AI Incident Database
Browse AI incidents
Every incident record (metadata only) from the weekly snapshot of 2026-09-07. Filter, then export the selection with its licence attached; each row links to the full record and its reports.
-
COEMPT Quality Assurance Engineers Allegedly Violated Indian CBSE Student Data Privacy Rights by Processing It with Google Gemini AIID ↗
The Hindu reported that vulnerabilities in the OnMark exam-marking portal used by India's Central Board of Secondary Education (CBSE) allegedly exposed sensitive student data, including answer-sheet images. Ethical hacker Nisarga Adhikary also alleged that COEMPT Eduteck quality-assurance scripts processed students' personal information through Google Gemini. CBSE said the vulnerabilities had been contained.
-
Hidden Prompt Injection in Brazilian Labor-Court Petition Reportedly Tried to Manipulate Galileu AIID ↗
Galileu, an AI tool used by Brazil's labor courts, reportedly detected hidden instructions embedded in an initial petition before the 3rd Labor Court of Parauapebas. The text allegedly told the AI to contest the petition superficially and not challenge documents. Galileu reportedly alerted the judge and blocked the hidden content from processing; the judge then reviewed the material before imposing any procedural consequences.
-
Meta Internal AI Agent Reportedly Gave Advice That Allegedly Exposed Sensitive Data to Unauthorized Employees AIID ↗
Reporting alleged that a Meta internal AI agent, purportedly similar to OpenClaw, posted inaccurate technical advice to an internal forum without approval. An employee reportedly followed the advice, allegedly causing an SEV1 incident in which sensitive company and user data became accessible to unauthorized employees for nearly two hours.
-
CodeWall's Autonomous Agent Reportedly Obtained Unauthorized Access to McKinsey's Lilli AI Platform Database AIID ↗
CodeWall reported that its autonomous agent exploited vulnerabilities in McKinsey's Lilli AI platform and obtained unauthorized read and write access to production systems, allegedly exposing internal chat messages, files, user accounts, and prompts. McKinsey confirmed the vulnerability and said it fixed the issue within hours, but said it found no evidence that client data or client confidential information were accessed.
-
Meta AI Smart Glasses Reportedly Routed Intimate Imagery to Reviewers at Kenyan Contractor Sama Before Meta Ended Contract AIID ↗
Meta AI smart glasses reportedly sent media and transcripts from AI interactions to Sama contractors in Kenya for human review. Workers said they saw nudity, bathroom use, sex, bank cards, and other private activity, sometimes involving people unaware they were recorded or faces left visible despite filtering. The reports prompted lawsuits and regulatory inquiries before Meta paused the work and ended its Sama contract, affecting 1,108 workers.
-
Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale AIID ↗
Anthropic said it identified large-scale campaigns that used fraudulent accounts and proxy services to generate high volumes of Claude interactions to extract model capabilities for competitor training ("distillation"). Anthropic attributed the activity to DeepSeek, Moonshot, and MiniMax and said it involved millions of exchanges across thousands of accounts, violating its terms and access restrictions. Anthropic described detection measures, account controls, and indicator-sharing in response.
-
Grok Reportedly Disclosed Adult Performer Siri Dahl's Legal Name and Birthdate, Allegedly Contributing to Doxxing and Harassment AIID ↗
Grok is reported to have publicly provided adult performer Siri Dahl's legal name and birthdate without being asked for that information. Dahl reportedly said she had worked to keep those details private and that, after the disclosure, impersonation accounts and reposts of stolen content using her legal name purportedly appeared online.
-
DJI Romo Cloud Authorization Bug Reportedly Exposed Camera, Microphone, and Home-Mapping Data From Nearly 7,000 Robot Vacuums AIID ↗
A software engineer reportedly used an AI coding assistant while attempting to reverse-engineer his DJI robot vacuum so he could control it with a video game controller. In the course of that work, he reportedly said he discovered that credentials used to communicate with DJI's cloud servers could also grant access to data associated with nearly 7,000 other vacuums across 24 countries, including live camera feeds, microphone audio, maps, and status information.
-
Moltbook Database Exposure Allegedly Revealed Users' Private Communications and API Authentication Tokens AIID ↗
Wiz researchers reported accessing an exposed Moltbook database in under three minutes, allegedly obtaining ~35,000 email addresses, thousands of private DMs, and ~1.5 million API authentication tokens. The exposure was described as enabling read/write access and potential impersonation or manipulation of "AI agent" accounts. Wiz said it disclosed the issue to Moltbook, which reportedly secured the database within hours and deleted accessed data.
-
NPR Host David Greene Alleged Google's NotebookLM Replicated His Voice Without Consent, Prompting Lawsuit AIID ↗
NPR's David Greene reportedly sued Google LLC and Alphabet in Santa Clara County, alleging NotebookLM's Audio Overviews uses a synthetic male voice that purportedly mimics his cadence and delivery without consent or compensation. The complaint reportedly cited an independent voice-recognition analysis reporting 53–60% confidence his voice trained the model. Google reportedly called the allegations baseless and said the voice is based on a paid actor.
-
Border Patrol Agent Allegedly Claimed Facial Recognition Identified Minneapolis ICE Observer and Global Entry Was Reportedly Revoked Three Days Later AIID ↗
On 01/10/2026 near Minneapolis, Minnesota, legal observer Nicole Cleland reportedly stated that a CBP Border Patrol agent stopped her vehicle, addressed her by name, and claimed agents used facial recognition to identify her while recording on body cam. She reportedly had her Global Entry and TSA PreCheck revoked on 01/13/2026, which she alleged was retaliatory intimidation, causing travel burden and chilling effects.
-
Perplexity AI Reportedly Accused in Federal Lawsuit of Purported Copyright Infringement and False Attribution of Chicago Tribune Content AIID ↗
The Chicago Tribune filed a federal lawsuit alleging that Perplexity AI unlawfully reproduced and paraphrased its copyrighted journalism in generative chatbot and search outputs. The complaint claims the AI system produced substitutive answers that bypassed links to the Tribune's website, diverted revenue, and at times hallucinated inaccurate information falsely attributed to the newspaper.
-
Secret Desires AI Platform Reportedly Exposed Nearly Two Million Sensitive Images in Cloud Storage Leak AIID ↗
The erotic AI chatbot and image-generation platform Secret Desires reportedly left nearly two million sensitive images and videos publicly exposed in misconfigured cloud storage. The leaked files reportedly included personal photos, workplace and university information, and explicit AI-generated deepfakes of women and girls. The content reportedly became inaccessible shortly after journalists contacted the platform.
-
ChatGPT Reportedly Found to Reproduce Protected German Lyrics in Copyright Case AIID ↗
A Munich regional court ruled that ChatGPT reportedly reproduced protected German song lyrics and that OpenAI's models were trained on copyrighted texts, including works by musician Herbert Grönemeyer, without authorization. The court reportedly found both memorization of nine songs and lyric output to infringe exploitation rights. OpenAI disputes the ruling and may appeal. Damages were ordered, with implications for AI training on copyrighted works.
-
Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration AIID ↗
Malicious versions of the popular Nx monorepo tool and plugins were reportedly published to npm after attackers compromised its CI workflow. The malware's postinstall script reportedly harvested credentials and exfiltrated data, reportedly weaponizing local AI coding agents such as Claude Code, Gemini, and Amazon q. By invoking unsafe flags, it allegedly coerced the tools into scanning developer machines for sensitive files, marking one of the first known AI-assisted supply chain attacks.
-
Gaggle AI Monitoring at Lawrence, Kansas High School Reportedly Misflags Student Content and Blocks Emails AIID ↗
In Lawrence, Kansas, students allege the Gaggle Safety Management AI wrongly flagged benign schoolwork, including art photos and casual messages, as child pornography or threats. The system reportedly deleted content, blocked an email records request, and led to questioning of students. Critics cite chilling effects and privacy risks. A lawsuit filed in August 2025 challenges the district's use of Gaggle as unconstitutional surveillance. Gaggle reportedly denies compromising privacy.
-
Microsoft's Windows Recall Allegedly Stores Passwords and Social Security Numbers in Preview Mode AIID ↗
Microsoft's Windows Recall, an AI-powered screenshot and retrieval tool for Copilot+ PCs, was allegedly still capturing sensitive information such as passwords, Social Security numbers, and bank details despite a built-in "filter sensitive information" feature. Independent testing reportedly found the filter failed in multiple cases. Microsoft reportedly classified Recall as a preview feature and said improvements were in progress.
-
Reported Public Exposure of Over 100,000 LLM Conversations via Share Links Indexed by Search Engines and Archived AIID ↗
Across 2024 and 2025, the share features in multiple LLM platforms, including ChatGPT, Claude, Copilot, Qwen, Mistral, and Grok, allegedly exposed user conversations marked "discoverable" to search engines and archiving services. Over 100,000 chats were reportedly indexed and later scraped, purportedly revealing API keys, access tokens, personal identifiers, and sensitive business data.
-
Reported Hack of Tea Dating App Compromises Data from Purportedly AI-Supported Identity and Image Checks AIID ↗
In July 2025, the Tea dating advice app, which purportedly uses AI-assisted tools for user verification and reverse image search, reportedly suffered a breach of a legacy storage system. Hackers allegedly accessed about 72,000 images, including selfies, photo IDs, and other content, which were purportedly circulated on 4chan. The incident reportedly exposed sensitive data of users who signed up before February 2024.
-
Alleged Malicious Wiping Command Found in Amazon Q AI Assistant AIID ↗
A reported compromise of Amazon's AI coding assistant "Q" allegedly involved the insertion of commands that, if executed, could have wiped local files and potentially affected cloud resources. The altered code was reportedly incorporated into a public release before being detected and removed.
-
CISA Acting Director Reportedly Uploaded Sensitive Government Documents to Public ChatGPT Instance AIID ↗
Madhu Gottumukkala, acting director of the Cybersecurity and Infrastructure Security Agency (CISA), reportedly uploaded government contracting documents marked "for official use only" into a public version of ChatGPT. The uploads reportedly triggered automated cybersecurity alerts and prompted a Department of Homeland Security review to assess potential exposure of sensitive information.
-
Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update AIID ↗
Security researchers reported that the Urban VPN Proxy browser extension introduced AI conversation–harvesting functionality in version 5.5.0, released July 9, 2025. The extension allegedly intercepted and exfiltrated private conversations from AI platforms including ChatGPT, Claude, Gemini, Grok, and others without a user-facing opt-out. The data, including sensitive personal and financial information, was reportedly shared with affiliated data brokers for commercial analytics.
-
Microsoft 365 Copilot Vulnerability Allegedly Allowed File Access Without Audit Log Entry AIID ↗
A vulnerability in Microsoft 365 Copilot reportedly allowed users to access and summarize files without generating audit log entries, allegedly undermining traceability and compliance. Security researcher Zack Korman disclosed the issue to Microsoft, which reportedly classified it as "important" and fixed it on August 17, 2025, but reportedly chose not to notify customers or assign a CVE.
-
McDonald's McHire AI Recruitment Platform Reportedly Exposed Data of 64 Million Applicants via Default Login and API Vulnerability AIID ↗
Researchers Ian Carroll and Sam Curry reported that McDonald's AI-powered hiring tool, McHire (using Paradox.ai's "Olivia" chatbot), could purportedly be accessed via default admin credentials and an insecure direct object reference in an internal API. The flaws allegedly allowed viewing of applicants' personally identifiable information and chat histories. McDonald's and Paradox reportedly patched the issues within a day of disclosure; Paradox stated only five records were accessed.
-
Voice Actor Alleges Unconsented Use of AI-Generated Voice on ScotRail Trains AIID ↗
Scottish voice actor Gayanne Potter alleges her voice was used without proper consent in ScotRail's AI train announcements. She claims she had agreed to limited use of her voice data by ReadSpeaker but was not informed it would be used in a synthetic voice system called "Iona." ScotRail continues to use the voice, stating the dispute is between Potter and ReadSpeaker.
-
New Orleans Police Reportedly Used Real-Time Facial Recognition Alerts Supplied by Project NOLA Despite Local Ordinance AIID ↗
New Orleans police reportedly received real-time facial recognition alerts from a privately operated surveillance network run by Project NOLA, reportedly leading to dozens of arrests. This purported use of AI surveillance appears to conflict with a 2022 city ordinance that restricts facial recognition to specific post-incident investigations. Police are alleged to have not consistently disclosed the technology's use.
-
Serviceaide AI Platform Implicated in Health Data Exposure Affecting 483,000 Catholic Health Patients AIID ↗
An AI-linked platform operated by Serviceaide exposed sensitive health data from Catholic Health, affecting 483,000 patients. The breach stemmed from a misconfigured Elasticsearch database used in Serviceaide’s agentic AI infrastructure. Exposed information included medical records, insurance details, and login credentials. While no misuse has been confirmed, the nature of the data has prompted regulatory scrutiny and legal investigations.
-
Meta AI App Reportedly Publishes Personal Chats Without Users Fully Realizing AIID ↗
Meta launched a stand-alone AI app with a "Discover" feed allowing users to share conversations with its chatbot. Multiple reports indicate that some users may have inadvertently published highly personal interactions, including audio recordings, medical questions, legal concerns, and intimate relationship disclosures. While Meta states that sharing is opt-in, the feature's design and labeling may have led to user confusion about what would be publicly visible.
-
Reportedly Unsafe Deployment of Llama.cpp Reveals Interactive AI-Generated CSAM Roleplay Prompts AIID ↗
A study by UpGuard reports that misconfigured llama.cpp servers publicly exposed user prompts, including hundreds of interactive roleplay scenarios. Some prompts explicitly described fictional sexual abuse of children aged 7–12. While no real children were involved, the findings demonstrate how open-source LLMs can be exploited to generate AI-enabled child sexual abuse material (CSAM).
-
GenNomis AI Database Reportedly Exposes Nearly 100,000 Deepfake and Nudify Images in Public Breach AIID ↗
In March 2025, cybersecurity researcher Jeremiah Fowler discovered an unprotected database linked to GenNomis by AI-NOMIS, a South Korean company offering face-swapping and "nudify" AI services. The exposed 47.8GB dataset included nearly 100,000 files. Many depicted explicit deepfake images, some involving minors or celebrities. No personal data was found, but the breach was a serious failure in data security and consent safeguards in AI image-generation platforms.
-
Alleged Fraudulent Prompts via AIXBT Dashboard Led Purported AI Trading Agent to Transfer 55.5 ETH from Simulacrum Wallet AIID ↗
A reported hacker attack allegedly compromised the autonomous AI crypto bot AIXBT, purportedly resulting in the theft of 55.5 ETH (approximately $106,200). The attacker is reported to have infiltrated the secure dashboard of the AIXBT autonomous system at 2:00 AM UTC on March 18, 2025, and allegedly queued two fraudulent prompts that instructed the AI agent to transfer funds from its simulacrum wallet.
-
Alleged ChatGPT Misuse by Contractor Leads to Reported Data Exposure in New South Wales Resilient Homes Program AIID ↗
A former contractor of the New South Wales Reconstruction Authority reportedly uploaded a spreadsheet containing personal and health information of Resilient Homes Program applicants to ChatGPT during a three-day period in March 2025. Up to 3,000 people may have reportedly been affected.
-
Alleged Inclusion of 12,000 Live API Keys in LLM Training Data Reportedly Poses Security Risks AIID ↗
A dataset used to train large language models allegedly contained 12,000 live API keys and authentication credentials. Some of these were reportedly still active and allowed unauthorized access. Truffle Security found these secrets in a December 2024 Common Crawl archive, which spans 250 billion web pages. The affected credentials could have been exploited for unauthorized data access, service disruptions, financial fraud, and a variety of other malicious uses.
-
Microsoft Copilot Reportedly Able to Access Cached Data from Since-Private GitHub Repositories AIID ↗
Lasso Security reported that Microsoft Copilot could return content from GitHub repositories that had been public briefly but later set to private or deleted. Lasso attributed this to Bing's caching system, which stored "zombie data" from over 20,000 repositories. The cached content allegedly included sensitive information such as access keys, tokens, and internal packages. Microsoft reportedly classified the issue as low severity and applied only partial mitigations.
-
Purported Graphite Spyware Linked to Paragon Solutions Allegedly Deployed Against Journalists and Civil Society Workers AIID ↗
Researchers at Citizen Lab and Censys reportedly identified spyware infections involving Graphite, a tool attributed to Israeli firm Paragon Solutions. The spyware was allegedly deployed against civil society actors, including journalists and aid workers, through a zero-click WhatsApp exploit. WhatsApp notified over 90 targeted individuals. Evidence reportedly suggests deployments in multiple democratic countries.
-
Meta AI Bug in Deployed Service Reportedly Allowed Potential Access to Other Users' Prompts and Responses AIID ↗
A security researcher reported a vulnerability in Meta AI's deployed chatbot service that, under certain conditions, could allow an unauthorized user to view another user's prompts and AI-generated responses. The flaw reportedly involved guessable prompt IDs and insufficient server-side authorization checks. Meta reportedly fixed the issue in January 2025 and found no evidence of malicious exploitation, awarding the researcher a bug bounty.
-
Alleged AI-Powered Call Center Breach Exposes Over 10 Million Conversations in the Middle East AIID ↗
An AI-powered call center platform in the Middle East reportedly experienced a significant data breach, allegedly exposing over 10 million conversations between consumers, operators, and AI agents. Attackers allegedly accessed the platform’s management dashboard, stealing sensitive data, including national ID documents. The breach poses reported risks such as phishing, identity theft, and social engineering attacks. The stolen data was reportedly listed for sale on the dark web.
-
AI Avatar of Murder Victim Created Without Consent on Character.ai Platform AIID ↗
A user on the Character.ai platform created an unauthorized AI avatar of Jennifer Ann Crecente, a murder victim from 2006, without her family's consent. The avatar was made publicly available, violating Character.ai's policy against impersonation. After the incident surfaced, Character.ai removed the avatar, acknowledging a policy violation.
-
AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions AIID ↗
AI-powered meeting assistants, such as Otter.ai's OtterPilot and Zoom's AI Companion, have reportedly shared sensitive and private conversations beyond the intended audience. These tools, which are set to automatically record and distribute meeting transcripts, allegedly sent confidential discussions after participants had left the meeting, the consequences of which led to unintended exposure of proprietary information and privacy breaches.
-
ChatGPT Reportedly Introduces Errors in Critical Child Protection Court Report AIID ↗
A child protection worker in Victoria, Australia reportedly used ChatGPT to draft a report submitted to the Children's Court. The purportedly AI-generated report contained inaccuracies and downplayed risks to the child, allegedly resulting in a privacy breach when sensitive information was shared with OpenAI.
-
Clearview AI Reportedly Faces $33.7 Million Fine for Violating GDPR with Biometric Data Harvesting AIID ↗
Clearview AI was reportedly fined $33.7 million by the Dutch data protection authority for allegedly creating an illegal facial recognition database by scraping billions of images from the Internet without consent. The company allegedly used AI to convert these images into biometric data and sold the service to law enforcement. This act was reportedly in violation of privacy laws and the GDPR.
-
Chatbot in Workplace Training at Bunbury Prison Reveals Real Names in Sexual Harassment Case AIID ↗
During workplace training at Bunbury Prison in Western Australia, a trainer used Microsoft's Copilot AI chatbot to generate case study scenarios. The chatbot produced a scenario that included the real name of a former employee involved in a sexual harassment case, revealing sensitive information.
-
Gemini AI Allegedly Reads Google Drive Files Without Explicit User Consent AIID ↗
Kevin Bankston, a privacy activist, claims that Google's Gemini AI scans private Google Drive PDFs without explicit user consent. Bankston reports that after using Gemini on one document, the AI continues to access similar files automatically. Google disputes these claims, stating that Gemini requires proactive user activation and operates within privacy-preserving settings.
-
NullBulge's AI-Powered Malware Allegedly Compromises Disney Employee and Internal Data AIID ↗
A Disney employee, Matthew Van Andel, reportedly downloaded AI-powered malware allegedly developed by the cybercriminal group NullBulge, resulting in a major cybersecurity breach. Hackers purportedly accessed Disney's Slack system, exposing 44 million internal messages, employee and customer data, and financial records. NullBulge also reportedly leaked Van Andel’s personal financial information, leading to identity theft and his eventual termination.
-
OpenAI's ChatGPT Mac App Stored User Data in Unencrypted Text Files AIID ↗
OpenAI's ChatGPT macOS app stored user conversations in plain text. If accessed by a malicious actor, these conversations could have been easily read. The critical security flaw was demonstrated by a third party and ultimately resolved after OpenAI released an update to encrypt the stored data.
-
Auto Insurers Allegedly Are Surreptitiously Collecting and Scoring Driver Data AIID ↗
The insurance industry allegedly uses AI and telematics to score drivers based on behaviors tracked by automakers and apps like Life360. Data, often collected without clear consent, may affect insurance rates and raises privacy concerns. Consumers are largely unaware of this surveillance, leading to potential misuse and discrimination based on driving habits or socioeconomic factors.
-
Reportedly Hacked AI-Powered Robot Vacuums Allegedly Used for Surveillance and Harassment AIID ↗
Hackers reportedly exploited a vulnerability in Ecovacs’s Deebot X2 robot vacuums, gaining unauthorized access to camera and microphone controls. Users reported privacy invasions and offensive language broadcasted through the devices. Although Ecovacs claimed to have resolved the security flaw, researchers suggest vulnerabilities remain that could potentially leave users exposed to surveillance and harassment through their AI-enabled devices.
-
Scarlett Johansson Alleges OpenAI's Sky Imitates Her Voice Without Licensing AIID ↗
OpenAI unveiled a voice assistant with a voice resembling Scarlett Johansson's, despite her refusal to license her voice. Johansson claimed the assistant, "Sky," sounded "eerily similar" to her voice, leading her to seek legal action. OpenAI suspended Sky, asserting the voice was from a different actress.
-
AI Firm Lovo Reportedly Accused of Illegally Replicating Voice Actors' Voices AIID ↗
Two voice actors, Paul Skye Lehrman and Linnea Sage, are reportedly suing AI start-up Lovo for allegedly creating and promoting unauthorized clones of their voices. Lovo's synthetic voices were allegedly discovered in various media, including a podcast and promotional videos. The actors claim they were misled into providing voice samples, which were then allegedly used without consent, violating trademark and privacy laws.
-
OpenAI, Google, and Meta Alleged to Have Overstepped Legal Boundaries for Training AI AIID ↗
In late 2021, OpenAI and other tech giants like Google and Meta reportedly faced data shortages for training AI models. OpenAI is said to have developed a tool called Whisper to transcribe over one million hours of YouTube videos, potentially violating YouTube’s terms of service. Similarly, Google allegedly transcribed YouTube videos, risking copyright infringements. Meta reportedly explored summarizing copyrighted texts without permission and debated acquiring Simon & Schuster for data.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.