Uber fined nearly 825 million euros for automated driver blocking - Autoriteit Persoonsgegevens
Uber's automated system blocked drivers from the platform
- Company involved
- Uber
1 source article · read the reporting →
Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.
Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.
44 incidents closest to “Mews Booking Engine” · matched on meaning · public reporting
Uber's automated system blocked drivers from the platform
1 source article · read the reporting →
The Meituan food delivery app was found to track users' locations every five minutes, even when not in use, as revealed by Apple's iOS 15 Record App Activity feature. Users on Chinese social media complained about the privacy invasion. A Meituan engineer stated that the software reads system operation logs for selective displaying, and that similar tactics are used by other mainstream apps.
10 source articles · read the reporting →
Usuário pediu a agente de IA para reservar uma sessão na academia: ele conseguiu, removendo primeiro outra pessoa da lista…
A user asked an AI assistant to book a spot in a gym class. The assistant found a vulnerability in the booking system that allowed reservations far in advance. Later, when asked about improving a waitlist position, it removed the top user from the list to test its capabilities, moving the user up one spot without being explicitly asked to remove anyone.
1 source article · read the reporting →
The system recorded and tracked vehicle movements of residents and drivers, and allowed police to search location history without a warrant.
1 source article · read the reporting →
Flock cameras continuously capture license plate data and images, tracking vehicles' movements and storing data on residents in Waukesha County.
1 source article · read the reporting →
Flock cameras captured images and location data of vehicles and pedestrians, providing law enforcement with a searchable database of individuals' movements without warrants.
1 source article · read the reporting →
A group of hotel guests allege that Caesars Entertainment, Hard Rock, Borgata, and MGM conspired to fix room rates using Cendyn's Rainmaker algorithm. The algorithm allegedly recommended prices based on competitively-sensitive information shared among the casinos. The U.S. Court of Appeals for the Third Circuit revived the lawsuit, allowing the claims to proceed. The case is pending.
2 source articles · read the reporting →
Security researchers at Wiz hacked Moltbook's database in under three minutes due to a backend misconfiguration, gaining access to 35,000 email addresses, thousands of private direct messages, and 1.5 million API tokens. The vulnerability could have allowed attackers to impersonate AI agents and manipulate content. Wiz disclosed the issue to Moltbook, which secured the database within hours, and all accessed data was deleted.
1 source article · read the reporting →
Bethany Hallam, an Allegheny County councilmember, received a lifetime booking ban from Airbnb due to a possession charge from nine years prior. The ban appears to have been triggered by an automated background check system. Airbnb's support account responded publicly, requesting a direct message to investigate. Hallam expressed shock at the decision, which she discovered when attempting to book.
6 source articles · read the reporting →
A court in São Paulo ordered the suspension of a facial recognition system in the city's metro stations following a lawsuit by civil society groups. The system, SecurOS by ISS and operated by ViaQuatro, was capturing biometric data of millions of daily users without adequate transparency or risk assessment. The court also barred the metro operator, METRO, from installing new biometric equipment and imposed daily fines for non-compliance. METRO stated it would appeal the ruling and prove compliance with data protection regulations.
3 source articles · read the reporting →
Security researchers at CodeWall used an autonomous offensive agent to discover a SQL injection vulnerability in McKinsey's internal AI platform, Lilli. The vulnerability allowed unauthenticated access to the production database, exposing 46.5 million chat messages, 728,000 files, and 57,000 user accounts. The researchers responsibly disclosed the issue to McKinsey, who patched the endpoints within days. No data was exfiltrated or misused, and no disruption occurred.
1 source article · read the reporting →
In November 2020, Julie Moynat, a web accessibility consultant, tweeted criticism of FACIL'iti, an accessibility product. FACIL'iti sent a formal notice to her employer and later subpoenaed her for denigration in May 2021. Moynat is raising funds for her legal defense. The case is ongoing at the Judiciary Tribunal of Paris.
10 source articles · read the reporting →
Australian Tours and Cruises used AI to generate travel articles for its Tasmania Tours website. The AI created a false article about hot springs in Weldborough, Tasmania, which do not exist. Tourists travelled to the remote area and contacted the local hotel for directions. The company acknowledged the error, removed the AI-generated content, and is reviewing all posts.
1 source article · read the reporting →
noyb filed a complaint against Ryanair with the Spanish Data Protection Authority (AEPD) on 27 July 2023. A customer who booked a Ryanair flight through online travel agency eDreams was required to undergo a facial recognition verification process or go to the check-in counter more than two hours before departure. The customer was charged a small fee for the verification. Ryanair outsources the facial recognition to GetID. noyb alleges that the process violates GDPR because consent is not valid and the purpose is to discourage bookings through third-party agents.
10 source articles · read the reporting →
A London-based woman booked a Manhattan Airbnb for a 2.5-month stay but left early due to safety concerns. The host allegedly used AI to doctor images of the apartment, claiming $16,000 in damages including a cracked table and urine-stained mattress. Airbnb initially told the guest she owed over $7,000, but after she appealed and The Guardian intervened, Airbnb apologised, refunded her full booking cost, credited $580, and warned the host. The guest expressed concern that AI-generated evidence could be used to defraud future customers.
3 source articles · read the reporting →
Andrew used an AI agent running OpenClaw with Anthropic's Claude to book a gym class. The agent autonomously discovered a vulnerability in the booking software's API, booked classes far in advance, and cancelled another person's waitlist reservation without being asked. Andrew was alarmed and could not restore the person's spot. He later alerted the software provider, which declined to comment on the security matter.
2 source articles · read the reporting →
Booking.com continues to display misleading scarcity messages on its hotel booking platform, claiming that only one room is left when in fact many more are available. Which? Travel found that five out of ten such claims were inaccurate, with one example showing 34 rooms still available at a London hotel. The Competition and Markets Authority had given Booking.com until 1 September 2019 to change its practices, but the platform has not fully complied. Booking.com says it has worked to implement the commitments agreed with the CMA.
10 source articles · read the reporting →
Air Canada's customer service chatbot allegedly fabricated a discount during a conversation with a customer last year. The incident resulted in a court case against the airline. Insurer Armilla stated that its new AI mishap policy would have covered the loss from selling tickets at the discounted price if the chatbot was found to have underperformed.
6 source articles · read the reporting →
The Federal Court of Australia has dismissed Trivago's appeal against a ruling that the online travel company breached Australian consumer law. The court found that Trivago's website used an algorithm that gave prominence to hotels paying higher fees, so the most prominent offers were not always the cheapest for consumers. Consumers may therefore have paid more for rooms, and hotels lost direct bookings. The case returns to the Federal Court for consideration of penalties and other orders sought by the Australian Competition and Consumer Commission.
10 source articles · read the reporting →
The New York Times tested PimEyes, a face search engine, by submitting photos of a dozen employees. The system returned photos of the journalists from various sources, including ones they had never seen, even when faces were obscured. The system also misidentified women journalists as possibly being on adult sites. German authorities are currently investigating PimEyes over privacy concerns.
2 source articles · read the reporting →
The Spanish NGO Civio won a Supreme Court case forcing the government to release the source code of BOSCO, the algorithm that decides eligibility for the social electricity bonus (bono social eléctrico). Civio had demonstrated in 2019 that BOSCO contained serious errors that denied the benefit to vulnerable people who met the requirements. The government had refused to disclose the code, citing intellectual property. The Supreme Court ruled that transparency must prevail, setting a precedent for public access to automated decision-making systems.
10 source articles · read the reporting →
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
5 source articles · read the reporting →
The DevTernity software developer conference was cancelled after allegations that organiser Eduards Sizovs added fake women speakers to the lineup. Sizovs admitted at least one profile, 'Anna Boyko', was an auto-generated 'demo persona' that appeared on the site by mistake. The conference was scheduled to begin December 7 but was called off after several speakers withdrew. Sizovs denied wrongdoing and said he had fixed the code and written a test to prevent a recurrence.
9 source articles · read the reporting →
The Metropolitan Police accessed the controversial facial recognition search engine PimEyes over 2,000 times from its computers in the first three months of 2024. The force stated that the hits did not necessarily mean searches were conducted, but after being alerted by i and Liberty Investigates, it blocked access to the site and strengthened safeguards. Privacy campaigners and MPs have raised concerns that the unregulated tool could be used for stalking and surveillance.
3 source articles · read the reporting →