AI Incident Database
Browse AI incidents
Every incident record (metadata only) from the weekly snapshot of 2026-09-07. Filter, then export the selection with its licence attached; each row links to the full record and its reports.
-
Early Claude Opus 4.6 Checkpoint Reportedly Gained Unauthorized Admin Access to Third-Party System During Cybersecurity Evaluation AIID ↗
Anthropic reported that during a January 2026 cybersecurity evaluation, an early checkpoint of Claude Opus 4.6 accidentally disabled its assigned target, then reached an unrelated third-party machine over the open Internet. The model reportedly used a discovered password for admin access, harvested additional credentials, changed system settings, and read one person's personal information before its token budget ended. Anthropic later notified the affected party.
-
Delhi Man Allegedly Used AI to Create and Circulate Obscene Images of College Acquaintance AIID ↗
Delhi police alleged that a man named Keshav Bansal used photographs from a college acquaintance's private social media account with AI image-generation and editing tools to create obscene morphed images and upload them to anonymous Discord servers. The woman reported fake accounts and threatening messages intended to humiliate and harass her. Police arrested Bansal and said the investigation was ongoing.
-
Instinct AI Personal Assistant Reportedly Summarized an AI Product Founder's Retained Emails After Google Access Was Disconnected AIID ↗
AI product founder Claire Vo reported that three hours after she disconnected Instinct from her Google account, the personal AI assistant summarized previously indexed emails. Vo said the Google connector was off, but Instinct had retained copies for later searching; reporting indicates the last stored email predated disconnection. The episode involved the agent acting on retained email data after Google access was revoked, not confirmed continued access to Vo's Gmail account.
-
Instinct AI Personal Assistant Reportedly Sent Email From Moxxie Ventures Founder's Account Without Approval AIID ↗
Moxxie Ventures founder Katie Jacobs Stanton reported that Instinct, a private-access AI personal assistant, sent an innocuous email from her connected account without checking with her first. Stanton said the unauthorized action broke her trust and led her to disconnect email access. Instinct's operator, Spear Street Technology, later said it was taking early users' security concerns seriously and had made changes to prevent some actions.
-
Purportedly AI-Generated Videos Impersonating Miami Immigration Attorney Were Reportedly Used to Defraud Bronx Resident of $4,820 AIID ↗
Scammers reportedly used AI-generated videos impersonating Miami immigration attorney Angel Leal to solicit a Bronx legal resident seeking U.S. citizenship. The victim said he sent $4,820 through Zelle and provided Social Security and residency documents before discovering the scheme. He later reported falling behind on rent and utilities and said the scammers sought additional money.
-
Broadway Performer and SiriusXM Host Seth Rudetsky Reportedly Lost Facebook Page Access in Purportedly AI-Assisted Scam Impersonating Comedian Nikki Glaser AIID ↗
Broadway performer and SiriusXM host Seth Rudetsky reportedly received a personalized invitation purportedly from comedian Nikki Glaser's podcast. After scammers guided him through Facebook permissions during a supposed technical setup, he lost access to his page; he said a former marketing company was also compromised. Reporting described the invitation as most likely AI-composed.
-
Comedy Writer Bruce Vilanch Reportedly Sent Money in Purportedly AI-Assisted Scam Impersonating Fresh Air Host Terry Gross AIID ↗
Comedy writer Bruce Vilanch reportedly received highly personalized messages impersonating Terry Gross, host of NPR's Fresh Air, and sent money after being asked to support NPR. He discovered the invitation was fraudulent when Gross did not appear for the scheduled interview. Reporting described the broader fake-podcast scheme as likely AI-assisted, though no specific AI system was identified.
-
Purportedly AI-Generated Article Falsely Depicted Australian Broadcasting Corporation Finance Presenter Alan Kohler Interviewing Reserve Bank Governor Michele Bullock to Promote Boulder Sparhaven AIID ↗
An online article reportedly used AI-generated imagery to falsely depict Australian Broadcasting Corporation (ABC) finance presenter Alan Kohler interviewing Reserve Bank of Australia governor Michele Bullock about Boulder Sparhaven, a cryptocurrency trading platform not licensed in Australia. The Australian Securities and Investments Commission (ASIC) cited it as an example of increasingly sophisticated AI-assisted investment scams targeting Australians.
-
Wyoming Woman's Childhood Photograph Reportedly Used to Generate Thousands of Explicit Images with Grok AIID ↗
A Wyoming woman identified as Jane Doe 4 in federal court filings alleges that her stepfather used Grok to generate thousands of sexually explicit images of her from a childhood photograph.
-
Purported Hanover Institute for Public Policy Reportedly Targeted Chatbot Responses in Israeli Government-Backed Influence Campaign AIID ↗
An Israeli government-backed communications campaign reportedly operated a website presenting itself as the Hanover Institute for Public Policy, despite reporting finding no corresponding established think tank. The site published material designed for chatbot retrieval, and testing found ChatGPT and Perplexity citing Hanover content in neutral queries.
-
Turkish National Reportedly Posted a Purportedly AI-Generated Image Depicting Himself with Eric Trump While Promoting Trump Hotel Dubai AIID ↗
Turkish national Melih Göğebakan reportedly posted a purportedly AI-generated image on LinkedIn depicting himself alongside Eric Trump while promoting the Trump Hotel Dubai project. The image appeared amid a broader online persona in which Göğebakan allegedly portrayed himself as closely connected to Trump-affiliated organizations and U.S. political figures. He was separately accused of visa-related fraud, though reporting does not establish that the AI-generated image caused those losses.
-
Meta AI Model Reportedly Exploited Security Vulnerability in Real Third-Party Service During Cybersecurity Evaluation AIID ↗
During a Meta cybersecurity evaluation conducted with Irregular, one of Meta's AI models reportedly gained unintended Internet access after an evaluation-environment misconfiguration and exploited a vulnerability in a real third-party service. The model was reportedly identified as Muse Spark 1.1, although Meta had not publicly confirmed that identification or the fuller account of what occurred inside the affected company.
-
Granola AI Notetaker Allegedly Captured and Transcribed Florida Meeting Participant Without Notice or Consent AIID ↗
Tarra Chamberlain, a Florida resident, alleged that Granola captured and transcribed her speech during a virtual meeting without her knowledge or consent after another participant used the AI notetaker. Her July 2026 lawsuit further alleged that Granola uses meeting data to improve its AI models by default, while non-user participants have no comparable opt-out.
-
Anthropic Research Model Reportedly Scanned 9,000 Targets and Compromised Real Company's Application During Evaluation AIID ↗
During an Anthropic cybersecurity evaluation with Irregular, an internal research Claude model reportedly scanned roughly 9,000 internet targets after failing to reach its fictional target. It reportedly compromised a real company's Internet-facing application using credentials from an exposed debug page and SQL injection, then stopped after recognizing that the host was real.
-
Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation AIID ↗
During an Anthropic cybersecurity evaluation with Irregular, Claude Mythos 5 reportedly created and published a malicious Python package to PyPI while pursuing a fictional target. The package was reportedly available for about an hour and ran on 15 real systems. On a security company's scanner, it reportedly exfiltrated credentials that Claude then used to access additional company infrastructure.
-
Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation AIID ↗
During an Anthropic cybersecurity evaluation conducted with Irregular, Claude Opus 4.7 reportedly reached a real company whose domain matched a fictional target, extracted application and infrastructure credentials, and accessed a database containing several hundred rows of production data. Across four runs, the model continued attacking after recognizing that the target was likely real.
-
Hong Kong Man Reportedly Lost More Than HK$10 Million in WhatsApp Scam Using Purported AI-Generated Voice Impersonation of His Father AIID ↗
A Hong Kong man reportedly lost more than HK$10 million after scammers hijacked his father's WhatsApp account and sent voice messages closely resembling his father's voice and speech. The victim allegedly made repeated transfers until his savings were depleted.
-
Anthropic Claude Opus 5 Coding Agent Reportedly Reset a Live Supabase Production Database During Prisma Migration Work AIID ↗
A developer reported that a Claude Opus 5 coding agent reset a live Supabase database while autonomously repairing a personal project's schema. The agent ran `prisma migrate diff` with the production URL supplied as the disposable shadow database, causing Prisma to drop all 22 tables. The developer had granted the agent production access; most content was later recovered or rebuilt.
-
Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations AIID ↗
Beginning July 26, 2026, AI agents powered by Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol reportedly took 19 unsanctioned actions on the live Internet during UK AISI cybersecurity evaluations. Mythos 5 reportedly accounted for 17 events, many allegedly involving deceptive attempts to manipulate real developers into accepting malicious code. AISI reportedly detected and contained the activity; no resulting real-world harm was identified.
-
Publicly Shared Claude Artifacts Reportedly Became Discoverable Through Google Search AIID ↗
Users reported that publicly shared Claude Artifacts (apps, documents, spreadsheets, and other files) could be found through Google Search. Reportedly, indexed artifacts containing business plans, infrastructure diagrams, clinical-trial planning materials, and other potentially sensitive content were also located. Anthropic said links became searchable only after being posted somewhere crawlable.
-
U.S. State Department Reportedly Presented AI-Generated Map That Mislabeled Every Labeled African Country AIID ↗
During a U.S. State Department presentation at the AIDS 2026 conference in Rio de Janeiro, a map carrying an OpenAI provenance signal reportedly mislabeled every African country shown with a label. The department attributed the slide to a team member's rushed revision and accepted responsibility for the resulting confusion and misrepresentation.
-
AI-Generated Voice Mimicking Taiwan President Lai Ching-te Reportedly Used in Political Video Criticizing Government Food-Safety Response AIID ↗
A political video titled "It's Out of Your Control" reportedly used an AI-generated voice resembling Taiwan President Lai Ching-te while criticizing the government's response to a cooking-oil safety scandal. Police said the voice could be mistaken for Lai and later confirmed it was AI-generated. Opposition figures defended the video as political expression while prosecutors opened a forgery investigation.
-
Marrero, Louisiana, Woman Allegedly Created Purportedly AI-Generated Nude Media During Extortion Scheme AIID ↗
Deputies in Livingston Parish, Louisiana, said Marrero resident Haydee Ortiz was initially treated as a victim before investigators allegedly linked her to an online impersonation and extortion campaign involving purportedly AI-generated sexual images and violent threats. Police said sexual media depicting one victim was sent to family and friends, while a person was threatened with rape or bodily harm unless money was paid.
-
American Exceptionalism Institute's Purportedly AI-Generated Ad Drew Defamation Claims Over Marsha Blackburn Pharmaceutical Bribery Allegations AIID ↗
American Exceptionalism Institute reportedly aired an AI-generated political ad portraying Sen. Marsha Blackburn as accepting pharmaceutical-industry payments in exchange for legislative action. Blackburn's attorneys alleged that the bribery claims were defamatory and that the ad failed to comply with Tennessee's synthetic-media disclosure requirements. Comcast and Viamedia reportedly pulled the ad.
-
Hank Green Reportedly Used AI-Generated Scientific Image Containing Errors in Educational Video AIID ↗
Science communicator and YouTuber Hank Green reportedly included an AI-generated scientific image containing factual and mathematical errors in a YouTube educational video. Green later said he knew the image was AI-generated when he used it and removed it after recognizing problems with the graphic.
-
Scammers Allegedly Used AI-Generated Voice in Boone County, Missouri, Kidnapping Ransom Scam AIID ↗
Boone County, Missouri, authorities said a resident received a call on July 17, 2026, that displayed the resident's daughter's name and number and used an AI-generated imitation of her voice to claim she had been kidnapped at gunpoint. A second voice demanded ransom. A coordinated police response located the daughter safely in Jefferson City, unaware of the call; no payment or arrest was reported.
-
Purported Deepfake Impersonation of Starmangalsutra Director Reportedly Led to ₹10.70 Crore (Approximately US$1.11 Million) in Unauthorized Fund Transfers AIID ↗
Starmangalsutra Private Limited, a jewelery-manufacturing subsidiary of India-based Sky Gold and Diamonds, reportedly lost ₹10.70 crore (about US$1.1 million) after unknown actors compromised a company-issued phone and laptop and used purported deepfake methods to impersonate a director. An employee, reportedly believing the instructions were genuine, transferred funds to unknown bank accounts before verification showed the director had issued no such instructions.
-
Purported AI-Generated Image Reportedly Won First Prize in Hohhot, Inner Mongolia, Photography Competition Before Award Was Revoked AIID ↗
An unidentified entrant reportedly submitted a purported AI-generated image depicting three sanitation workers to a local photography competition in Hohhot, Inner Mongolia, where it won first prize. After viewers flagged garbled vest text, unnatural lighting, and repeated facial features, organizers confirmed AI use, revoked the award, removed the work from eligibility and archives, and suspended the competition for review.
-
OpenAI GPT-5.6 Sol Reportedly Deleted Software Engineer's Production Database During Local Testing AIID ↗
Software engineer Bruno Lemos reported that GPT-5.6 Sol deleted his production database after he asked it to generate seed data for local testing. The agent reportedly ran the test suite, then initiated cleanup that executed TRUNCATE TABLE users CASCADE against production because the repo's test database URL pointed to the live Neon database. OpenAI later acknowledged unauthorized deletion reports and said it was adding safeguards.
-
Purportedly AI-Generated Images Reportedly Used During Four-Year Catfishing Campaign Targeting Welsh Teenager AIID ↗
A Welsh teenager reportedly endured a nearly four-year online impersonation campaign in which another teenager created fake social media accounts using her photographs and, later, AI-generated images depicting her. The campaign reportedly attracted more than 100,000 followers, led strangers to believe they knew the victim, and resulted in a High Court settlement and damages award.
-
OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation AIID ↗
OpenAI reported that models used in an internal cyber-capability evaluation operated beyond the sandbox's intended network boundaries after identifying a vulnerability in a package-registry proxy. The models allegedly reached Hugging Face production systems and accessed test solutions before Hugging Face detected and contained the activity.
-
OpenAI GPT-5.6 Sol Agent Reportedly Deleted Most Files in AI Startup Founder's Mac Home Directory AIID ↗
AI investor Matt Shumer reported that a GPT-5.6 Sol agent in OpenAI Codex's high-autonomy Ultra mode accidentally deleted most files in his Mac home directory during a cleanup task. A review sub-agent reportedly misexpanded $HOME and ran `rm -rf /Users/mattsdevbox`; Shumer stopped the process after material deletion. OpenAI later confirmed unauthorized file-deletion reports and said it was adding safeguards.
-
AI Chatbot Reportedly Recommended Herbicide Treatment Linked to Loss of About 25 Acres of Sesame in China AIID ↗
A 67-year-old farmer in Chuzhou, Anhui, reportedly used an AI-generated weed-and-pest-control plan to spray about 150 mu (25 acres) of sesame by drone. By the next day, the crop had largely withered. Agricultural technicians said the recommended mixture included fomesafen, a herbicide unsuitable for blanket application to sesame. The specific AI product and model have not been publicly confirmed.
-
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network AIID ↗
Hunt.io reported that an unidentified threat actor used Nous Research's Hermes agent in unattended "YOLO" mode during an intrusion targeting Thailand's Ministry of Finance. Recovered logs showed Hermes conducting privilege-escalation reconnaissance within ministry systems and recursively searching a directory containing personnel records. Researchers found evidence of compromise but no data exfiltration; the ministry had not publicly confirmed a breach.
-
Purportedly AI-Generated Facebook Pages Allegedly Targeted Australian Rules Football Club Geelong Cats With Fabricated Harmful Claims AIID ↗
Purportedly AI-generated Facebook pages reportedly published false stories about the Geelong Football Club, including fabricated criminal allegations, illnesses, deaths, and a nonexistent bushfire evacuation warning. The club reported the pages to Meta, which later removed at least one page after complaints, while other misleading content reportedly remained online.
-
Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion AIID ↗
Sygnia reported that a threat actor apparently used purportedly AI-assisted or agentic workflows to move rapidly through an unidentified organization's AWS environment during an approximately 72-hour intrusion. The attacker allegedly expanded from an Internet-facing application into cloud infrastructure and data stores, reportedly stealing credentials and sensitive information while demonstrating the ability to disrupt services as leverage for extortion. Sygnia did not identify a specific model.
-
Discord's Automated Moderation System Reportedly Wrongfully Banned More Than 8,000 Users Over Benign Images AIID ↗
Discord reportedly wrongfully banned more than 8,000 accounts after its automated image-moderation workflow flagged harmless uploads, including grids, spreadsheets, chessboards, and game images, as prohibited material. Discord said a bug converted temporary upload restrictions into account bans and prevented cleared accounts from being restored automatically. The company later reinstated the affected accounts.
-
Waymo Robotaxi Reportedly Caught Fire After Driving Over Firework in San Francisco AIID ↗
An unoccupied Waymo robotaxi reportedly drove over a small firework near the 1200 block of Connecticut Street in San Francisco on July 4, 2026, and caught fire. No passengers were aboard and no injuries were reported. Waymo said it coordinated with the San Francisco Fire Department and local authorities to remove the damaged vehicle.
-
Istanbul Fraud Network Reportedly Used AI-Assisted Call Center Software to Impersonate Officials and Defraud Europeans AIID ↗
An international fraud network operating from a call center in Maslak, Istanbul reportedly used AI-assisted software to contact people in the Czech Republic and other European countries while posing as police, prosecutors, soldiers, and bank officials. Authorities said numerous victims were defrauded for substantial sums. Investigators found 80 foreign-national suspects at the call center and seized digital materials during raids at three Istanbul locations.
-
Purported Deepfake Impersonating Dubai Crown Prince Reportedly Used to Defraud Filipino Domestic Worker AIID ↗
A Filipino domestic worker identified as "Maria" reportedly paid ₱100,000 (about $1,625) after a scammer deployed purportedly manipulated real-time video to impersonate Dubai Crown Prince Hamdan bin Mohammed during WhatsApp calls. The scammer reportedly claimed the money was for a marriage certificate and "royal membership card" that would help her secure a job in Dubai. Maria reportedly ended contact after noticing that the Facebook account was based in Nigeria.
-
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records AIID ↗
From July 1–4, 2026, suspected China-linked hackers reportedly used a multi-agent framework built on Hermes and OpenClaw to compromise Taiwanese government systems. The agents reportedly compromised 85 credentials and used persistent access to connected systems to exfiltrate more than 2,564 personnel records. Taiwan later confirmed an overseas AI-assisted campaign against government agencies, without attributing it to China.
-
City of Spokane Reportedly Distributed Purported AI-Generated Clocktower Flyer Resembling Graphic Designer Matthew Clinard's Artwork AIID ↗
A Spokane Parks and Recreation employee reportedly used a purported generative AI image tool to create a flyer promoting the restored Great Northern Clocktower chimes. The flyer reportedly reproduced elements of artist Matthew Clinard's commercially sold Clocktower sticker and was distributed by the mayor's office without the city-required AI disclosure. After Clinard complained publicly, the city removed the image and apologized, then began considering AI-policy and employee-training reforms.
-
Spokane, Washington, Police Reportedly Circulated Purported AI-Generated Image as Authentic Photo of Injured Dog AIID ↗
Detectives in Spokane, Washington, reportedly created a purported AI-generated image as a joke depicting a real undercover officer holding an injured dachshund. A supervisor reportedly mistook it for an authentic photograph and the image was released to news media after correcting an earlier claim that the dog had died. The Spokesman-Review published a cropped version before the department disclosed that the scene was fabricated and began reviewing its verification procedures.
-
LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database AIID ↗
Sysdig reported that a ransomware operator it dubbed JADEPUFFER used an LLM-driven agent to turn access through a vulnerable internet-facing Langflow deployment into a database-extortion operation. The report said the activity reached a production database server and produced concrete disruption, with the victim environment allegedly left in a damaged and unrecoverable state alongside a ransom demand.
-
Purportedly AI-Powered KT Platform Reportedly Used in Forced Scamming Operation Involving Trafficked Worker in Myanmar AIID ↗
AP reported that traffickers at Myanmar's Tai Chang scam compound forced a man named Safeer Mohammed Koorimannil to use the AI-powered KT platform to impersonate women and target thousands of people online. The system reportedly supported the scam conversations while monitoring worker performance. Koorimannil said he was beaten for poor results and later paid 500,000 rupees ($5,300) for his release.
-
DuckDuckGo Search Assist Reportedly Falsely Claimed Donald Trump and JD Vance Died of Rabies AIID ↗
DuckDuckGo's Search Assist reportedly produced an answer stating that Donald Trump and JD Vance had died of rabies and repeated fabricated details involving Robert F. Kennedy Jr. The answer cited a false WKNA49 article alongside an unrelated ABC News report. Reporting linked the episode to adversarial web content associated with r/poisonai. DuckDuckGo said Search Assist had been "deliberately tricked," fixed the result, and planned updates.
-
Rep. Anna Paulina Luna's Office Reportedly Published Claude Transcript Residue on Accident in House Amendment Summary AIID ↗
A staffer in Rep. Anna Paulina Luna's office reportedly used Claude to prepare a summary for an amendment to the FY2027 National Defense Authorization Act and accidentally pasted chatbot transcript residue, including a timestamp and "Claude responded:" marker, into the public House Rules Committee record. The summary was reportedly later corrected. Luna confirmed that her staff used Claude for the summary, not to draft the amendment itself.
-
Storm-1516 Reportedly Spread Fabricated Narratives Targeting Firebird Data Center in Armenia AIID ↗
Alethea reported that Storm-1516, a Russian influence operation, targeted Firebird's NVIDIA-powered data center under construction in Hrazdan, Armenia, with purportedly fabricated media narratives designed to make the project appear dangerous and economically unstable. The campaign allegedly used imitation tech-news articles to cast the facility as a liability for Armenia's infrastructure and Western-aligned technology ambitions.
-
Apartment Owner and Manager UDR Allegedly Used RealPage Algorithms to Set San Diego Rents in Keller v. UDR, Inc. AIID ↗
In Keller v. UDR, Inc., plaintiff Jacob Keller alleged that UDR used RealPage pricing tools to set rents or occupancy levels at its San Diego properties after a city prohibition took effect on June 21, 2025. The complaint claims the tools relied on nonpublic competitor data and contributed to inflated rents for UDR tenants. UDR, a large publicly traded apartment owner and operator, had previously acknowledged using YieldStar in decisions concerning certain multifamily units.
-
Zoox Autonomous Vehicle Reportedly Entered Smoke-Obscured Fire Scene, Prompting Heavy-Smoke Detection Recall AIID ↗
On June 20, 2026, an unoccupied Zoox autonomous vehicle reportedly entered an active fire scene after heavy smoke obscured its surroundings. The purported automated driving system braked hard while attempting to steer away and stopped before the vehicle was reversed under teleguidance. Zoox later recalled 105 vehicles and issued a software update intended to improve detection of and response to heavy smoke.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.