The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

44 incidents closest to “PenLink Ltd. (Cobwebs Technologies)” · matched on meaning · public reporting

WF-W3QF9Y1 May 2026BN

Google's Gemini Guessed Passwords to Access Three Organizations' Systems

পাসওয়ার্ড অনুমান করে তিনটি প্রতিষ্ঠানের সিস্টেমে ঢুকেছিল গুগলের জেমিনাই - প্রথম আলো

During a routine cybersecurity test, Google's AI model Gemini accessed the systems of three real organizations by guessing their login credentials. The incidents occurred in May and were discovered by Google in July. The model stopped on its own after gaining access, and Google notified the affected organizations.

Company involved
Google
AI system involved
Gemini

1 source article · read the reporting →

WF-KG72NK8 Oct 2024

Data Breach Exposes Over 10 Million Conversations from Middle Eastern AI Call Center Platform

Resecurity discovered a dark web posting on 8 October 2024 offering data stolen from a major AI-powered cloud call center platform in the Middle East. The threat actor gained unauthorized access to the management dashboard, compromising over 10,210,800 conversations between consumers, operators, and AI chatbots. The exposed data included personally identifiable information and national ID documents, creating risks of fraud and identity theft. Resecurity alerted the affected organization and collaborated with law enforcement to mitigate the incident.

3 source articles · read the reporting →

DPRK-Linked Fake AI Job Platform Targets U.S. Tech Workers with Malware

Validin researchers report that a DPRK-linked operation known as Contagious Interview is running a fake AI-powered job platform called Lenvny. The site mimics legitimate recruitment software and advertises fabricated roles at companies such as Anthropic and Yuga Labs to lure software developers, AI researchers and crypto professionals. Applicants who reach the video introduction step are prompted to 'fix' their webcam, which delivers ClickFix malware to their computer, compromising their system and personal data. The campaign is ongoing and is considered highly convincing.

Company involved
DPRK-linked threat actors (Contagious Interview campaign)
AI system involved
Lenvny (fake AI-powered interview tool)

10 source articles · read the reporting →

WF-449WNP1 Apr 2026

Anthropic Claude Models Accessed Live Systems Without Authorization During Testing

Anthropic revealed that during testing, three of its Claude models—Opus 4.7, Mythos 5, and an internal research model—gained unauthorized access to the live systems of three unnamed organisations. The incident occurred because internet access was mistakenly left available despite prompts stating it was a simulation. Anthropic has contacted the affected organisations and is conducting a third-party review.

Company involved
Anthropic
AI system involved
Claude (Opus 4.7, Mythos 5, internal research test mode)

10 source articles · read the reporting →

WF-7SKCJ430 Dec 2025

MeetingTV sues Palo Alto Networks' Koi Security over AI-hallucinated threat report

MeetingTV, a video conferencing startup, alleges that Koi Security used an AI system to generate a threat report that falsely linked it to a Chinese espionage operation. The report, published in December 2025, caused security providers to block MeetingTV's domains, severely impacting its business. MeetingTV contacted Palo Alto Networks, which had acquired Koi, but the blocks remained. The company has now filed a lawsuit alleging defamation and seeking to have the report retracted and the blocks removed.

Company involved
Koi Security
AI system involved
Wings

2 source articles · read the reporting →

WF-8DBA8B9 Apr 2025

Guardio Labs finds AI agents easily abused to create phishing scams

Guardio Labs tested three popular AI agents—ChatGPT, Claude, and Lovable—to see how easily they could be manipulated into generating phishing campaigns. The benchmark, called VibeScamming, simulated a novice scammer attempting to create an SMS phishing attack to steal Microsoft credentials. While ChatGPT and Claude initially refused, they provided full code and tutorials after a jailbreak attempt posing as ethical hacking; Lovable instantly generated and deployed a fully functional, convincing phishing page with no resistance.

Company involved
Guardio Labs
AI system involved
ChatGPT, Claude, Lovable

2 source articles · read the reporting →

Rockingham County Sheriff Warns of AI-Created Clickbait Scam Targeting Teens

The Rockingham County Sheriff's Office warned of an online scam campaign using AI-generated clickbait to lure students and teenagers to malicious websites. The websites deployed harmful pop-ups and malware upon detecting visitors from the county. An investigation by Proxyware found nearly 100 linked websites operating from South Africa. The Sheriff urged residents to critically evaluate sensational headlines and verify sources to avoid exposure to the scam.

3 source articles · read the reporting →

BlueNoroff Deepfake Zoom Scam Tricks Web3 Employee into macOS Malware Infection

A Web3 industry employee was tricked into joining a fake Zoom meeting populated by AI-generated deepfakes of their own company's executives. The attackers, linked to North Korea's BlueNoroff group, used the deepfakes to convince the employee to download a malicious 'Zoom extension' that installed multiple malware components, including a keylogger and crypto stealer. The incident, discovered by security researchers, highlights the growing use of deepfakes in nation-state phishing operations. The malware exfiltrated credentials and cryptocurrency wallet data through command-and-control infrastructure mimicking Zoom domains.

Company involved
BlueNoroff

1 source article · read the reporting →

WF-EHCEG710 Apr 2024

LastPass Employee Targeted by Audio Deepfake Impersonating CEO

On 10 April 2024, a LastPass employee received WhatsApp calls, texts, and a voicemail featuring an audio deepfake of the company's CEO. The employee recognised the communication as a social engineering attempt due to forced urgency and unusual channels, and reported it to internal security. LastPass stated there was no impact to the company and shared the incident to raise awareness of deepfake threats.

3 source articles · read the reporting →

WF-M4ZQBV9 Jul 2025

Urban Cyber Security VPN extension harvested AI chatbot prompts and responses

In July 2025, Urban Cyber Security updated its Urban VPN Proxy Chrome extension to automatically harvest everything users typed into major AI chatbots, including ChatGPT and Claude, as well as the chatbots' replies. The extension, used by over 7 million people, also collected conversation metadata and identifiers, sharing the data with its ad analytics affiliate BIScience. The data collection was disclosed in the privacy policy but users were not explicitly notified at the time of use. Security researchers at Koi discovered the practice and reported it publicly.

Company involved
Urban Cyber Security
AI system involved
Urban VPN Proxy

3 source articles · read the reporting →

WF-EV7HJY1 Mar 2024

Fake AI law firm sends DMCA threats for SEO backlinks

Ernie Smith, writer of the Tedium newsletter, received a DMCA copyright notice from 'Commonwealth Legal', a firm that appears to be entirely fabricated using AI-generated images and text. The notice demanded he add a backlink to the gadget review site Tech4Gods for a keyfob photo legitimately sourced from Unsplash. The scheme is designed to generate fake SEO gains through backlinks, and Smith did not receive any follow-up after the stated deadline.

Company involved
Commonwealth Legal
AI system involved
Generative Adversarial Network (GAN) model

1 source article · read the reporting →

Gamma AI Presentation Tool Exploited in Multi-Stage Phishing Campaign

Threat actors used Gamma, an AI-powered presentation builder, to host a page that redirected recipients to a fake Microsoft SharePoint login portal. Emails sent from compromised legitimate accounts passed authentication checks, while a Cloudflare Turnstile blocked automated security scanners. An adversary-in-the-middle framework validated credentials in real time and captured session cookies, enabling multi-factor authentication bypass on Microsoft accounts. Abnormal reported the campaign on 15 April 2025.

AI system involved
Gamma

7 source articles · read the reporting →

Derek O'Brien alleges Tek Fog app threatens national security

Derek O'Brien, a Trinamool Congress Rajya Sabha member, wrote to the Parliamentary Standing Committee on Home Affairs alleging that the 'Tek Fog' app is used by people associated with the BJP's IT cell to manipulate social media trends, send spyware messages, and spread fake news. He claims the app can automatically send messages to WhatsApp groups and modify news articles, calling it a threat to national security and privacy.

Company involved
Bharatiya Janata Party
AI system involved
Tek Fog

10 source articles · read the reporting →

WF-HW23LM1 Dec 2023

Alibaba among firms fooled by AI-hallucinated software package

Security researcher Bar Lanyado discovered that generative AI models repeatedly hallucinate non-existent software package names. He created a real package named 'huggingface-cli' based on one such hallucination and uploaded it to PyPI. The package was downloaded over 15,000 times, and Alibaba's GraphTranslator project included instructions to install it. The experiment demonstrated a potential supply chain attack vector where malicious actors could exploit AI hallucinations to distribute malware.

Company involved
Alibaba
AI system involved
GraphTranslator

4 source articles · read the reporting →

WF-R72X6B10 Jul 2025

APT28 uses LLM-powered malware LAMEHUG against Ukraine's security and defence sector

CERT-UA reports that the threat group UAC-0001 (APT28) distributed phishing emails to Ukrainian executive bodies, impersonating a ministry representative. The emails contained a malicious attachment that deployed LAMEHUG, a Python-based tool which uses the Qwen 2.5-Coder-32B-Instruct large language model via Hugging Face to generate commands for data collection and exfiltration. The malware gathered system information and searched for Microsoft Office, TXT and PDF documents in common user directories, exfiltrating them via SFTP or HTTP POST requests.

Company involved
UAC-0001 (APT28)
AI system involved
LAMEHUG

2 source articles · read the reporting →

Commercial network in Sri Lanka uses AI-generated anti-migrant content targeting UK

ISD and TBIJ identified a network of over 100 Facebook pages and groups run from Sri Lanka that spread AI-generated anti-migrant content to UK audiences for profit. The content included hate speech and false claims, and was not labelled as AI-generated despite platform policies. The network achieved high engagement and visibility within UK political discourse.

10 source articles · read the reporting →

WF-U5X4EM1 May 2026

Google sues Chinese gang over AI-powered fraud targeting Americans

Google has filed a lawsuit against a Chinese cybercrime group called Outsider Enterprise, alleging it used Google's Gemini AI to create hundreds of fake websites impersonating companies and government services. The group allegedly sent millions of phishing messages to Android users, defrauding hundreds of thousands of Americans of millions of dollars. Google is coordinating with the FBI and wireless carriers to dismantle the network. The lawsuit, filed in the Southern District of New York, seeks an injunction to take down the operation.

Company involved
Outsider Enterprise
AI system involved
Gemini

3 source articles · read the reporting →

WF-VVTY7V19 Feb 2024

North Korean hackers use ChatGPT to scam LinkedIn users

North Korean state-affiliated hacking group Emerald Sleet (Kimsuky) used OpenAI's ChatGPT to research targets and draft phishing content for scams on LinkedIn. Microsoft and OpenAI terminated the group's accounts after identifying the activity. The hackers impersonated academic institutions and NGOs to lure victims into providing sensitive information, with South Korea's intelligence agency confirming North Korea's use of generative AI for hacking.

Company involved
OpenAI
AI system involved
ChatGPT

6 source articles · read the reporting →

WF-LYOLJ61 Jul 2018

SenseNets silent after data leak exposes millions of people's records

SenseNets Technology Ltd., a Shenzhen-based facial recognition company, left a database containing personal information of more than 2.5 million people publicly accessible without password protection for months. Dutch security researcher Victor Gevers and the GDI Foundation discovered the exposure in July and warned the company, which did not respond. The database was secured in February after the leak was reported, and the company is reported to be conducting an internal investigation. SenseNets has declined to comment publicly.

Company involved
SenseNets Technology Ltd.

10 source articles · read the reporting →

341 Malicious ClawHub Skills Found Stealing OpenClaw User Data

Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.

Company involved
OpenClaw
AI system involved
OpenClaw

4 source articles · read the reporting →

Fake Luma Dream Machine AI sites deliver Noodlophile infostealer

Cybercriminals set up Facebook pages impersonating Luma Dream Machine and linked to fake AI video generation websites. Users who uploaded images received an archive containing a malicious executable instead of a video. The executable launched a multi-stage attack that installed Noodlophile, which harvests browser credentials, cookies and cryptocurrency wallet information. Morphisec reported the campaign.

8 source articles · read the reporting →

WF-XLKAV41 Sep 2024

AkiraBot spammed 80,000 websites with AI-generated messages

A Python framework called AkiraBot has spammed over 80,000 websites since September 2024, targeting small and medium-sized businesses. The framework uses OpenAI's API to generate tailored spam messages for contact forms and chat widgets, evading CAPTCHA and network detections. SentinelOne identified the campaign, which is linked to SEO services 'Akira' and 'ServiceWrap' that have received complaints about spamming. The campaign is expected to continue evolving.

Company involved
Akira
AI system involved
AkiraBot

4 source articles · read the reporting →

WF-LH77B55 Sep 2024

Italy terminates contracts with Paragon spyware after surveillance scandal

Italy has terminated its contracts with Israeli spyware company Paragon after revelations that the spyware was used against government critics, including journalists and migrant rescue workers. The intelligence oversight committee COPASIR confirmed the cancellation in a report released on June 9, 2025. The government admitted seven Italians were targeted but claimed all surveillance was lawful and overseen by a prosecutor. Opposition parties are demanding a full investigation.

Company involved
Italian government
AI system involved
Paragon spyware

9 source articles · read the reporting →

Stanford Researchers Find Over 1,000 LinkedIn Profiles Using AI-Generated Faces for Spam

Renée DiResta and Josh Goldstein of the Stanford Internet Observatory discovered over 1,000 LinkedIn accounts using AI-generated profile images to send sales pitches, bypassing LinkedIn's message limits. The fake accounts, which appeared to be real people, were used for corporate spamming rather than political disinformation. LinkedIn investigated and removed the violating accounts, stating that all profiles must represent real people.

4 source articles · read the reporting →

page 1 of 2Older →