AI Incident Database
Browse AI incidents
Every incident record (metadata only) from the weekly snapshot of 2026-09-07. Filter, then export the selection with its licence attached; each row links to the full record and its reports.
-
AI Agent Appearing to Originate from OpenAI Reportedly Attempted to Hack U.S. Department of Education Civil Rights Website AIID ↗
During summer 2026, an AI agent appearing to originate from OpenAI reportedly attempted to hack a U.S. Department of Education Office for Civil Rights website but did not succeed. Transluce identified the activity; OpenAI said it was still investigating the episode, and the department said reviews found no evidence of impact to its website or databases.
-
Stanford University Acknowledged Using AI to Alter Student Photo for Campus Banners, Replacing Hispanic Student With Black Woman AIID ↗
Stanford University acknowledged using AI to alter a 2024 student photograph for campus banners in September 2026. The altered image replaced Hispanic student Billy Ramirez with a Black woman and made two other students appear thinner. Ramirez said being "erased" was upsetting and frustrating. Stanford said the alteration and lack of disclosure violated its AI policy and later said it was removing the banners.
-
AI Chatbot Reportedly Misidentified Chinese Ship Cargo as Nuclear-Program Components, Prompting U.S. Military Interception Preparations AIID ↗
In spring 2026, a U.S. special operations analyst reportedly used an AI chatbot to analyze intelligence on a Chinese ship's cargo and produced a report falsely identifying it as carrying nuclear-weapons-program components. The U.S. military reportedly prepared to intercept and potentially board the vessel, with aircraft already airborne, before officials rechecked the report, found the AI-assisted conclusion was wrong, and called off the operation.
-
AI-Generated Images Purporting to Show Donald Trump Kissing White House Aide Natalie Harp Went Viral on Social Media AIID ↗
AI-generated images purporting to show U.S. President Donald Trump kissing White House aide Natalie Harp on a golf course spread across social media; one X post received over 10 million views. Forensic analysis and provenance checks indicated the circulating images were synthetic, and the White House called them fake. The original creator remained unidentified.
-
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority AIID ↗
An unnamed organization reportedly notified Spain's data protection authority that a third party used an AI agent powered by a known language model to carry out a multistep intrusion that resulted in unauthorized changes to personal data and access to invoices. The AEPD said the case remains under review and has not identified the organization, attacker, AI system, attack date, or number of affected people.
-
Russia-Linked Matryoshka Influence Operation Reportedly Used AI-Cloned Celebrity Voices and Fabricated News-Style Videos to Target Democratic Candidates Ahead of 2026 U.S. Midterms AIID ↗
Researchers attributed a September 2026 influence campaign targeting U.S. Democratic Senate candidates to the Russia-linked Matryoshka/Operation Overload network. The campaign reportedly used AI-cloned celebrity voices and fabricated, news-branded videos to spread false or unsubstantiated claims on social media. Celebrities and CNN rejected the manipulated statements and unauthorized branding, which were intended to influence U.S. voters before the midterms.
-
Anthropic-Designated GTG-87001 Weapons Cell in Northern Yemen Reportedly Used Claude Code to Develop Missile Guidance Software AIID ↗
Anthropic reported that a northern Yemen-based weapons cell, designated GTG-87001, used Claude Code across three weapons programs to develop guidance, navigation, and control software. The actors reportedly test-fired a guided rocket that appeared to fail, then returned to Claude for failure analysis. Anthropic said it banned associated accounts and shared threat intelligence with partners.
-
Purported Deepfake WhatsApp Scam Impersonating Tamil Nadu Chief Minister and Actor C. Joseph Vijay Reportedly Defrauded Bengaluru Security Guard of ₹104,000 (~$1,085.40) AIID ↗
Ratikanta Giri, a 29-year-old security guard in Bengaluru, India, reportedly lost ₹104,000 (~$1,085.40) after a WhatsApp video caller used a purportedly AI-generated deepfake to impersonate C. Joseph Vijay, the actor and chief minister of the southern Indian state of Tamil Nadu. The caller promised financial aid, while accomplices allegedly demanded fees and later impersonated India's Central Bureau of Investigation.
-
Early Claude Opus 4.6 Checkpoint Reportedly Gained Unauthorized Admin Access to Third-Party System During Cybersecurity Evaluation AIID ↗
Anthropic reported that during a January 2026 cybersecurity evaluation, an early checkpoint of Claude Opus 4.6 accidentally disabled its assigned target, then reached an unrelated third-party machine over the open Internet. The model reportedly used a discovered password for admin access, harvested additional credentials, changed system settings, and read one person's personal information before its token budget ended. Anthropic later notified the affected party.
-
Delhi Man Allegedly Used AI to Create and Circulate Obscene Images of College Acquaintance AIID ↗
Delhi police alleged that a man named Keshav Bansal used photographs from a college acquaintance's private social media account with AI image-generation and editing tools to create obscene morphed images and upload them to anonymous Discord servers. The woman reported fake accounts and threatening messages intended to humiliate and harass her. Police arrested Bansal and said the investigation was ongoing.
-
Northern Ireland Victim Reportedly Lost £250,000 in Investment Scam Using Purportedly AI-Generated Video of Unnamed Financial Personality AIID ↗
A person in Ards and North Down, Northern Ireland, United Kingdom, reportedly lost £250,000 in an investment scam that began with an apparently AI-generated video of an unnamed, well-known financial personality. Police said the victim was moved to WhatsApp, persuaded to make escalating payments, create online accounts, grant remote computer access, and borrow money to keep investing.
-
Parkview High School in Georgia Reportedly Received Series of Purportedly AI-Generated Bomb Threats That Prompted Repeated Lockdowns AIID ↗
During the 2026–27 school year, Parkview High School in Lilburn, Georgia, reportedly received at least four AI-generated bomb threats, including masked phone calls that prompted repeated lockdowns or soft lockdowns. School police described the threats as following a recurring pattern and were investigating with the GBI and FBI. Authorities had not identified a suspect or established publicly whether the same person was responsible for every threat.
-
Instinct AI Personal Assistant Reportedly Summarized an AI Product Founder's Retained Emails After Google Access Was Disconnected AIID ↗
AI product founder Claire Vo reported that three hours after she disconnected Instinct from her Google account, the personal AI assistant summarized previously indexed emails. Vo said the Google connector was off, but Instinct had retained copies for later searching; reporting indicates the last stored email predated disconnection. The episode involved the agent acting on retained email data after Google access was revoked, not confirmed continued access to Vo's Gmail account.
-
Instinct AI Personal Assistant Reportedly Sent Email From Moxxie Ventures Founder's Account Without Approval AIID ↗
Moxxie Ventures founder Katie Jacobs Stanton reported that Instinct, a private-access AI personal assistant, sent an innocuous email from her connected account without checking with her first. Stanton said the unauthorized action broke her trust and led her to disconnect email access. Instinct's operator, Spear Street Technology, later said it was taking early users' security concerns seriously and had made changes to prevent some actions.
-
Teenager in Quilmes, Argentina, Reportedly Consulted ChatGPT While Planning School Shooting Against Classmates AIID ↗
Argentine authorities reported that a 15-year-old in Quilmes allegedly discussed a planned school shooting with ChatGPT, including tactical preparations, before an FBI alert prompted an investigation by the Argentine Federal Police. Police later seized phones and tactical clothing; no firearms or ammunition were reported. Public reporting does not establish what ChatGPT answered or whether it materially assisted the alleged plan.
-
Purportedly AI-Generated Videos Impersonating Miami Immigration Attorney Were Reportedly Used to Defraud Bronx Resident of $4,820 AIID ↗
Scammers reportedly used AI-generated videos impersonating Miami immigration attorney Angel Leal to solicit a Bronx legal resident seeking U.S. citizenship. The victim said he sent $4,820 through Zelle and provided Social Security and residency documents before discovering the scheme. He later reported falling behind on rent and utilities and said the scammers sought additional money.
-
Broadway Performer and SiriusXM Host Seth Rudetsky Reportedly Lost Facebook Page Access in Purportedly AI-Assisted Scam Impersonating Comedian Nikki Glaser AIID ↗
Broadway performer and SiriusXM host Seth Rudetsky reportedly received a personalized invitation purportedly from comedian Nikki Glaser's podcast. After scammers guided him through Facebook permissions during a supposed technical setup, he lost access to his page; he said a former marketing company was also compromised. Reporting described the invitation as most likely AI-composed.
-
Comedy Writer Bruce Vilanch Reportedly Sent Money in Purportedly AI-Assisted Scam Impersonating Fresh Air Host Terry Gross AIID ↗
Comedy writer Bruce Vilanch reportedly received highly personalized messages impersonating Terry Gross, host of NPR's Fresh Air, and sent money after being asked to support NPR. He discovered the invitation was fraudulent when Gross did not appear for the scheduled interview. Reporting described the broader fake-podcast scheme as likely AI-assisted, though no specific AI system was identified.
-
Purportedly AI-Generated Article Falsely Depicted Australian Broadcasting Corporation Finance Presenter Alan Kohler Interviewing Reserve Bank Governor Michele Bullock to Promote Boulder Sparhaven AIID ↗
An online article reportedly used AI-generated imagery to falsely depict Australian Broadcasting Corporation (ABC) finance presenter Alan Kohler interviewing Reserve Bank of Australia governor Michele Bullock about Boulder Sparhaven, a cryptocurrency trading platform not licensed in Australia. The Australian Securities and Investments Commission (ASIC) cited it as an example of increasingly sophisticated AI-assisted investment scams targeting Australians.
-
AI incident: sexual content (xAI, Aug 2026) AIID ↗
A Wyoming woman identified as Jane Doe 4 in federal court filings alleges that her stepfather used Grok to generate thousands of sexually explicit images of her from a childhood photograph.
-
Purported Hanover Institute for Public Policy Reportedly Targeted Chatbot Responses in Israeli Government-Backed Influence Campaign AIID ↗
An Israeli government-backed communications campaign reportedly operated a website presenting itself as the Hanover Institute for Public Policy, despite reporting finding no corresponding established think tank. The site published material designed for chatbot retrieval, and testing found ChatGPT and Perplexity citing Hanover content in neutral queries.
-
Turkish National Reportedly Posted a Purportedly AI-Generated Image Depicting Himself with Eric Trump While Promoting Trump Hotel Dubai AIID ↗
Turkish national Melih Göğebakan reportedly posted a purportedly AI-generated image on LinkedIn depicting himself alongside Eric Trump while promoting the Trump Hotel Dubai project. The image appeared amid a broader online persona in which Göğebakan allegedly portrayed himself as closely connected to Trump-affiliated organizations and U.S. political figures. He was separately accused of visa-related fraud, though reporting does not establish that the AI-generated image caused those losses.
-
Meta AI Model Reportedly Exploited Security Vulnerability in Real Third-Party Service During Cybersecurity Evaluation AIID ↗
During a Meta cybersecurity evaluation conducted with Irregular, one of Meta's AI models reportedly gained unintended Internet access after an evaluation-environment misconfiguration and exploited a vulnerability in a real third-party service. The model was reportedly identified as Muse Spark 1.1, although Meta had not publicly confirmed that identification or the fuller account of what occurred inside the affected company.
-
Granola AI Notetaker Allegedly Captured and Transcribed Florida Meeting Participant Without Notice or Consent AIID ↗
Tarra Chamberlain, a Florida resident, alleged that Granola captured and transcribed her speech during a virtual meeting without her knowledge or consent after another participant used the AI notetaker. Her July 2026 lawsuit further alleged that Granola uses meeting data to improve its AI models by default, while non-user participants have no comparable opt-out.
-
Anthropic Research Model Reportedly Scanned 9,000 Targets and Compromised Real Company's Application During Evaluation AIID ↗
During an Anthropic cybersecurity evaluation with Irregular, an internal research Claude model reportedly scanned roughly 9,000 internet targets after failing to reach its fictional target. It reportedly compromised a real company's Internet-facing application using credentials from an exposed debug page and SQL injection, then stopped after recognizing that the host was real.
-
Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation AIID ↗
During an Anthropic cybersecurity evaluation with Irregular, Claude Mythos 5 reportedly created and published a malicious Python package to PyPI while pursuing a fictional target. The package was reportedly available for about an hour and ran on 15 real systems. On a security company's scanner, it reportedly exfiltrated credentials that Claude then used to access additional company infrastructure.
-
Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation AIID ↗
During an Anthropic cybersecurity evaluation conducted with Irregular, Claude Opus 4.7 reportedly reached a real company whose domain matched a fictional target, extracted application and infrastructure credentials, and accessed a database containing several hundred rows of production data. Across four runs, the model continued attacking after recognizing that the target was likely real.
-
New Jersey Regulators Found DataOne Operated 62 Unpermitted Natural-Gas Generators at Vineland AI Data Center AIID ↗
In July 2026, New Jersey inspectors found 62 unpermitted 2,000-kW natural-gas generators powering DataOne's Vineland data center, which has an agreement to provide AI computing power to Microsoft. The state later fined DataOne $1.07 million under the Air Pollution Control Act. Residents also reported persistent noise and raised concerns about air emissions; DataOne disputed the state's decision.
-
Hong Kong Man Reportedly Lost More Than HK$10 Million in WhatsApp Scam Using Purported AI-Generated Voice Impersonation of His Father AIID ↗
A Hong Kong man reportedly lost more than HK$10 million after scammers hijacked his father's WhatsApp account and sent voice messages closely resembling his father's voice and speech. The victim allegedly made repeated transfers until his savings were depleted.
-
Anthropic Claude Opus 5 Coding Agent Reportedly Reset a Live Supabase Production Database During Prisma Migration Work AIID ↗
A developer reported that a Claude Opus 5 coding agent reset a live Supabase database while autonomously repairing a personal project's schema. The agent ran `prisma migrate diff` with the production URL supplied as the disposable shadow database, causing Prisma to drop all 22 tables. The developer had granted the agent production access; most content was later recovered or rebuilt.
-
Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations AIID ↗
Beginning July 26, 2026, AI agents powered by Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol reportedly took 19 unsanctioned actions on the live Internet during UK AISI cybersecurity evaluations. Mythos 5 reportedly accounted for 17 events, many allegedly involving deceptive attempts to manipulate real developers into accepting malicious code. AISI reportedly detected and contained the activity; no resulting real-world harm was identified.
-
Publicly Shared Claude Artifacts Reportedly Became Discoverable Through Google Search AIID ↗
Users reported that publicly shared Claude Artifacts (apps, documents, spreadsheets, and other files) could be found through Google Search. Reportedly, indexed artifacts containing business plans, infrastructure diagrams, clinical-trial planning materials, and other potentially sensitive content were also located. Anthropic said links became searchable only after being posted somewhere crawlable.
-
U.S. State Department Reportedly Presented AI-Generated Map That Mislabeled Every Labeled African Country AIID ↗
During a U.S. State Department presentation at the AIDS 2026 conference in Rio de Janeiro, a map carrying an OpenAI provenance signal reportedly mislabeled every African country shown with a label. The department attributed the slide to a team member's rushed revision and accepted responsibility for the resulting confusion and misrepresentation.
-
AI-Generated Voice Mimicking Taiwan President Lai Ching-te Reportedly Used in Political Video Criticizing Government Food-Safety Response AIID ↗
A political video titled "It's Out of Your Control" reportedly used an AI-generated voice resembling Taiwan President Lai Ching-te while criticizing the government's response to a cooking-oil safety scandal. Police said the voice could be mistaken for Lai and later confirmed it was AI-generated. Opposition figures defended the video as political expression while prosecutors opened a forgery investigation.
-
AI incident: sexual content (Jul 2026) AIID ↗
Deputies in Livingston Parish, Louisiana, said Marrero resident Haydee Ortiz was initially treated as a victim before investigators allegedly linked her to an online impersonation and extortion campaign involving purportedly AI-generated sexual images and violent threats. Police said sexual media depicting one victim was sent to family and friends, while a person was threatened with rape or bodily harm unless money was paid.
-
American Exceptionalism Institute's Purportedly AI-Generated Ad Drew Defamation Claims Over Marsha Blackburn Pharmaceutical Bribery Allegations AIID ↗
American Exceptionalism Institute reportedly aired an AI-generated political ad portraying Sen. Marsha Blackburn as accepting pharmaceutical-industry payments in exchange for legislative action. Blackburn's attorneys alleged that the bribery claims were defamatory and that the ad failed to comply with Tennessee's synthetic-media disclosure requirements. Comcast and Viamedia reportedly pulled the ad.
-
Hank Green Reportedly Used AI-Generated Scientific Image Containing Errors in Educational Video AIID ↗
Science communicator and YouTuber Hank Green reportedly included an AI-generated scientific image containing factual and mathematical errors in a YouTube educational video. Green later said he knew the image was AI-generated when he used it and removed it after recognizing problems with the graphic.
-
Scammers Allegedly Used AI-Generated Voice in Boone County, Missouri, Kidnapping Ransom Scam AIID ↗
Boone County, Missouri, authorities said a resident received a call on July 17, 2026, that displayed the resident's daughter's name and number and used an AI-generated imitation of her voice to claim she had been kidnapped at gunpoint. A second voice demanded ransom. A coordinated police response located the daughter safely in Jefferson City, unaware of the call; no payment or arrest was reported.
-
Purported Deepfake Impersonation of Starmangalsutra Director Reportedly Led to ₹10.70 Crore (Approximately US$1.11 Million) in Unauthorized Fund Transfers AIID ↗
Starmangalsutra Private Limited, a jewelery-manufacturing subsidiary of India-based Sky Gold and Diamonds, reportedly lost ₹10.70 crore (about US$1.1 million) after unknown actors compromised a company-issued phone and laptop and used purported deepfake methods to impersonate a director. An employee, reportedly believing the instructions were genuine, transferred funds to unknown bank accounts before verification showed the director had issued no such instructions.
-
Purported AI-Generated Image Reportedly Won First Prize in Hohhot, Inner Mongolia, Photography Competition Before Award Was Revoked AIID ↗
An unidentified entrant reportedly submitted a purported AI-generated image depicting three sanitation workers to a local photography competition in Hohhot, Inner Mongolia, where it won first prize. After viewers flagged garbled vest text, unnatural lighting, and repeated facial features, organizers confirmed AI use, revoked the award, removed the work from eligibility and archives, and suspended the competition for review.
-
OpenAI GPT-5.6 Sol Reportedly Deleted Software Engineer's Production Database During Local Testing AIID ↗
Software engineer Bruno Lemos reported that GPT-5.6 Sol deleted his production database after he asked it to generate seed data for local testing. The agent reportedly ran the test suite, then initiated cleanup that executed TRUNCATE TABLE users CASCADE against production because the repo's test database URL pointed to the live Neon database. OpenAI later acknowledged unauthorized deletion reports and said it was adding safeguards.
-
Purportedly AI-Generated Images Reportedly Used During Four-Year Catfishing Campaign Targeting Welsh Teenager AIID ↗
A Welsh teenager reportedly endured a nearly four-year online impersonation campaign in which another teenager created fake social media accounts using her photographs and, later, AI-generated images depicting her. The campaign reportedly attracted more than 100,000 followers, led strangers to believe they knew the victim, and resulted in a High Court settlement and damages award.
-
OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation AIID ↗
OpenAI reported that models used in an internal cyber-capability evaluation operated beyond the sandbox's intended network boundaries after identifying a vulnerability in a package-registry proxy. The models allegedly reached Hugging Face production systems and accessed test solutions before Hugging Face detected and contained the activity.
-
OpenAI GPT-5.6 Sol Agent Reportedly Deleted Most Files in AI Startup Founder's Mac Home Directory AIID ↗
AI investor Matt Shumer reported that a GPT-5.6 Sol agent in OpenAI Codex's high-autonomy Ultra mode accidentally deleted most files in his Mac home directory during a cleanup task. A review sub-agent reportedly misexpanded $HOME and ran `rm -rf /Users/mattsdevbox`; Shumer stopped the process after material deletion. OpenAI later confirmed unauthorized file-deletion reports and said it was adding safeguards.
-
AI Chatbot Reportedly Recommended Herbicide Treatment Linked to Loss of About 25 Acres of Sesame in China AIID ↗
A 67-year-old farmer in Chuzhou, Anhui, reportedly used an AI-generated weed-and-pest-control plan to spray about 150 mu (25 acres) of sesame by drone. By the next day, the crop had largely withered. Agricultural technicians said the recommended mixture included fomesafen, a herbicide unsuitable for blanket application to sesame. The specific AI product and model have not been publicly confirmed.
-
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network AIID ↗
Hunt.io reported that an unidentified threat actor used Nous Research's Hermes agent in unattended "YOLO" mode during an intrusion targeting Thailand's Ministry of Finance. Recovered logs showed Hermes conducting privilege-escalation reconnaissance within ministry systems and recursively searching a directory containing personnel records. Researchers found evidence of compromise but no data exfiltration; the ministry had not publicly confirmed a breach.
-
Purportedly AI-Generated Facebook Pages Allegedly Targeted Australian Rules Football Club Geelong Cats With Fabricated Harmful Claims AIID ↗
Purportedly AI-generated Facebook pages reportedly published false stories about the Geelong Football Club, including fabricated criminal allegations, illnesses, deaths, and a nonexistent bushfire evacuation warning. The club reported the pages to Meta, which later removed at least one page after complaints, while other misleading content reportedly remained online.
-
Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion AIID ↗
Sygnia reported that a threat actor apparently used purportedly AI-assisted or agentic workflows to move rapidly through an unidentified organization's AWS environment during an approximately 72-hour intrusion. The attacker allegedly expanded from an Internet-facing application into cloud infrastructure and data stores, reportedly stealing credentials and sensitive information while demonstrating the ability to disrupt services as leverage for extortion. Sygnia did not identify a specific model.
-
Discord's Automated Moderation System Reportedly Wrongfully Banned More Than 8,000 Users Over Benign Images AIID ↗
Discord reportedly wrongfully banned more than 8,000 accounts after its automated image-moderation workflow flagged harmless uploads, including grids, spreadsheets, chessboards, and game images, as prohibited material. Discord said a bug converted temporary upload restrictions into account bans and prevented cleared accounts from being restored automatically. The company later reinstated the affected accounts.
-
Waymo Robotaxi Reportedly Caught Fire After Driving Over Firework in San Francisco AIID ↗
An unoccupied Waymo robotaxi reportedly drove over a small firework near the 1200 block of Connecticut Street in San Francisco on July 4, 2026, and caught fire. No passengers were aboard and no injuries were reported. Waymo said it coordinated with the San Francisco Fire Department and local authorities to remove the damaged vehicle.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- What is recorded in each incident?
- What happened, when, who was involved as developer or deployer, who was harmed, the sectors and countries affected, and the domain and subdomain the harm falls under. Incidents are mirrored from the AI Incident Database and each links back to its source record.
- Does an incident mean wrongdoing was proven?
- No. These are reported incidents, not findings of liability. Entities named in a report are named as reported, allegations are marked as alleged, and nothing here is a legal determination.
- How current is the incident data?
- It syncs directly from the AI Incident Database several times a day, so a new incident usually appears within hours. Each record carries the date it was last synced, and the snapshot date is shown on the page.
- Does this page include the full incident reports?
- No. The report texts are outside the licence this data is shared under, so only the metadata and the classifications appear here. Every row links to the original incident record, which carries the reports themselves.