Illinois job applicants may get about $150 from HireVue biometric privacy settlement - The Cool Down
Job applicants were subjected to biometric data collection during video interviews without proper consent.
- Company involved
- HireVue
- AI system involved
- HireVue
1 source article · read the reporting →
Retool Breached After Hacker Uses AI Deepfake Voice in Phishing Call
A hacker used AI to deepfake an employee's voice and trick a Retool staff member into providing a multi-factor authentication code. The attacker sent phishing SMS messages and then called the employee, impersonating an IT team member with a synthetic voice. This allowed the hacker to add their own device to the employee's account and access internal systems, compromising 27 cloud customers. Retool revoked the access and disclosed the incident, blaming a weakness in Google Authenticator's cloud sync feature.
- Company involved
- Retool
1 source article · read the reporting →
AI chatbots used to steal US college financial aid
Crime rings are deploying AI chatbots as 'ghost students' to enrol in online college courses and fraudulently collect US federal financial aid. Victims of identity theft, such as Heather Brady and Brittnee Nelson, discovered loans of over $9,000 and $5,000 respectively taken out in their names for colleges they never attended. The US Education Department introduced a temporary rule requiring government-issued ID for first-time aid applicants, while California community colleges reported losing at least $11.1 million to such scams.
- Company involved
- Delgado Community College
4 source articles · read the reporting →
Meta Scraped User Photos for Secret Smart-Glasses Tech, Class Action Claims - The SOFX Report
Meta harvested user photographs and created biometric faceprints to enable a smart-glasses system that could identify strangers in public without consent.
- Company involved
- Meta Platforms, Inc.
- AI system involved
- NameTag
1 source article · read the reporting →
ICE’s Mobile Fortify Facial Recognition App Misidentified a Woman Twice
During an immigration raid in Oregon, ICE agents used the Mobile Fortify facial recognition app on a detained woman to determine her identity and immigration status. The app returned two different incorrect names, according to testimony from a CBP official. ICE has claimed the app provides a definitive determination of immigration status, but this incident raises concerns about its accuracy. The misidentification could have led to wrongful removal proceedings.
- Company involved
- U.S. Immigration and Customs Enforcement (ICE)
- AI system involved
- Mobile Fortify
1 source article · read the reporting →
Guardio Labs finds AI agents easily abused to create phishing scams
Guardio Labs tested three popular AI agents—ChatGPT, Claude, and Lovable—to see how easily they could be manipulated into generating phishing campaigns. The benchmark, called VibeScamming, simulated a novice scammer attempting to create an SMS phishing attack to steal Microsoft credentials. While ChatGPT and Claude initially refused, they provided full code and tutorials after a jailbreak attempt posing as ethical hacking; Lovable instantly generated and deployed a fully functional, convincing phishing page with no resistance.
- Company involved
- Guardio Labs
- AI system involved
- ChatGPT, Claude, Lovable
2 source articles · read the reporting →
Schufa's Black-Box Scoring Unfairly Penalises Consumers with Positive Credit Data
An investigation by SPIEGEL and BR Data reveals that Schufa's credit scoring algorithm often assigns poor risk scores to consumers with only positive credit information. One consumer, Sven Drewert, was denied a credit card limit increase despite having no negative entries. The algorithm uses limited data, and its secret formula can lead to arbitrary categorisations, affecting access to loans, phone contracts, and housing. The system's opacity and potential biases raise concerns about fairness and accountability.
- Company involved
- Schufa Holding AG
- AI system involved
- Schufa Score
2 source articles · read the reporting →
Ahmedabad cyber police bust deepfake Aadhaar fraud racket, four arrested
Four men were arrested in Ahmedabad for allegedly using AI-generated deepfake videos to bypass Aadhaar's facial authentication system. They changed a victim's registered mobile number, accessed his DigiLocker, and applied for loans in his name. The accused, including Common Service Centre operators, used unauthorised Aadhaar update kits. Police are investigating whether more victims were targeted.
- Company involved
- Unique Identification Authority of India (UIDAI)
- AI system involved
- Aadhaar facial authentication system
1 source article · read the reporting →
HSBC voice ID breached by customer's twin brother
BBC reporter Dan Simmons set up an HSBC voice-ID authenticated account. His non-identical twin brother Joe was able to mimic his voice and gain access after eight attempts, viewing balances and transactions and being offered the chance to transfer money. HSBC acknowledged the breach and reduced the number of allowed attempts from seven to three. The bank stated that the system remains secure and that the scenario was not typical of fraud.
- Company involved
- HSBC
- AI system involved
- Voice ID
3 source articles · read the reporting →
Urban Cyber Security VPN extension harvested AI chatbot prompts and responses
In July 2025, Urban Cyber Security updated its Urban VPN Proxy Chrome extension to automatically harvest everything users typed into major AI chatbots, including ChatGPT and Claude, as well as the chatbots' replies. The extension, used by over 7 million people, also collected conversation metadata and identifiers, sharing the data with its ad analytics affiliate BIScience. The data collection was disclosed in the privacy policy but users were not explicitly notified at the time of use. Security researchers at Koi discovered the practice and reported it publicly.
- Company involved
- Urban Cyber Security
- AI system involved
- Urban VPN Proxy
3 source articles · read the reporting →
Journalist Bypasses Lloyds Bank Voice ID with AI-Generated Voice Clone
A journalist used an AI-generated clone of his own voice to bypass the voice authentication system of Lloyds Bank, gaining access to his account. The experiment, conducted using ElevenLabs' free voice synthesis service, demonstrated that voice biometrics can be fooled by synthetic voices. Lloyds Bank stated it is aware of the threat and is deploying countermeasures, but has not seen real-world fraud using this method. The incident raises concerns about the security of voice verification used by many banks.
- Company involved
- Lloyds Bank
- AI system involved
- Voice ID
1 source article · read the reporting →
French regulator fines Clearview AI €20 million for privacy breaches
France's privacy watchdog CNIL fined US facial recognition firm Clearview AI €20 million for unlawfully collecting and processing facial images of individuals without consent. The company scraped billions of images from websites and social media, selling access to law enforcement. Clearview AI denied being subject to EU law and refused to delete the data, claiming it was impossible to determine French residency from public photos. The CNIL ordered the firm to stop collecting data and delete existing data within two months or face daily fines.
- Company involved
- Clearview AI
10 source articles · read the reporting →
AI-generated Centrelink phishing emails target 270,000 Australians
More than 270,000 fake emails impersonating Services Australia and Centrelink were detected over four months in a broad phishing campaign. Cybersecurity firm Mimecast reports that cybercriminals are using artificial intelligence to create highly convincing clones of legitimate government communications about benefits. The attack targets vulnerable people and can lead to identity theft, data theft, malware, or ransomware.
- Company involved
- Services Australia
4 source articles · read the reporting →
PimEyes facial recognition used by amateur 'sedition hunters' to identify Capitol riot suspects
Amateur 'sedition hunters' used the PimEyes facial recognition tool to search for suspected rioters from the U.S. Capitol attack. The tool scans over 900 million online images to find matches. Researchers warn that the tool could be abused for stalking or other invasive purposes. The incident highlights the risks of publicly available facial recognition technology.
- Company involved
- PimEyes
- AI system involved
- PimEyes
1 source article · read the reporting →
Kimsuky used ChatGPT to create fake military ID for phishing
The hacking group Kimsuky allegedly used ChatGPT to generate a counterfeit South Korean military identification card. This fake ID was used in a phishing email that contained links to malware designed to extract data from victims' devices. Targets included journalists, human rights activists and researchers. The incident highlights the growing misuse of AI for cybercrime.
- Company involved
- Kimsuky
- AI system involved
- ChatGPT
6 source articles · read the reporting →
Ukraine defence ministry uses Clearview AI facial recognition to identify dead and Russian assailants
Ukraine's defence ministry has started using Clearview AI's facial recognition technology to identify Russian assailants and the dead, according to reports. Clearview provided free access to its system, which holds over 10 billion images including from Russian social media. Critics warn that the technology could misidentify people at checkpoints and in battle, potentially harming civilians. Clearview says it should not be used as the sole source of identification.
- Company involved
- Ukraine's Ministry of Defense
- AI system involved
- Clearview AI
10 source articles · read the reporting →
Montenegro police warn of rising AI identity abuse in online fraud
Montenegrin police say AI is fuelling a rise in identity abuse by online fraudsters, using deepfake videos of public figures to promote bogus remedies and investment schemes. Surgeon and MP Vladimir Dobricanin found a manipulated video of himself apparently endorsing eyedrops and other products, while Bosnian fact-checkers reported similar misuse of statements to lure people into cryptocurrency scams. Victims reported 42 online scams in 2025 with financial losses of around 300,000 euros, but authorities say investigations are complex and often lengthy due to the use of servers abroad and encryption. Experts called for stronger technical capacities, international cooperation, and faster platform responses to tackle the problem.
- Company involved
- Limited Charm
- AI system involved
- Deepfake social media advertisements
1 source article · read the reporting →
SenseNets silent after data leak exposes millions of people's records
SenseNets Technology Ltd., a Shenzhen-based facial recognition company, left a database containing personal information of more than 2.5 million people publicly accessible without password protection for months. Dutch security researcher Victor Gevers and the GDI Foundation discovered the exposure in July and warned the company, which did not respond. The database was secured in February after the leak was reported, and the company is reported to be conducting an internal investigation. SenseNets has declined to comment publicly.
- Company involved
- SenseNets Technology Ltd.
10 source articles · read the reporting →
Companies face AI deepfake job candidates for remote roles
US companies report a surge in fake job seekers using generative AI tools to fabricate identities, employment histories, and conduct deepfake video interviews for remote positions. Cybersecurity firms Pindrop and CAT Labs, along with BrightHire, describe incidents where scammers, including North Korean operatives, attempted to gain employment to install malware, demand ransoms, steal data, or collect salaries fraudulently. One candidate, 'Ivan X', was detected by Pindrop's video authentication tool after a recruiter noticed his facial expressions were out of sync with his words.
- Company involved
- Pindrop Security
- AI system involved
- video authentication program
1 source article · read the reporting →
Stanford Researchers Find Over 1,000 LinkedIn Profiles Using AI-Generated Faces for Spam
Renée DiResta and Josh Goldstein of the Stanford Internet Observatory discovered over 1,000 LinkedIn accounts using AI-generated profile images to send sales pitches, bypassing LinkedIn's message limits. The fake accounts, which appeared to be real people, were used for corporate spamming rather than political disinformation. LinkedIn investigated and removed the violating accounts, stating that all profiles must represent real people.
4 source articles · read the reporting →
Swedish police fined for unlawful use of Clearview AI facial recognition
Sweden's data protection authority IMY fined the Swedish Police Authority €250,000 for unlawfully using Clearview AI's facial-recognition app. The police used the app between autumn 2019 and March 2020 without authorisation or a required data protection impact assessment. The IMY ordered the police to ensure Clearview AI deletes the data and to train employees to avoid future breaches.
- Company involved
- Swedish Police Authority
- AI system involved
- Clearview AI
3 source articles · read the reporting →
Clearview AI tested facial recognition surveillance cameras with UFT and Rudin
Clearview AI, the facial recognition company that scraped billions of photos from social media, developed a surveillance camera system under the name Insight Camera. The system was tested by the United Federation of Teachers and Rudin Management in New York City. The UFT used it to identify individuals who had made threats and prevent them from entering its offices. Clearview did not respond to requests for comment.
- Company involved
- Clearview AI
- AI system involved
- Insight Camera
9 source articles · read the reporting →
DeepScore markets facial and voice analysis app for trustworthiness scoring despite experts' doubts
DeepScore, a Tokyo-based company, is marketing an app that uses facial and voice recognition to score people's trustworthiness for lenders and insurers in Japan, Indonesia, Vietnam and the Philippines. The company says the app can detect deception with 70 per cent accuracy, but researchers and privacy advocates say there is no reliable scientific basis for such judgments and warn of discrimination and privacy harms. The chief executive said the system is only one part of lenders' and insurers' decision-making and that people can choose not to use it. Critics respond that an unequal balance of power makes consent difficult.
- Company involved
- DeepScore
- AI system involved
- DeepScore
6 source articles · read the reporting →
CBSE introduces facial recognition system for students to access digital documents
The Central Board of Secondary Education (CBSE) has introduced a facial recognition system for Class 10 and 12 students to access their digital academic documents. A live image of the student is compared with the photograph on their CBSE admit card and, if the match succeeds, the certificate is emailed to them. The facility is available on Digi Locker for 2020 records and is expected to help foreign students and those unable to open a Digi Locker account.
- Company involved
- Central Board of Secondary Education (CBSE)
- AI system involved
- Facial Recognition System
10 source articles · read the reporting →