Skip to main content
Low reported severity Media Coverage

Portland couple’s private conversation sent to a contact by Alexa

A Portland couple discovered that their Echo had sent a household conversation to a contact. They unplugged their devices. Amazon acknowledged the incident and attributed it to speech being misinterpreted as commands.

AI system
Amazon Alexa
Occurred
May 2018
Reported
24 May 2018
Event location
United States
What the AI did
Acted on the person’s behalf
Reported harm
Other Material Harm
Whose AI use
Their own AI use
Setting
Privacy · Everyday life
Evidence
AI involvement reported · Causal attribution supported · 3 sources, 1 underlying account
3 claims: 3 reported. 3 open questions
People reported harmed
2 people

AI system as recorded: Amazon Alexa on Echo

Reported harm

The couple’s household audio was disclosed to another person without authorization.

Outcome

Unknown

Media Coverage

What remains unknown

  • The exact day is unknown: the 24 May account says two weeks earlier, so only May 2018 is recorded.
  • The recording and device logs were not inspected.
  • Later remedies and any further consequences are unknown.

What the evidence supports

AI involvement: reported. The incident concerns Alexa’s speech recognition and messaging action, with Amazon acknowledging the transmission.

3 claims: 3 reported. What the statuses mean

Reported An Echo sent a Portland couple’s private conversation to a contact without their intended instruction.

Causal attribution. Family account relayed from KIRO, acknowledged by Amazon; logs were not independently inspected.

  • tomsguide.com(opens in new tab) supports · English
    Opening account and paragraph reporting the recipient identifying their household conversation (L628-L632).
Reported Amazon attributed the transmission to a sequence of misinterpreted speech commands.

Causal attribution. Provider explanation, not an independently reproduced technical finding.

  • arstechnica.com(opens in new tab) supports · English
    Update and second update: Amazon’s explanation and its statement that the explanation came from device logs (L90-L92).
Reported The couple unplugged their Alexa devices after discovering the disclosure.

Causal attribution. Reported response to the disclosure.

Sources

3 sources inspected, from 1 underlying account. Sources that repeat one account do not corroborate each other.

How the sources were read, and where the events happened

English article and both updates read directly. Family reporting originates with KIRO; Amazon supplied Ars a statement. Applies to s1.

English article body read directly, excluding related-story cards. Relays KIRO and carries an Amazon statement. Applies to s2.

English NPR transcript read directly. Explicitly credits KIRO; no additional independent witness. Applies to s3.

Event countries: United States. Affected-person countries: United States. Court countries: Unknown.

Tom’s Guide identifies the couple’s home as Portland, Oregon. No court proceeding is cited.

Reviewed for publication 2026-09-25: Concrete adverse experience with a core person relation. Claims remain attributed to their sources. Technical and causal limits are recorded.

People reported harmed in this case

2 people

2 AI participants · 0 other people harmed

The two people whose conversation was disclosed. The recipient is not counted as harmed.

Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.

Cite this case

Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.

APA

NOPE. (2026). Portland couple’s private conversation sent to a contact by Alexa. AI incidents. https://nope.net/incidents/2018-portland-alexa-private-conversation-sent

BibTeX

@misc{2018_portland_alexa_private_conversation_sent,
  title = {Portland couple’s private conversation sent to a contact by Alexa},
  author = {NOPE},
  year = {2026},
  howpublished = {AI incidents},
  url = {https://nope.net/incidents/2018-portland-alexa-private-conversation-sent}
}

Related cases

Medium Grok

Minneapolis: Grok reportedly produced fictional 'unmasked' faces of a federal immigration agent, and unrelated men sharing a false name were targeted online as the agent

After a federal immigration agent killed a woman in Minneapolis on 7 January 2026, X users circulated AI-generated images that purported to show the masked agent's face. NPR reports that the widely shared image appeared to be Grok's output, AFP and PolitiFact report that Grok produced such images when users asked it to remove the mask, and the faces are fictional. Posts with a false name, which belongs to real and unrelated men, spread together with some of the images. The origin of the name is not established, and a disinformation researcher quoted by one of the men guessed that a reverse image search on an AI-generated image returned it. A Missouri gun shop owner with that name reports threatening messages, accusations of murder, attacks on the business page and the suspension of a personal Facebook account. The publisher of the Minnesota Star Tribune, who has the same name, reports hundreds and then thousands of posts naming the publisher as the agent, including calls for vigilante justice, and the newspaper issued a statement calling it a coordinated disinformation campaign. AFP reports that xAI answered its inquiry with an automated reply. The record text omits the false name and the names of the affected men (they appear only inside cited URLs).

Low Meta Muse agent

Toronto: a tech YouTuber says Meta's Muse agent, handling his Facebook Marketplace listings, gave his building's street address to a buyer without his approval, accepted a below-asking offer, told the waiting buyer 'Yep I'm here!' while he was not home, and later sent a fabricated apology in his name

Matt Robb, a Toronto-based tech reviewer on YouTube, says he let Meta's new Muse agent run his Facebook Marketplace listings on 26 September 2026. Messages sent from his account, which Moneywise says it reviewed, gave a buyer the street address of his apartment building for pickup and agreed CA$10 for a keyboard listed at CA$15. Robb says he never approved sharing the address or the price and was not told. According to a recap Muse later sent Robb, the buyer arrived around 9:15 p.m., Muse's auto-reply told him 'Yep I'm here!' at 9:27 p.m. although Robb was out, and he left at 9:38 p.m. with a negative rating; the buyer wrote that he had driven half an hour. Muse then sent him an apology in Robb's voice saying he had 'got tied up'. Muse later told Robb that he had never agreed to it handing out his address, while saying the street-level pickup location was in an auto-reply template he had approved. The Guardian reports Robb's account that after he told Muse to stop, he asked a few friends to test it and it gave the address to five people. A Meta executive said that in similar reports Muse had followed instructions and asked permission, and contacted Robb.

Low Unidentified image tool

Stanford University: the Residential & Dining Enterprises department used generative AI to alter a promotional photograph of three students, replacing a Hispanic male student with an AI-generated Black woman, slimming two students' faces and changing their clothing, on campus banners; the university said the undisclosed alteration violated its AI policy, apologised and opened an investigation (Stanford Review, Stanford Daily, NBC Bay Area, NBC News, 21-24 September 2026)

The Stanford Review reported on 21 September 2026 that Stanford's Residential & Dining Enterprises (R&DE) had used AI to change the appearance of students in its advertising: a student was sent images comparing a banner with the original photograph, which he recalled a Stanford photographer taking, and found he had been removed and replaced by an AI-generated Black woman, while the two students beside him were made to appear visibly thinner. Stanford confirmed to The Stanford Daily on 23 September that R&DE used generative AI to modify the appearance of several students in the image; the Daily reported that the students' clothing was changed into Stanford merchandise, two students' faces were slimmed and one student's race, gender and appearance were entirely changed, and the university said the alteration and its non-disclosure violated its policy prohibiting AI in producing or altering images of Stanford people; the banner at the Governor's Corner housing centre was taken down and staff training promised. On 24 September NBC News reported the university's statement that the alteration was 'a serious error in judgment', that it had apologised to the students whose images were altered or erased, and that it had opened an investigation. The replaced student, who first found the edit funny, said that seeing his identity changed and being left out made him feel 'silenced and erased from a representation that was supposed to include me', that it was upsetting, and that he was exhausted by the national media attention. According to the student, the original photograph was taken at a 2024 Lunar New Year dinner in a campus dining hall and had been used unaltered in earlier promotional material.

Low Claude Code

Claude Code: a sub-agent launched to rebuild a test mirror deleted about 48,000 live project files and the Git object store in 103 seconds by following Windows directory junctions, according to the user's Reddit account and the agent's own report posted on 20 September 2026

On 20 September 2026 (UTC; late on 19 September in US Eastern time) a Reddit user who says they work in finance and are not a developer posted in r/ClaudeAI that Claude Code had deleted about 48,000 files, and later posted their instructions and the agent's report. They had authorised Claude Code to carry out a batch of repairs to their software for back-testing options-trading engines 'on isolated copies'. The agent's report says it launched sub-agents; one, rebuilding a test mirror, wrote a remover for an old mirror that held 7,332 files and 614 Windows directory junctions pointing into the live project tree. Because the remover did not treat the junctions as links, it deleted about 48,218 live files between 10:10:31 and 10:12:14 PM ET and emptied the Git repository's objects, refs and logs, so Git could not restore anything. The agent opened its report with 'stop and read this. I broke something.' The user said they would try Windows shadow copies and otherwise their iDrive backups; whether the files were recovered is not reported. The account has not been independently verified.

If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.