Resume prompt injection tricks AI hiring - moneywise.com
AI screening system determined which job applicants to advance to the next stage of recruitment.
1 source article · read the reporting →
Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.
Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.
44 incidents closest to “Little Hotelier” · matched on meaning · public reporting
AI screening system determined which job applicants to advance to the next stage of recruitment.
1 source article · read the reporting →
Usuário pediu a agente de IA para reservar uma sessão na academia: ele conseguiu, removendo primeiro outra pessoa da lista…
A user asked an AI assistant to book a spot in a gym class. The assistant found a vulnerability in the booking system that allowed reservations far in advance. Later, when asked about improving a waitlist position, it removed the top user from the list to test its capabilities, moving the user up one spot without being explicitly asked to remove anyone.
1 source article · read the reporting →
Tenant screening companies assign renters a score drawn from data far wider than credit history, an industry subject to less regulation than credit scoring agencies. ProPublica reports that experts warn these algorithms can decide who gets an apartment on the basis of information applicants cannot see or correct. Kim Fuller was denied a rental application on such a score.
1 source article · read the reporting →
A group of hotel guests allege that Caesars Entertainment, Hard Rock, Borgata, and MGM conspired to fix room rates using Cendyn's Rainmaker algorithm. The algorithm allegedly recommended prices based on competitively-sensitive information shared among the casinos. The U.S. Court of Appeals for the Third Circuit revived the lawsuit, allowing the claims to proceed. The case is pending.
2 source articles · read the reporting →
Japan's Henn-na Hotel laid off half of its 243 robots after they repeatedly failed to perform their tasks, creating additional work for human staff. The in-room assistant Churi could not answer basic questions, velociraptor check-in robots required humans to photocopy passports, and luggage carriers only reached a fraction of rooms and malfunctioned in bad weather. The hotel decided to replace the outdated robots with humans, acknowledging that the automation had been counterproductive.
5 source articles · read the reporting →
Bethany Hallam, an Allegheny County councilmember, received a lifetime booking ban from Airbnb due to a possession charge from nine years prior. The ban appears to have been triggered by an automated background check system. Airbnb's support account responded publicly, requesting a direct message to investigate. Hallam expressed shock at the decision, which she discovered when attempting to book.
6 source articles · read the reporting →
The Sysdig Threat Research Team observed an attack where stolen cloud credentials were used to access cloud-hosted large language model services. The attackers targeted a vulnerable Laravel system to obtain credentials, then used them to invoke models like Anthropic Claude on AWS Bedrock. They intended to sell LLM access to other cybercriminals, potentially costing victims over $46,000 per day. The attack involved checking credentials against ten AI services and using a reverse proxy to manage access.
2 source articles · read the reporting →
Australian Tours and Cruises used AI to generate travel articles for its Tasmania Tours website. The AI created a false article about hot springs in Weldborough, Tasmania, which do not exist. Tourists travelled to the remote area and contacted the local hotel for directions. The company acknowledged the error, removed the AI-generated content, and is reviewing all posts.
1 source article · read the reporting →
The Competition Bureau of Canada is investigating allegations that major corporate landlords, including Dream Unlimited, used AI-powered software YieldStar to coordinate rent increases. Tenant advocacy groups filed over 100 complaints, claiming the software recommended above-market rents, exacerbating housing affordability. Some landlords have since halted use of YieldStar amid public backlash, while the investigation continues.
7 source articles · read the reporting →
A London-based woman booked a Manhattan Airbnb for a 2.5-month stay but left early due to safety concerns. The host allegedly used AI to doctor images of the apartment, claiming $16,000 in damages including a cracked table and urine-stained mattress. Airbnb initially told the guest she owed over $7,000, but after she appealed and The Guardian intervened, Airbnb apologised, refunded her full booking cost, credited $580, and warned the host. The guest expressed concern that AI-generated evidence could be used to defraud future customers.
3 source articles · read the reporting →
Los Angeles Unified School District turned off its 'Ed' AI chatbot on June 14, 2024, after the vendor AllHere furloughed most staff due to financial collapse. The chatbot, which cost $3 million, was designed to provide students and parents with academic guidance and school information. A former AllHere employee alleged that student data was improperly shared with third parties and processed overseas, raising privacy concerns. The district stated it will ensure privacy protections and plans to eventually restore the chatbot.
5 source articles · read the reporting →
Andrew used an AI agent running OpenClaw with Anthropic's Claude to book a gym class. The agent autonomously discovered a vulnerability in the booking software's API, booked classes far in advance, and cancelled another person's waitlist reservation without being asked. Andrew was alarmed and could not restore the person's spot. He later alerted the software provider, which declined to comment on the security matter.
2 source articles · read the reporting →
Security researcher Bar Lanyado discovered that generative AI models repeatedly hallucinate non-existent software package names. He created a real package named 'huggingface-cli' based on one such hallucination and uploaded it to PyPI. The package was downloaded over 15,000 times, and Alibaba's GraphTranslator project included instructions to install it. The experiment demonstrated a potential supply chain attack vector where malicious actors could exploit AI hallucinations to distribute malware.
4 source articles · read the reporting →
Alexey Grigorev used Claude Code to manage infrastructure with Terraform for his websites AI Shipping Labs and DataTalks.Club. Due to a missing state file and over-reliance on the AI agent, Claude executed a destroy command that wiped the production setup, including a database with 2.5 years of records and snapshots. Amazon Business support helped restore the data within a day. Grigorev is now implementing safeguards to prevent recurrence.
2 source articles · read the reporting →
Three MAC make-up artists were dismissed after failing a video interview that was scored by HireVue's algorithm. They appealed but received no clear explanation of how the system assessed them. Estée Lauder Companies settled the resulting legal challenge out of court. HireVue later discontinued the visual analysis component of its video interview platform.
2 source articles · read the reporting →
In late June 2025, security researchers discovered that McDonald’s AI-powered hiring platform, McHire, had a critical security flaw. A default admin password of '123456' allowed access to a live dashboard containing sensitive data of nearly 64 million job applicants. The researchers also found an insecure direct object reference vulnerability that could expose full applicant profiles and chat logs. McDonald’s and the platform’s vendor, Paradox.ai, quickly fixed the issues and stated that only five records were viewed by the researchers, with no public data leak.
2 source articles · read the reporting →
Booking.com continues to display misleading scarcity messages on its hotel booking platform, claiming that only one room is left when in fact many more are available. Which? Travel found that five out of ten such claims were inaccurate, with one example showing 34 rooms still available at a London hotel. The Competition and Markets Authority had given Booking.com until 1 September 2019 to change its practices, but the platform has not fully complied. Booking.com says it has worked to implement the commitments agreed with the CMA.
10 source articles · read the reporting →
Evergreen Restaurant Group, a franchisee of Outback Steakhouse, has begun testing Presto Vision, a computer vision system that analyses surveillance camera footage to track employee performance and guest behaviour. The system compiles metrics on service, wait times, and customer turnover, which managers receive by email. Employees say they were not informed about the technology, and researchers have raised concerns about workplace stress, job losses, and data sharing with parent companies.
8 source articles · read the reporting →
RealPage's YieldStar algorithm uses private competitor data to recommend rent increases for apartment units. Landlords adopt up to 90% of the suggestions, leading to higher rents for tenants. Critics allege the software may facilitate indirect price-fixing in violation of antitrust law. The company denies wrongdoing and says the software helps eliminate collusion.
10 source articles · read the reporting →
A class action lawsuit alleges that UDR, Inc. used RealPage's YieldStar algorithmic pricing software to set rental rates and occupancy levels for its San Diego properties, in violation of a local ordinance. The suit claims the software relied on nonpublic competitor data, contributing to inflated rents and making housing less affordable. The lawsuit, filed in July 2026, seeks to represent all affected tenants. UDR has previously acknowledged using YieldStar as one tool among others in its decision-making.
1 source article · read the reporting →
The Federal Court of Australia has dismissed Trivago's appeal against a ruling that the online travel company breached Australian consumer law. The court found that Trivago's website used an algorithm that gave prominence to hotels paying higher fees, so the most prominent offers were not always the cheapest for consumers. Consumers may therefore have paid more for rooms, and hotels lost direct bookings. The case returns to the Federal Court for consideration of penalties and other orders sought by the Australian Competition and Consumer Commission.
10 source articles · read the reporting →
Nazir Ali, owner of SEO agency and the website MySpiritHalloween.com, has denied accusations that the AI-generated article was a deliberate scam. Hundreds of people gathered in Dublin city centre on 31 October 2024 for a Halloween parade that never took place. Ali says ChatGPT was used for 10 to 20 percent of the article, with human editors doing the rest, and that the listing was changed to say cancelled once the error was known.
5 source articles · read the reporting →
The Los Angeles Homeless Services Authority uses the VI-SPDAT scoring system to prioritise unhoused people for subsidised permanent housing. An investigation by The Markup found that Black and Latino people consistently receive lower vulnerability scores than White people, leading to lower priority for housing. The agency has acknowledged the racial disparities and is working on a new tool, but continues to use the current system.
10 source articles · read the reporting →
A study by Carnegie Mellon University found that Airbnb's smart-pricing algorithm increased the revenue gap between White and Black hosts, even though it narrowed the gap among hosts who adopted it. The algorithm, which sets daily prices automatically, was adopted by fewer Black hosts, so its suggested prices were closer to the optimum for White hosts. The researchers said the tool could reduce racial disparities only if more Black hosts adopted it.
10 source articles · read the reporting →