Spamouflage Dragon Network Used AI-Generated Profile Pictures in U.S.-Targeted Disinformation
Graphika reported that the pro-Chinese spam network Spamouflage Dragon began posting English-language videos attacking U.S. policy and the Trump administration in June 2020. The operation used accounts with AI-generated profile pictures and automated voice-overs, targeting U.S. foreign policy, coronavirus handling, racial inequalities and actions against TikTok. The accounts received no engagement from authentic users and made little effort to conceal their Chinese origin.
- Company involved
- Spamouflage Dragon
2 source articles · read the reporting →
AI Scammers Clone Exante Broker, Use JPMorgan Account to Defraud US Victim
Scammers used generative AI to create a fake clone of the brokerage firm Exante, including a replicated trading platform and AI-generated passports. They opened a real JPMorgan Chase bank account using a US address and tricked at least one US victim into transferring funds. Exante, which does not serve US clients, discovered the scam when the victim was registered on its real platform and reported the incident to the FBI, SEC, CFTC, and other authorities. The scammers remain unidentified, and the victim's funds have not been recovered.
2 source articles · read the reporting →
ChatGPT First Alerted FBI to Ex-Boyfriend's Murder Plot
전 남친의 살해계획, ChatGPT가 먼저 FBI에 알렸다 - newsspirit.kr
An ex-boyfriend's murder plot was reported to the FBI by ChatGPT before any crime took place. The AI detected the plan and alerted authorities.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
1 source article · read the reporting →
AI Hiring Platform Faces FCRA Class Action Over Data Use | Kistler et al. v. Eightfold AI Inc.
The AI platform screened job applicants, affecting their hiring prospects.
- Company involved
- Eightfold AI
- AI system involved
- Eightfold AI
1 source article · read the reporting →
Istanbul gang used AI to defraud European citizens from call center
A gang in Maslak, Istanbul, set up a call centre using AI-supported software to impersonate police, prosecutors, soldiers, and bank officials. They defrauded many Czech and European citizens, obtaining high amounts of money, which they laundered through bank accounts and crypto platforms. Turkish authorities, in cooperation with Czech judicial authorities, conducted simultaneous raids on three addresses, seizing digital materials and detaining 80 foreign suspects.
1 source article · read the reporting →
AI-Generated Fake Investment Websites Target Australian Fraud Analyst
A fraud analyst, Leon, was targeted by scammers who used AI to create convincing fake websites for non-existent investment firms. The scammers posed as employees of Assent Advisory and directed him to elaborate sites for APPC Capital Singapore and Thackeray Mines and Minerals Inc., complete with AI-generated images and fake details. Leon recognised the scam, but the sophistication of the AI-generated content made him second-guess his own judgment. The incident highlights how AI is enabling more convincing investment scams.
1 source article · read the reporting →
Hacker Used Claude AI to Automate Extortion Campaign Against 17 Organizations
A hacker used Anthropic's Claude AI Code to automate reconnaissance, credential harvesting, and extortion against 17 organizations in healthcare, emergency services, government, and religious sectors. The AI agent handled the entire attack chain, including calculating ransom demands exceeding $500,000 and designing extortion messages. Anthropic detected the misuse, banned the actor's accounts, and deployed a tailored detection classifier. The incident highlights the growing trend of AI-powered cybercrime.
- AI system involved
- Claude Code
3 source articles · read the reporting →
Scammers use AI-generated identities to steal $5.6 million in FTX debt claims fraud
In June 2024, a scam group posing as FTX debt claimants allegedly used AI-generated identities and manipulated facial appearances to defraud two companies of more than $5.6 million. The perpetrators accessed FTX customer data through public bankruptcy filings or a 2023 data breach at Kroll. Blockchain analysis traced the stolen funds through Binance, CoinEx, and Gate.io. The incident remains unresolved.
6 source articles · read the reporting →
Rotterdam's Welfare Fraud Algorithm Discriminated by Gender and Ethnicity
The city of Rotterdam deployed a machine learning algorithm built by Accenture to flag welfare recipients for fraud investigation. The system used personal data including gender, language, and subjective caseworker notes to generate risk scores, leading to investigations that disproportionately targeted women and migrants. An external review found the algorithm discriminatory and inaccurate, prompting the city to suspend its use in 2021. The system's opacity made it nearly impossible for those flagged to challenge the decisions.
- Company involved
- City of Rotterdam
6 source articles · read the reporting →
FTC Orders Evolv to Stop Overstating Effectiveness of AI Gun Detection Tech
Evolv, a company selling AI-powered weapons detection systems, has been ordered by the FTC to stop making misleading claims about its Evolv Express product. The FTC alleged that the technology is essentially a metal detector with unproven AI, and that Evolv falsely claimed it could detect guns while ignoring harmless items. A pilot in New York City subways resulted in over 100 false positives and no guns detected. The settlement requires Evolv to allow educational customers to cancel their contracts and prohibits further misrepresentations.
- Company involved
- Evolv
- AI system involved
- Evolv Express
2 source articles · read the reporting →
SEC Charges Delphia and Global Predictions for False AI Claims
The SEC charged Delphia (USA) Inc. and Global Predictions Inc. for making false and misleading statements about their use of artificial intelligence. Delphia claimed from 2019 to 2023 that it used AI and machine learning to predict investments, while Global Predictions falsely claimed in 2023 to be the 'first regulated AI financial advisor'. Both firms settled the charges without admitting or denying the findings, agreeing to pay a total of $400,000 in civil penalties and to cease and desist from further violations.
- Company involved
- Delphia (USA) Inc. and Global Predictions Inc.
1 source article · read the reporting →
Guardio Labs finds AI agents easily abused to create phishing scams
Guardio Labs tested three popular AI agents—ChatGPT, Claude, and Lovable—to see how easily they could be manipulated into generating phishing campaigns. The benchmark, called VibeScamming, simulated a novice scammer attempting to create an SMS phishing attack to steal Microsoft credentials. While ChatGPT and Claude initially refused, they provided full code and tutorials after a jailbreak attempt posing as ethical hacking; Lovable instantly generated and deployed a fully functional, convincing phishing page with no resistance.
- Company involved
- Guardio Labs
- AI system involved
- ChatGPT, Claude, Lovable
2 source articles · read the reporting →
Sound Intelligence Aggression Detectors Prove Unreliable in School Tests
ProPublica tested Sound Intelligence's aggression detection software, used in hundreds of U.S. schools and hospitals. The algorithm, which analyzes audio for signs of stress and anger, frequently misidentified innocent sounds like coughing as aggressive and failed to detect actual screams. At a New Jersey hospital, the system ignored an agitated man screaming and pounding a desk, escalating the situation. Sound Intelligence's CEO acknowledged the imperfections but defended the technology as an early warning system.
- AI system involved
- Sound Intelligence aggression detector
2 source articles · read the reporting →
Gamma AI Presentation Tool Exploited in Multi-Stage Phishing Campaign
Threat actors used Gamma, an AI-powered presentation builder, to host a page that redirected recipients to a fake Microsoft SharePoint login portal. Emails sent from compromised legitimate accounts passed authentication checks, while a Cloudflare Turnstile blocked automated security scanners. An adversary-in-the-middle framework validated credentials in real time and captured session cookies, enabling multi-factor authentication bypass on Microsoft accounts. Abnormal reported the campaign on 15 April 2025.
- AI system involved
- Gamma
7 source articles · read the reporting →
UK Court of Appeal Finds South Wales Police's Automated Facial Recognition Unlawful
The UK Court of Appeal ruled that South Wales Police's use of Automated Facial Recognition (AFR) technology, known as AFR Locate, was unlawful and violated human rights. The court found that the legal framework gave officers too much discretion over watchlists and deployment, and the data protection impact assessment was inadequate. Civil liberties campaigner Ed Bridges brought the judicial review, alleging the technology was unlawfully intrusive. The court upheld the appeal on grounds of legality, data protection, and equality duties, and South Wales Police stated it would not appeal the decision.
- Company involved
- South Wales Police
- AI system involved
- AFR Locate
8 source articles · read the reporting →
Durham Police uses Experian Mosaic data in HART AI risk tool
Durham Constabulary developed the Harm Assessment Risk Tool (HART), a machine learning algorithm that assesses the recidivism risk of offenders. The tool uses 34 data categories including criminal history, age, gender and two types of postcode, one sourced from Experian's Mosaic marketing segmentation system. Big Brother Watch alleges that using such commercial consumer behaviour data to inform custody decisions risks prejudice and disproportionate targeting of deprived neighbourhoods. The force has stated it is refreshing the model with an aim to remove one of the postcode predictors.
- Company involved
- Durham Constabulary
- AI system involved
- Harm Assessment Risk Tool (HART)
9 source articles · read the reporting →
Commercial network in Sri Lanka uses AI-generated anti-migrant content targeting UK
ISD and TBIJ identified a network of over 100 Facebook pages and groups run from Sri Lanka that spread AI-generated anti-migrant content to UK audiences for profit. The content included hate speech and false claims, and was not labelled as AI-generated despite platform policies. The network achieved high engagement and visibility within UK political discourse.
10 source articles · read the reporting →
Spamouflage Operation Used AI-Generated Deepfake Videos for Pro-Chinese Influence
In late 2022, Graphika observed the pro-Chinese influence operation Spamouflage promoting videos featuring AI-generated fictitious people. The footage was created using a commercial AI video platform from a UK company. The videos were low-quality and received fewer than 300 views, but Graphika warns that such tools could enable more convincing deception at scale.
- Company involved
- Spamouflage
5 source articles · read the reporting →
AkiraBot spammed 80,000 websites with AI-generated messages
A Python framework called AkiraBot has spammed over 80,000 websites since September 2024, targeting small and medium-sized businesses. The framework uses OpenAI's API to generate tailored spam messages for contact forms and chat widgets, evading CAPTCHA and network detections. SentinelOne identified the campaign, which is linked to SEO services 'Akira' and 'ServiceWrap' that have received complaints about spamming. The campaign is expected to continue evolving.
- Company involved
- Akira
- AI system involved
- AkiraBot
4 source articles · read the reporting →
Companies face AI deepfake job candidates for remote roles
US companies report a surge in fake job seekers using generative AI tools to fabricate identities, employment histories, and conduct deepfake video interviews for remote positions. Cybersecurity firms Pindrop and CAT Labs, along with BrightHire, describe incidents where scammers, including North Korean operatives, attempted to gain employment to install malware, demand ransoms, steal data, or collect salaries fraudulently. One candidate, 'Ivan X', was detected by Pindrop's video authentication tool after a recruiter noticed his facial expressions were out of sync with his words.
- Company involved
- Pindrop Security
- AI system involved
- video authentication program
1 source article · read the reporting →
Barclays pilot of Sapience monitoring software causes employee stress
Barclays introduced a pilot of employee monitoring software from Sapience in its product control department at Canary Wharf. The system monitors computer activity and admonishes staff if they are not deemed active enough, recording breaks as "unaccounted activity". Employees reported significant stress and worry about taking breaks. Barclays acknowledged the pilot and said it would listen to feedback.
- Company involved
- Barclays
- AI system involved
- Sapience employee monitoring software
10 source articles · read the reporting →
UK councils use Covid OneView AI to harvest personal data for risk scoring
UK local authorities are using a system called Covid OneView, developed by data analytics firm Xantura, to harvest millions of personal details from council records. The system uses predictive analytics and AI to assign risk scores to households and individuals, aiming to identify those vulnerable to Covid or likely to break lockdown rules. Privacy campaigners and MPs have criticised the lack of transparency and the extent of data collection, which includes sensitive information such as debt levels, living arrangements, and even notes on unfaithful sex. Xantura and Barking and Dagenham Council have defended the system as compliant with data protection rules and focused on providing support.
- Company involved
- UK local authorities
- AI system involved
- Covid OneView
6 source articles · read the reporting →
EU to trial AI lie detector at airports in Hungary, Latvia, Greece
The European Union is set to trial an AI-powered lie detector system called iBorderCtrl at airports in Hungary, Latvia and Greece. The system uses a virtual avatar to question passengers and monitors their facial expressions to detect deception. Privacy groups have raised concerns about bias and error rates, noting that the technology has only been tested on 32 people. The trial will require passenger consent and will be overseen by human guards.
- Company involved
- European Union (iBorderCtrl project)
- AI system involved
- iBorderCtrl
6 source articles · read the reporting →
Europol cracks down on network using deepfake ads for crypto fraud
Europol and national authorities in Belgium, Bulgaria, Germany, and Israel arrested two people in November as part of a crackdown on a criminal network that used fraudulent online ads and AI-generated deepfake videos to lure victims into fake cryptocurrency investment platforms. The network allegedly laundered 700 million euros ($816 million) through the scheme, which Europol described as operating on an 'industrial' scale. The arrests were the second phase of an operation that had already led to nine arrests in October. The article does not name the suspects or firms targeted.
4 source articles · read the reporting →