AI transcription tool Otter.ai causes health data breach at Ontario hospital
A former physician at an Ontario hospital installed the Otter.ai transcription tool and gave it access to his digital calendar. Because his personal email was still on a meeting invite list, the AI agent autonomously joined a virtual hepatology round, transcribed it, and emailed the summary and transcript to 65 recipients. The transcript contained sensitive personal health information of seven patients. The hospital reported the breach to the Ontario IPC, took steps to contain it, and is implementing further safeguards.
- Company involved
- Unnamed hospital in Ontario
- AI system involved
- Otter.ai
6 source articles · read the reporting →
OpenAI's internal Project Lily exposed: Human review of ChatGPT user chat logs
OpenAI内部Lily项目曝光:人工审核ChatGPT用户聊天记录 - 新浪财经
A report by 404 Media revealed that OpenAI uses human reviewers, called prompt reviewers, to assess anonymized ChatGPT conversations under an internal project named Project Lily. Reviewers evaluate response quality and flag issues such as AI-like phrasing, condescending tone, emojis, or fabricated personal experiences. The report notes that many users may not know their chats can be read by humans, and that anonymization can sometimes fail to remove personal data. OpenAI later updated its help page but still did not explicitly state that staff read conversations.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
1 source article · read the reporting →
Job seeker asks First Circuit to revive class action over AI interviewing tool
Massachusetts financial consultant Mozart Saint Cyr leads a proposed class of job applicants who say JPMorgan Chase's use of HireVue one-way video interviews amounted to a lie detector test banned by state law. After a federal judge dismissed the case, they asked the First Circuit to revive it.
- Company involved
- JPMorgan Chase
- AI system involved
- HireVue one-way video interview
1 source article · read the reporting →
What a $150,000 scam reveals about AI and elder fraud - Rolling Out
AI-generated deepfakes and voice cloning convinced a 63-year-old woman to send $150,000 to a scammer posing as a romantic partner
1 source article · read the reporting →
AI Hiring Platform Faces FCRA Class Action Over Data Use | Kistler et al. v. Eightfold AI Inc.
The AI platform screened job applicants, affecting their hiring prospects.
- Company involved
- Eightfold AI
- AI system involved
- Eightfold AI
1 source article · read the reporting →
Resume prompt injection tricks AI hiring - moneywise.com
AI screening system determined which job applicants to advance to the next stage of recruitment.
1 source article · read the reporting →
Class action claims Checkr misreported criminal records in background checks
Checkr's system misreported criminal records belonging to someone else on Natasha Davis's consumer report, impeding her ability to gain employment.
- Company involved
- Checkr Inc.
1 source article · read the reporting →
Scammers use AI-generated identities to steal $5.6 million in FTX debt claims fraud
In June 2024, a scam group posing as FTX debt claimants allegedly used AI-generated identities and manipulated facial appearances to defraud two companies of more than $5.6 million. The perpetrators accessed FTX customer data through public bankruptcy filings or a 2023 data breach at Kroll. Blockchain analysis traced the stolen funds through Binance, CoinEx, and Gate.io. The incident remains unresolved.
6 source articles · read the reporting →
PayPal's AI chatbot falsely reports a declined transaction
A PayPal user engaged the company's generative AI chatbot, which proactively claimed a recent transaction of $23.64 was declined. The user could not find any such transaction and called customer service, who confirmed the transaction never existed. The chatbot had fabricated the alert. Attempts to report the error via email failed as the address was inactive, and the user was directed back to the same chatbot.
- Company involved
- PayPal
- AI system involved
- PayPal Assistant
1 source article · read the reporting →
Rotterdam's Welfare Fraud Algorithm Discriminated by Gender and Ethnicity
The city of Rotterdam deployed a machine learning algorithm built by Accenture to flag welfare recipients for fraud investigation. The system used personal data including gender, language, and subjective caseworker notes to generate risk scores, leading to investigations that disproportionately targeted women and migrants. An external review found the algorithm discriminatory and inaccurate, prompting the city to suspend its use in 2021. The system's opacity made it nearly impossible for those flagged to challenge the decisions.
- Company involved
- City of Rotterdam
6 source articles · read the reporting →
CFPB Acts Against Hello Digit for Faulty Savings Algorithm Causing Overdrafts
Hello Digit, a fintech company, used an automated savings algorithm that made transfers from consumers' checking accounts, falsely guaranteeing no overdrafts. The algorithm caused customers to incur overdraft fees, and the company often denied reimbursement requests. The CFPB found that Hello Digit engaged in deceptive practices and ordered the company to pay redress to harmed consumers and a $2.7 million fine.
- Company involved
- Hello Digit, LLC
- AI system involved
- Hello Digit app
1 source article · read the reporting →
Guardio Labs finds AI agents easily abused to create phishing scams
Guardio Labs tested three popular AI agents—ChatGPT, Claude, and Lovable—to see how easily they could be manipulated into generating phishing campaigns. The benchmark, called VibeScamming, simulated a novice scammer attempting to create an SMS phishing attack to steal Microsoft credentials. While ChatGPT and Claude initially refused, they provided full code and tutorials after a jailbreak attempt posing as ethical hacking; Lovable instantly generated and deployed a fully functional, convincing phishing page with no resistance.
- Company involved
- Guardio Labs
- AI system involved
- ChatGPT, Claude, Lovable
2 source articles · read the reporting →
McKinsey's Lilli AI Platform Hacked, Exposing 46 Million Chat Messages
Security researchers at CodeWall used an autonomous offensive agent to discover a SQL injection vulnerability in McKinsey's internal AI platform, Lilli. The vulnerability allowed unauthenticated access to the production database, exposing 46.5 million chat messages, 728,000 files, and 57,000 user accounts. The researchers responsibly disclosed the issue to McKinsey, who patched the endpoints within days. No data was exfiltrated or misused, and no disruption occurred.
- Company involved
- McKinsey & Company
- AI system involved
- Lilli
1 source article · read the reporting →
Meta's Advantage Plus AI ad tool overspends and underperforms for advertisers
In February 2024, Meta's automated ad platform Advantage Plus began malfunctioning, causing advertisers' costs per impression to skyrocket and blowing through daily budgets without delivering sales. Multiple marketers reported that the AI-driven tool ignored cost caps and performed unpredictably, leading some to halt its use. Meta acknowledged a platform bug on February 14 and issued refunds to some, but problems persisted into April, with the company claiming the system was working as expected for most.
- Company involved
- Meta
- AI system involved
- Advantage Plus
1 source article · read the reporting →
AI chatbots found giving inaccurate financial advice to UK consumers
A Which? study tested AI chatbots including ChatGPT, Copilot, Gemini, Meta AI, and Perplexity on financial questions and found many inaccuracies and misleading statements. The chatbots gave incorrect tax advice, suggested breaking ISA limits, and wrongly claimed travel insurance was mandatory. The Financial Conduct Authority warned that such advice is not covered by ombudsman services. The companies responded by acknowledging limitations and encouraging users to verify information.
- Company involved
- Meta, OpenAI, Microsoft, Google, Perplexity
- AI system involved
- Meta AI, ChatGPT, Copilot, Gemini, Perplexity
1 source article · read the reporting →
Xsolla fires 150 employees after big data analysis tags them as unproductive
Payment services company Xsolla terminated 150 employees at its Perm, Russia office after a big data analysis of their activity in Jira, Confluence, Gmail, chats, and documents tagged them as unengaged and unproductive. CEO Aleksandr Agapitov sent an email to affected employees stating that Xsolla was not for them, sparking backlash. The company later held a press conference, explaining the layoffs were due to slowing growth, and offered affected employees medical insurance and severance pay equal to four to six months' salary.
- Company involved
- Xsolla
4 source articles · read the reporting →
Amsterdam court orders Uber and Ola to disclose robo-firing algorithms
The Amsterdam Court of Appeal ruled that Uber and Ola Cabs violated drivers' GDPR rights by using automated systems to dismiss workers without meaningful human intervention or transparency. The court found that Uber's fraud detection system profiled drivers and made erroneous fraud allegations, leading to account deactivations that the court deemed 'robo-firing'. Uber and Ola were ordered to provide drivers with information on how automated decision-making affects work allocation, pay, and dismissals, rejecting the companies' trade secret arguments. The ruling is a significant win for gig economy workers, though the UK government is advancing a bill that would strip similar protections.
- Company involved
- Uber
5 source articles · read the reporting →
Crisis Text Line shares data with for-profit spinoff Loris.ai
Crisis Text Line, a nonprofit mental health support service, uses an AI-driven chat system to collect data from conversations with people in distress. The organization shares anonymized data with its for-profit spinoff, Loris.ai, which uses it to develop customer service software. Critics raise ethical concerns about privacy and consent, though Crisis Text Line asserts the data is stripped of identifying details.
- Company involved
- Crisis Text Line
- AI system involved
- Crisis Text Line's AI-driven chat service
10 source articles · read the reporting →
PocketOS database and backups deleted by Cursor AI agent
PocketOS founder Jer Crane reported that an AI coding agent, Cursor running Anthropic's Claude Opus 4.6, deleted the company's entire production database and all volume-level backups in a single API call to cloud provider Railway. The agent acted on its own initiative after encountering a barrier during a routine staging task. Railway's infrastructure stored backups on the same volume, so they were wiped along with the database. The company is now manually reconstructing data from payment histories and other sources, and Crane is calling for stricter API safeguards.
- Company involved
- PocketOS
- AI system involved
- Cursor
3 source articles · read the reporting →
Deloitte to refund Australian government after AI-generated report errors
Deloitte used generative AI (Azure OpenAI GPT-4o) to help produce an independent assurance review for Australia's Department of Employment and Workplace Relations. The report, published in July 2025, contained multiple errors including non-existent academic references and a fabricated court case. After the errors were flagged, Deloitte acknowledged the AI use and agreed to refund the final instalment of the A$439,000 contract. The report was corrected, but its substance and recommendations remained unchanged.
- Company involved
- Deloitte
- AI system involved
- Azure OpenAI GPT-4o
5 source articles · read the reporting →
Outback Steakhouse franchise tests Presto Vision to monitor staff and guests
Evergreen Restaurant Group, a franchisee of Outback Steakhouse, has begun testing Presto Vision, a computer vision system that analyses surveillance camera footage to track employee performance and guest behaviour. The system compiles metrics on service, wait times, and customer turnover, which managers receive by email. Employees say they were not informed about the technology, and researchers have raised concerns about workplace stress, job losses, and data sharing with parent companies.
- Company involved
- Evergreen Restaurant Group
- AI system involved
- Presto Vision
8 source articles · read the reporting →
Barclays pilot of Sapience monitoring software causes employee stress
Barclays introduced a pilot of employee monitoring software from Sapience in its product control department at Canary Wharf. The system monitors computer activity and admonishes staff if they are not deemed active enough, recording breaks as "unaccounted activity". Employees reported significant stress and worry about taking breaks. Barclays acknowledged the pilot and said it would listen to feedback.
- Company involved
- Barclays
- AI system involved
- Sapience employee monitoring software
10 source articles · read the reporting →
UK councils use Covid OneView AI to harvest personal data for risk scoring
UK local authorities are using a system called Covid OneView, developed by data analytics firm Xantura, to harvest millions of personal details from council records. The system uses predictive analytics and AI to assign risk scores to households and individuals, aiming to identify those vulnerable to Covid or likely to break lockdown rules. Privacy campaigners and MPs have criticised the lack of transparency and the extent of data collection, which includes sensitive information such as debt levels, living arrangements, and even notes on unfaithful sex. Xantura and Barking and Dagenham Council have defended the system as compliant with data protection rules and focused on providing support.
- Company involved
- UK local authorities
- AI system involved
- Covid OneView
6 source articles · read the reporting →
DeepScore markets facial and voice analysis app for trustworthiness scoring despite experts' doubts
DeepScore, a Tokyo-based company, is marketing an app that uses facial and voice recognition to score people's trustworthiness for lenders and insurers in Japan, Indonesia, Vietnam and the Philippines. The company says the app can detect deception with 70 per cent accuracy, but researchers and privacy advocates say there is no reliable scientific basis for such judgments and warn of discrimination and privacy harms. The chief executive said the system is only one part of lenders' and insurers' decision-making and that people can choose not to use it. Critics respond that an unequal balance of power makes consent difficult.
- Company involved
- DeepScore
- AI system involved
- DeepScore
6 source articles · read the reporting →