and open accounts. The deepfakes were created by merging scammers' faces with those on lost identity cards using artificial intelligence. The arrests were announced on 19 April 2025.

2 source articles · read the reporting →

WF-3RBX5G1 Jan 2021

Ukrainian Hacker Pleads Guilty to Operating OnlyFake AI ID Scam Site

Yurii Nazarenko, a Ukrainian national, pleaded guilty to running OnlyFake, an AI-powered website that generated and sold over 10,000 counterfeit identification documents globally. The site allowed users to create realistic fake IDs, including driver's licenses and passports, to bypass identity verification at banks and cryptocurrency exchanges. Nazarenko faces up to 15 years in prison and agreed to forfeit $1.2 million. Sentencing is scheduled for June 2026.

Company involved
OnlyFake
AI system involved
OnlyFake

3 source articles · read the reporting →

Tencent launches Zero-Point Cruise facial recognition to enforce night-time game curfew

Tencent has introduced a feature called Zero-Point Cruise in its games, which subjects accounts registered as adults that play at night beyond a set time to facial recognition. Anyone who refuses or fails the verification is treated as a minor and logged out. Tencent says this is intended to stop children using adult identities to evade the game curfew, and that adults who mistakenly refuse can wait for the next authentication.

Company involved
Tencent
AI system involved
零点巡航 (Zero-Point Cruise)

10 source articles · read the reporting →

WF-ASJEKJ1 Jan 2021

GSMA fined €200,000 for facial recognition privacy violation at MWC

In 2021, Dr Anastasia Dedyukhina was invited to speak at Mobile World Congress in Barcelona. The organizers required her to upload biometric data (passport) online for identity verification, which she refused. She was then forced to attend virtually. She filed a complaint with the Spanish data protection agency (AEPD) along with Adam Leon Smith. Two years later, the AEPD fined GSMA €200,000 for infringing the privacy of nearly 20,000 attendees through the use of facial recognition without proper justification.

Company involved
GSMA

10 source articles · read the reporting →

WF-D9RCX416 Mar 2023

Services Australia voiceprint system fooled by AI voice clone

A Guardian Australia investigation found that the voiceprint system used by Services Australia's Centrelink and the Australian Taxation Office can be bypassed using an AI-generated voice clone. A journalist created a clone of their own voice from four minutes of audio and used it with a customer reference number to access their Centrelink self-service account. The system is used by millions of Australians for identity verification over the phone. Services Australia stated that it continually assesses risks and applies additional tests if unusual circumstances are detected, but did not commit to changing the technology.

Company involved
Services Australia
AI system involved
Voiceprint

1 source article · read the reporting →

Gmail users warned of AI voice phishing scam impersonating Google support

Cybercriminals are using AI-generated voices to impersonate Google support in phone calls to Gmail users, attempting to trick them into revealing account credentials. The scam involves a caller ID that appears legitimate and a follow-up email from a spoofed Google address. Victims are told their account has been compromised and are asked to provide a recovery code. Google has advised users to enable Advanced Protection to secure their accounts.

8 source articles · read the reporting →

WF-2MBDEG13 Nov 2017

Apple's Face ID on iPhone X Bypassed by Researchers with 3D-Printed Mask

Security researchers at Bkav in Singapore demonstrated a method to unlock an iPhone X using a 3D-printed mask, makeup, and 2D images, bypassing Apple's Face ID facial recognition system. The proof-of-concept attack, which cost £115 to create, raises concerns for high-profile individuals whose devices could be targeted. Apple stated that Face ID is designed to be secure and that they worked with mask makers to prevent such bypasses, but the vulnerability was shown just ten days after the phone's release.

Company involved
Apple
AI system involved
Face ID

10 source articles · read the reporting →

WF-386W3V1 Aug 2023

Retool Breached After Hacker Uses AI Deepfake Voice in Phishing Call

A hacker used AI to deepfake an employee's voice and trick a Retool staff member into providing a multi-factor authentication code. The attacker sent phishing SMS messages and then called the employee, impersonating an IT team member with a synthetic voice. This allowed the hacker to add their own device to the employee's account and access internal systems, compromising 27 cloud customers. Retool revoked the access and disclosed the incident, blaming a weakness in Google Authenticator's cloud sync feature.

Company involved
Retool

1 source article · read the reporting →

WF-YUL9LB1 Jan 2023

AI chatbots used to steal US college financial aid

Crime rings are deploying AI chatbots as 'ghost students' to enrol in online college courses and fraudulently collect US federal financial aid. Victims of identity theft, such as Heather Brady and Brittnee Nelson, discovered loans of over $9,000 and $5,000 respectively taken out in their names for colleges they never attended. The US Education Department introduced a temporary rule requiring government-issued ID for first-time aid applicants, while California community colleges reported losing at least $11.1 million to such scams.

Company involved
Delgado Community College

4 source articles · read the reporting →

Apple iPhone X Face ID Unlocked by Colleague in China

A woman in Nanjing, China, reported that her colleague's face was able to unlock her iPhone X, and the same issue occurred with a replacement device. An Apple spokesman suggested the phones may have been trained to recognise both faces during passcode setup. The incident highlights a potential vulnerability in the facial recognition system. No harm was reported, and Apple has not examined the devices.

Company involved
Apple
AI system involved
iPhone X Face ID

10 source articles · read the reporting →

WF-ABSWDC1 Jan 2025

ICE’s Mobile Fortify Facial Recognition App Misidentified a Woman Twice

During an immigration raid in Oregon, ICE agents used the Mobile Fortify facial recognition app on a detained woman to determine her identity and immigration status. The app returned two different incorrect names, according to testimony from a CBP official. ICE has claimed the app provides a definitive determination of immigration status, but this incident raises concerns about its accuracy. The misidentification could have led to wrongful removal proceedings.

Company involved
U.S. Immigration and Customs Enforcement (ICE)
AI system involved
Mobile Fortify

1 source article · read the reporting →

WF-5LUPLZ3 Oct 2019

Krungthai Bank's Pao Tang app facial recognition fails, causing queues at branches

Users of the Thai government's Chim Chop Chai stimulus program reported being unable to verify their identity through the Pao Tang app's facial recognition system. Many had to queue at Krungthai Bank branches, with some using shoes to hold their place, to get assistance. The bank provided tips for successful scanning and advised those with persistent issues to visit a branch. The system was not down, but mismatches between appearance and ID photos caused failures.

Company involved
Krungthai Bank
AI system involved
Pao Tang

3 source articles · read the reporting →

WF-D9RCX416 Mar 2023

Services Australia voiceprint system fooled by AI voice clone

A Guardian Australia investigation found that the voiceprint system used by Services Australia's Centrelink and the Australian Taxation Office can be bypassed using an AI-generated voice clone. A journalist created a clone of their own voice from four minutes of audio and used it with a customer reference number to access their Centrelink self-service account. The system is used by millions of Australians for identity verification over the phone. Services Australia stated that it continually assesses risks and applies additional tests if unusual circumstances are detected, but did not commit to changing the technology.

Company involved
Services Australia
AI system involved
Voiceprint

1 source article · read the reporting →

Ahmedabad cyber police bust deepfake Aadhaar fraud racket, four arrested

Four men were arrested in Ahmedabad for allegedly using AI-generated deepfake videos to bypass Aadhaar's facial authentication system. They changed a victim's registered mobile number, accessed his DigiLocker, and applied for loans in his name. The accused, including Common Service Centre operators, used unauthorised Aadhaar update kits. Police are investigating whether more victims were targeted.

Company involved
Unique Identification Authority of India (UIDAI)
AI system involved
Aadhaar facial authentication system

1 source article · read the reporting →

WF-MHB24A3 Jul 2018

Uber's facial recognition suspends transgender drivers' accounts

Uber's Real-Time ID Check feature, which uses Microsoft facial recognition, prompted transgender drivers to take selfies to verify identity. When their appearance changed due to gender transition, the system flagged mismatches and temporarily suspended their accounts. Drivers like Janey Webb lost days of work and had to visit support centres to resolve the issue. Uber acknowledged the incident and stated it is working to improve the app experience.

Company involved
Uber
AI system involved
Real-Time ID Check

1 source article · read the reporting →

WF-EAXKQ219 May 2017

HSBC voice ID breached by customer's twin brother

BBC reporter Dan Simmons set up an HSBC voice-ID authenticated account. His non-identical twin brother Joe was able to mimic his voice and gain access after eight attempts, viewing balances and transactions and being offered the chance to transfer money. HSBC acknowledged the breach and reduced the number of allowed attempts from seven to three. The bank stated that the system remains secure and that the scenario was not typical of fraud.

Company involved
HSBC
AI system involved
Voice ID

3 source articles · read the reporting →

Ryanair requires facial recognition for customers booking via online travel agents

noyb filed a complaint against Ryanair with the Spanish Data Protection Authority (AEPD) on 27 July 2023. A customer who booked a Ryanair flight through online travel agency eDreams was required to undergo a facial recognition verification process or go to the check-in counter more than two hours before departure. The customer was charged a small fee for the verification. Ryanair outsources the facial recognition to GetID. noyb alleges that the process violates GDPR because consent is not valid and the purpose is to discourage bookings through third-party agents.

Company involved
Ryanair
AI system involved
GetID

10 source articles · read the reporting →

WF-ZRNJMY22 Feb 2023

Journalist Bypasses Lloyds Bank Voice ID with AI-Generated Voice Clone

A journalist used an AI-generated clone of his own voice to bypass the voice authentication system of Lloyds Bank, gaining access to his account. The experiment, conducted using ElevenLabs' free voice synthesis service, demonstrated that voice biometrics can be fooled by synthetic voices. Lloyds Bank stated it is aware of the threat and is deploying countermeasures, but has not seen real-world fraud using this method. The incident raises concerns about the security of voice verification used by many banks.

Company involved
Lloyds Bank
AI system involved
Voice ID

1 source article · read the reporting →

WF-MQJRJZ20 Oct 2022

French regulator fines Clearview AI €20 million for privacy breaches

France's privacy watchdog CNIL fined US facial recognition firm Clearview AI €20 million for unlawfully collecting and processing facial images of individuals without consent. The company scraped billions of images from websites and social media, selling access to law enforcement. Clearview AI denied being subject to EU law and refused to delete the data, claiming it was impossible to determine French residency from public photos. The CNIL ordered the firm to stop collecting data and delete existing data within two months or face daily fines.

Company involved
Clearview AI

10 source articles · read the reporting →

WF-MTDPWE17 Jul 2025

AI-generated Centrelink phishing emails target 270,000 Australians

More than 270,000 fake emails impersonating Services Australia and Centrelink were detected over four months in a broad phishing campaign. Cybersecurity firm Mimecast reports that cybercriminals are using artificial intelligence to create highly convincing clones of legitimate government communications about benefits. The attack targets vulnerable people and can lead to identity theft, data theft, malware, or ransomware.

Company involved
Services Australia

4 source articles · read the reporting →

WF-HXSBGM14 Apr 2025

Veriff founder targeted by real-time deepfake video call

Attackers used a real-time deepfake video of Veriff founder Kaarel Kotkas to target a company executive over WhatsApp. The executive became suspicious due to an out-of-character demand for an urgent call and the deepfake's failure to replicate Kotkas's Estonian accent. The fraud was confirmed via a separate communication channel on Slack. The incident is described as a near miss, with no financial loss reported.

Company involved
Veriff

1 source article · read the reporting →

Kimsuky used ChatGPT to create fake military ID for phishing

The hacking group Kimsuky allegedly used ChatGPT to generate a counterfeit South Korean military identification card. This fake ID was used in a phishing email that contained links to malware designed to extract data from victims' devices. Targets included journalists, human rights activists and researchers. The incident highlights the growing misuse of AI for cybercrime.

Company involved
Kimsuky
AI system involved
ChatGPT

6 source articles · read the reporting →

page 1 of 3Older →