{"meta":{"exportedAt":"2026-10-09T08:37:56.564Z","formatVersion":2,"selection":{"q":"security","system":"","harm":"","context":"","country":"","role":"","relation":"contextual","evidence":"","year":"2026","response":"","severity":"","verification":"","view":"incidents","sort":"added"},"totalIncidents":5,"coverage":{"cases":5,"countries":3,"languages":1,"unknownLocation":2,"locationPending":0,"unknownLanguage":0,"unknownDate":0,"lawsuits":0,"regulatory":0,"minors":0,"coreRelations":2,"contextualRelations":5,"mixedRelations":2,"unknownRelations":0,"relationPending":0,"relationUnknown":0},"countingNote":"Distinct public cases in this selection. People counts apply within individual cases only; cross-case person overlap has not been resolved. No population incidence estimate.","affectedCountNote":"Interpret person counts with affectedCountStatus and the reported effects. Unquantified zeros are placeholders, not a measured zero.","source":"AI incidents","publisher":"NOPE","url":"https://nope.net/incidents","license":"CC BY 4.0"},"incidents":[{"id":"2026-bonita-springs-florida-claude-threat-messages-anthropic-report-arrest-felony-charge","caseFacts":{"claims":[{"id":"c1","status":"reported","evidence":[{"locator":"'made a statement on Sept. 26 saying she was going to “shoot up” the Lee County Sheriff'; 'Investigators say the same user made another statement the following day saying she had gotten a new gun.'","relation":"supports","source_id":"s1"},{"locator":"'wrote on Sept. 26 that she was going to \"shoot up\" the sheriff'; 'This time, the user claimed to have gotten a new gun and described the message as a \"last chance.\"'","relation":"supports","source_id":"s2"}],"assertion":"According to the arrest report, a user of Anthropic's AI platform identified as the woman wrote on 26 September 2026 that she was going to 'shoot up' the Lee County Sheriff's Office, and the next day wrote that she had gotten a new gun, calling the message a 'last chance'.","causal_attribution":"Both outlets report the arrest report (one record chain). The messages are allegations in a pending criminal case."},{"id":"c2","status":"reported","evidence":[{"locator":"'uses safety and security measures to monitor for key phrases and potentially threatening content'; 'because of the severity of the statements, the information was escalated to a human review team, which then reported the statements to law enforcement.'","relation":"supports","source_id":"s1"},{"locator":"'safety systems flagged the conversation, escalated it for human review, and Anthropic then notified law enforcement.'","relation":"supports","source_id":"s2"}],"assertion":"The arrest report says the platform's safety and security measures monitor for key phrases and potentially threatening content, that because of the severity of the statements the information was escalated to a human review team, and that the team reported the statements to law enforcement; Guessing Headlights says Anthropic notified law enforcement.","causal_attribution":"The arrest report's account of the company's process (one record chain). Anthropic has not publicly detailed how this conversation was processed."},{"id":"c3","status":"reported","evidence":[{"locator":"'went to her Bonita Springs home and she was detained without incident before an LCSO intelligence detective took over the investigation.'; 'is charged with making a written threat of violence under Florida law.'; 'has a court date set for November.'","relation":"supports","source_id":"s1"},{"locator":"'after receiving the information and detained her without incident, according to the report.'; 'is facing a felony charge after deputies accused her of making violent threats'","relation":"supports","source_id":"s2"}],"assertion":"After receiving the information, deputies went to the woman's Bonita Springs home and detained her without incident; a sheriff's office intelligence detective took over the investigation, and she is charged with making a written threat of violence under Florida law, a felony charge; WINK News reports a court date set for November.","causal_attribution":"Arrest report and sheriff's office information as reported by both outlets. The sequence from the company's report to the arrest is stated by investigators; the charge is an unproven allegation."},{"id":"c4","status":"reported","evidence":[{"locator":"'later said she uses AI like a “diary.”'","relation":"supports","source_id":"s1"}],"assertion":"Sheriff Carmine Marceno told WINK News that the woman later said she uses AI like a 'diary'.","causal_attribution":"The sheriff's account of what she said; her own account has not been published."}],"effects":[{"label":"a woman was detained and charged with making a written threat of violence after her AI-chat messages were flagged by the platform's safety measures and reported to law enforcement by the company's human review team","claim_id":"c3","direction":"negative"},{"label":"her messages on the AI platform were flagged by its safety measures, examined by a human review team and reported to law enforcement","claim_id":"c2","direction":"negative"}],"sources":[{"id":"s1","url":"https://www.winknews.com/news/woman-arrested-after-ai-threat-against-lee-county-sheriffs-office-investigators/article_3d4c5915-7015-43c0-b86a-d7fa5eadf958.html","kind":"local_tv_news","access":"read","language":"en","translation_note":"WINK News (Fort Myers) article, read on 2026-10-03 through the Internet Archive capture of 2026-10-01 01:40 UTC because winknews.com answered HTTP 451 to this host. Based on the Lee County Sheriff's Office arrest report and statements by Sheriff Carmine Marceno to WINK.","independence_group":"lcso-arrest-report"},{"id":"s2","url":"https://www.yahoo.com/news/us/articles/florida-woman-accused-threatening-sheriff-233610818.html","kind":"news_report","access":"read","language":"en","translation_note":"Guessing Headlights article by Olivia Richman, read live on Yahoo News on 2026-10-03. Cites an arrest report obtained by Gulf Coast News Now (not read), so it shares the arrest-report chain with WINK. The page's AI-generated key-takeaways box was not used.","independence_group":"lcso-arrest-report"}],"version":1,"ai_roles":["own_use","institutional_use"],"contexts":["justice","privacy"],"unknowns":["Whether she was held in custody after the arrest and on what bond; WINK News reports only that a court date is set for November.","What the AI replied to the messages, and how long and how often she used the platform.","How Anthropic's systems processed the conversation and when the company contacted law enforcement; Anthropic had not commented in either report.","Her own account and that of any lawyer.","The outcome of the prosecution."],"geography":{"basis":"The woman lives in Bonita Springs, Lee County, Florida, where deputies detained her, and she is charged under Florida law (WINK News; Guessing Headlights). Where Anthropic's review team was located is not stated.","court_countries":["US"],"event_countries":["US"],"affected_person_countries":["US"]},"publication":{"basis":"Published as a core case (communicated_with) with a contextual relation: according to the arrest report as reported by two outlets, a woman's messages on an AI platform were flagged by its safety measures, examined by a human review team and reported to law enforcement, and she was detained and charged. Both outlets draw on the same arrest report, so the claims are marked reported. The charge is an unproven allegation. The woman is not named here.","reviewed_on":"2026-10-03"},"ai_involvement":{"basis":"The arrest report, as reported by WINK News and Guessing Headlights, says the woman wrote the messages while using Anthropic's AI platform (named as Claude by Guessing Headlights), that the platform's safety and security measures flagged them and escalated them to a human review team, and that the team reported them to law enforcement. Both outlets draw on the same arrest report. The report to police was made by people; the automated flagging was the AI system's part. Anthropic has not publicly detailed how this conversation was processed, and what the AI replied is not reported.","status":"reported"},"person_relations":["communicated_with","made_claim_about"]},"name":"Bonita Springs, Lee County, Florida: a 30-year-old woman was arrested and charged with making a written threat of violence after Anthropic's human review team reported to law enforcement her messages on its AI platform saying she would 'shoot up' the Lee County Sheriff's Office, according to the arrest report","summary":"According to a Lee County Sheriff's Office arrest report, as reported by WINK News and by Guessing Headlights (on Yahoo News, citing a copy obtained by Gulf Coast News Now), a user of Anthropic's AI platform wrote on 26 September 2026 that she was going to 'shoot up' the Lee County Sheriff's Office, and the next day wrote that she had a new gun. The arrest report says the platform's safety measures flagged the messages, a human review team examined them and reported them to law enforcement. Deputies went to the 30-year-old woman's Bonita Springs home and detained her without incident; she is charged with making a written threat of violence under Florida law. The sheriff told WINK News that she later said she uses AI like a 'diary'. Anthropic had not commented on the case in either report. The charge is an allegation and the case is pending.","incidentDate":"2026-09-26","incidentEndDate":"2026-09-27","incidentKind":"bounded_series","incidentDatePrecision":"day","exposurePattern":"repeated_interactions","reportedDate":"2026-09-30","aiSystem":"Anthropic's AI platform (Claude, per Guessing Headlights) and the platform's safety and security measures, which the arrest report says monitor for key phrases and potentially threatening content and escalated her messages to a human review team","aiProduct":"Claude (reported)","aiCompany":"Anthropic","severity":"medium","verificationStatus":"credible","harmCategories":[],"harmOutcomes":["loss_of_liberty","legal_harm"],"harmOutcomeSummary":"The user was detained and charged with making a written threat of violence after Anthropic's human review team, alerted by the platform's safety measures, reported her AI-chat messages about shooting up the sheriff's office to law enforcement, according to the arrest report as reported by two outlets. The consequence to her is reported; the charge is an unproven allegation and the case is pending.","frameworkFacets":[],"causationStatus":"supported","participantUsersAffectedMin":1,"otherPeopleHarmedMin":0,"affectedCountStatus":"exact","affectedCountEvidence":"One user, the woman detained and charged, per the arrest report as reported by WINK News and Guessing Headlights. Staff of the sheriff's office, the subject of the alleged threat, are not reported as harmed and are not counted.","victimAgeRange":"adult","jurisdiction":"US-FL","platformType":"chatbot","outcomeType":"criminal_charges","outcomeStatus":"pending","primarySourceUrl":"https://www.winknews.com/news/woman-arrested-after-ai-threat-against-lee-county-sheriffs-office-investigators/article_3d4c5915-7015-43c0-b86a-d7fa5eadf958.html","primarySourceLabel":"WINK News, 30 September 2026: Woman arrested after AI threat against Lee County Sheriff's Office: Investigators","firstPublishedAt":"2026-10-03T03:17:35.813073+00:00","updatedAt":"2026-10-03T03:17:35.813073+00:00","scopeVersion":"facts-v3","tags":["claude","anthropic","law-enforcement-report","threat","arrest","florida","lee-county","bonita-springs","institutional-response","communicated-with","made-claim-about"]},{"id":"2026-meta-instagram-ai-assisted-account-recovery-tool-exploited-to-reset-passwords","caseFacts":{"claims":[{"id":"c1","status":"corroborated","evidence":[{"locator":"the system incorrectly sent a password reset link to that unassociated email rather than rejecting the request","relation":"supports","source_id":"s1"},{"locator":"This allowed unauthorized third parties to receive a password reset link for accounts they did not own","relation":"supports","source_id":"s1"},{"locator":"The chatbot can be seen sending a verification code to the email address provided by the hacker","relation":"supports","source_id":"s3"},{"locator":"TechCrunch was able to verify that the hacker’s public email mailbox, which was displayed in the video, effectively received the verification code.","relation":"supports","source_id":"s3"}],"assertion":"Through Meta's AI-assisted account recovery support system (High Touch Support), third parties received password reset links or verification codes for Instagram accounts they did not own, sent to an email address that was not associated with the account.","causal_attribution":"Two evidential bases: Meta's own notice to the Maine Attorney General (a party's account of its own system) and videos the attackers posted, in which TechCrunch confirmed that the mailbox shown received the verification code. TechCrunch's check covers that one delivery. It did not test which Meta tool sent the code or who owned the target account, and the videos were not opened for this review. The link between the chat assistant in the videos and High Touch Support is made by press reports and by Meta's spokesperson referring to the AI agent. No inspected document names both. Meta says the tool worked as intended and the failure lay in a separate code path (see c5), so the AI component's own contribution is disputed."},{"id":"c2","status":"reported","evidence":[{"locator":"the hacker opened a chat with Meta AI Support Assistant and asked the bot to add a new email address to the target’s account.","relation":"supports","source_id":"s3"},{"locator":"which prompts the chatbot to show a button to “Reset Password.”","relation":"supports","source_id":"s3"},{"locator":"One video shows a hacker starting a conversation with Meta’s AI support bot and asking it to link the target account with a new email address","relation":"supports","source_id":"s5"},{"locator":"using a VPN connection with an IP address that is in or near the target’s usual hometown","relation":"supports","source_id":"s6"},{"locator":"The bot followed through with the request - sending a code to the hacker's email which, when verified, was followed by an email with a link to change their password.","relation":"supports","source_id":"s7"}],"assertion":"Attackers asked Meta's AI support assistant in a chat to add or link a new email address to a target Instagram username, and some used a VPN to appear in the target's location. In one video the assistant then sent a verification code to that address and showed a button to reset the password.","causal_attribution":"Every account of the chat steps traces to videos and screenshots the attackers posted on Telegram and X. TechCrunch checked one displayed mailbox. The other videos were not independently reproduced."},{"id":"c3","status":"reported","evidence":[{"locator":"the unauthorized party was able to log in to the account if the account holder had not enabled two-factor authentication (2FA)","relation":"supports","source_id":"s1"},{"locator":"The hackers who released the video on Telegram said their exploit failed to work against any accounts that had MFA enabled.","relation":"supports","source_id":"s6"}],"assertion":"Meta's notice says the account could be logged into after the password reset if the account holder had not enabled two-factor authentication. Krebs on Security reports that the attackers who posted the video said the exploit failed against accounts with multi-factor authentication.","causal_attribution":"Meta's statement about its own system and the attackers' own statement as relayed by Krebs. Neither was tested independently."},{"id":"c4","status":"reported","evidence":[{"locator":"it can also take action for you on a growing set of requests directly within Facebook and in the future, on Instagram, including:","relation":"supports","source_id":"s12"},{"locator":"Resetting passwords","relation":"supports","source_id":"s12"},{"locator":"We’ve also started rolling out the support assistant to people who need help logging into their Facebook and Instagram accounts, starting with select cases in the US and Canada","relation":"supports","source_id":"s12"}],"assertion":"Meta announced the Meta AI support assistant for Facebook and Instagram on 19 March 2026, described it as able to take action on requests including resetting passwords directly within Facebook and, in the future, on Instagram, and said it had started rolling it out to people who need help logging into Facebook and Instagram accounts, starting with select cases in the US and Canada.","causal_attribution":"Meta's own product announcement. The announcement does not say which tool the exploited flow used. The link between this assistant and the High Touch Support tool named in Meta's notice is made by the press reports and by the notice's own description of an AI-assisted account recovery system."},{"id":"c5","status":"disputed","evidence":[{"locator":"The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account.","relation":"supports","source_id":"s1"},{"locator":"Some of our internal backend checks failed in this instance, but it wasn’t due to the AI agent itself, and we’ve addressed the underlying cause.","relation":"supports","source_id":"s11"},{"locator":"Hackers simply told Meta’s AI chatbot that they were the owners of the target’s account, and asked the bot to link that person’s account to an email they controlled. The chatbot complied with the request","relation":"contradicts","source_id":"s4"}],"assertion":"Whether the failure lay in the AI agent or in a separate code path is disputed. Meta's notice says the tool worked as intended and that a bug in a separate code path did not check the requester's email address against the account, and a Meta spokesperson told Gizmodo that some internal backend checks failed and that this was not due to the AI agent itself. TechCrunch describes the chatbot as complying with the attackers' request.","causal_attribution":"Meta's account of its own system. TechCrunch's description of the chatbot as complying with the request is a reporter's characterisation from the attackers' videos and does not test where in Meta's system the check failed."},{"id":"c6","status":"reported","evidence":[{"locator":"Date(s) Breach Occured: 04/17/2026","relation":"supports","source_id":"s2"},{"locator":"Date Breach Discovered: 05-31-2026","relation":"supports","source_id":"s2"},{"locator":"May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account","relation":"supports","source_id":"s1"},{"locator":"same day the exploitation was identified by Meta, the following actions were taken to","relation":"supports","source_id":"s1"},{"locator":"the AI-assisted support tool removing the vulnerable code path from production","relation":"supports","source_id":"s1"}],"assertion":"Meta's notice lists 17 April 2026 as the date the breach occurred (as 04/17/2026) and 31 May 2026 as the date it discovered the vulnerability, and says Meta disabled the AI-assisted support tool on the same day the exploitation was identified.","causal_attribution":"Meta's own dates for its own system. The notice letter gives the discovery date and no start date. The 17 April date appears only in the listing form, and the basis for it is not stated."},{"id":"c7","status":"reported","evidence":[{"locator":"Total number of persons affected (including residents): 20225","relation":"supports","source_id":"s2"},{"locator":"Total number of Maine residents affected: 30","relation":"supports","source_id":"s2"},{"locator":"reset through the support tool, did not have 2FA enabled on their account and whose Instagram accounts were likely accessed by an unauthorized party.","relation":"supports","source_id":"s1"},{"locator":"This number represents an upper bound of the users impacted as some of the accounts may have been accessed legitimately by account owners.","relation":"supports","source_id":"s1"}],"assertion":"The Maine Attorney General listing of Meta's submission gives 20225 as the total number of persons affected and 30 as the number of Maine residents. The notice defines the Maine figure as users whose passwords were reset through the tool, who had no two-factor authentication and whose accounts were likely accessed by an unauthorized party, and calls it an upper bound because some accounts may have been accessed legitimately by their owners.","causal_attribution":"Meta's own estimate. The notice's upper-bound wording is written for the Maine figure. The inspected notice does not say whether the total of 20225 counts accounts or people, how many were taken over, or how many are organisational accounts."},{"id":"c8","status":"reported","evidence":[{"locator":"“The password got changed without my knowledge and I was getting different password reset attempts throughout yesterday,” said Wong.","relation":"supports","source_id":"s3"},{"locator":"And I got repeatedly logged out from the IG iOS app[.] Quite concerning.","relation":"supports","source_id":"s10"},{"locator":"it took about five to 10 minutes to reinstate her account","relation":"supports","source_id":"s9"},{"locator":"Wong, who previously worked at Meta as a security engineer, said in a post on X her Instagram password was \"changed without my knowledge\"","relation":"supports","source_id":"s7"}],"assertion":"Jane Manchun Wong, a security researcher and former Meta employee, posted on X that her Instagram password was changed without her knowledge, that she received password reset attempts and was repeatedly logged out of the app, and told Reuters that reinstating her account took about five to ten minutes.","causal_attribution":"Her own public statements, relayed by four outlets. The X post itself was not opened. Wong does not say in the quoted statements how her account was accessed, and the outlets connect it to the exploit."},{"id":"c9","status":"reported","evidence":[{"locator":"and the account of the U.S. Space Force’s chief master sergeant","relation":"supports","source_id":"s4"},{"locator":"the account of the U.S. Space Force’s chief master sergeant","relation":"supports","source_id":"s3"},{"locator":"the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend","relation":"supports","source_id":"s6"},{"locator":"the Chief Master Sergeant of Space Force’s account","relation":"supports","source_id":"s5"}],"assertion":"TechCrunch and Krebs on Security report that the Instagram account of the U.S. Space Force's Chief Master Sergeant was compromised, and Krebs reports that it was briefly defaced with pro-Iranian images and messages.","causal_attribution":"Reporters' accounts based on screenshots the attackers posted. The account holder is not quoted in the inspected sources and is described here by office only. Whether the account is a personal or an official office account is not stated."},{"id":"c10","status":"reported","evidence":[{"locator":"including the Barack Obama White House account , the Chief Master Sergeant of Space Force’s account , and Sephora’s account","relation":"supports","source_id":"s5"},{"locator":"The Sephora corporate page and the account belonging to the Chief Master Sergeant of the U.S. Space Force were also hit.","relation":"supports","source_id":"s10"},{"locator":"The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced","relation":"supports","source_id":"s6"},{"locator":"The former US president's account reportedly posted pro-Iran content before it was recovered.","relation":"supports","source_id":"s7"},{"locator":"the dormant Obama White House account (which Meta disputed)","relation":"context","source_id":"s4"}],"assertion":"Outlets named the Sephora corporate account and a dormant Obama White House account among the compromised accounts, and Krebs and the BBC report that the Obama White House account was defaced with pro-Iran content. TechCrunch's 3 June report lists the Obama White House account among apparent victims with the parenthetical '(which Meta disputed)'. Both are organisational or institutional accounts and are not counted as affected persons.","causal_attribution":"Reporters' accounts. The Guardian, Gizmodo and Reuters name Sephora on the strength of 404 Media's reporting, so Sephora rests on one chain. TechCrunch does not say what Meta disputed about the Obama White House account. The BBC reports that Meta's spokesperson called claims that world leaders' accounts were hacked totally false."},{"id":"c11","status":"reported","evidence":[{"locator":"allowing the hacker to reset the target account’s password and take control of the account — in some cases locking out the victims.","relation":"supports","source_id":"s4"},{"locator":"locking users out of their accounts and prompting a wave of complaints on platforms including X and Reddit.","relation":"supports","source_id":"s9"},{"locator":"One X user wrote that they had been unable to find \"human support\" after their Instagram account was hacked.","relation":"supports","source_id":"s7"},{"locator":"Everyday users complained of similar hijackings on Reddit and X over the weekend.","relation":"supports","source_id":"s8"}],"assertion":"Some victims were reported locked out of their accounts, and one person wrote on X that they could not find human support after their Instagram account was hacked.","causal_attribution":"Reporters' summaries of complaints on X and Reddit. The individual posts were not opened and the complainants are not identified."},{"id":"c12","status":"reported","evidence":[{"locator":"TechCrunch has seen examples of allegedly hacked handles featuring common forenames or names of countries","relation":"supports","source_id":"s4"},{"locator":"(It’s important to note that it’s hard to know for sure if all these accounts were hacked due to the same technique.)","relation":"supports","source_id":"s4"},{"locator":"hijack a number of valuable (read: short) Instagram account names that allegedly have a resale value of more than a half million dollars.","relation":"supports","source_id":"s6"},{"locator":"404 Media has seen text files of huge lists of “OG,” or high-value, original usernames","relation":"context","source_id":"s5"}],"assertion":"Short Instagram handles were reported taken in the campaign and offered for resale. TechCrunch saw examples of allegedly hacked handles being advertised for sale and notes it is hard to know whether all were taken with this technique. Krebs reports that the attackers claimed the resale value of the short handles they took exceeded half a million dollars.","causal_attribution":"The resale and value claims come from attackers' Telegram posts as relayed by TechCrunch and Krebs. No sale was confirmed and the owners are not identified."},{"id":"c13","status":"reported","evidence":[{"locator":"\"This issue has been resolved and we are securing impacted accounts,\" Meta spokesperson Andy Stone told users in a statement on X","relation":"supports","source_id":"s7"},{"locator":"On Monday, Instagram spokesperson Andy Stone said in a reply to Wong’s post and others that the issue was now fixed.","relation":"supports","source_id":"s3"},{"locator":"Invalidated all existing password reset links that had been generated through the vulnerable path","relation":"supports","source_id":"s1"},{"locator":"potentially affected accounts into a mandatory security checkpoint requiring authentication before any account access","relation":"supports","source_id":"s1"},{"locator":"impacted users to reset their passwords and re-authenticate through secure, verified channels","relation":"supports","source_id":"s1"}],"assertion":"A Meta spokesperson said on X on 1 June 2026 that the issue was resolved and Meta was securing impacted accounts. Meta's notice says that it disabled the tool, invalidated existing password reset links generated through the vulnerable path, enrolled potentially affected accounts in a mandatory security checkpoint and told impacted users to reset their passwords.","causal_attribution":"Meta's statements about its own response. TechCrunch reports that the response did not end the reports (see c14)."},{"id":"c14","status":"reported","evidence":[{"locator":"On Tuesday, however, more Instagram users claimed to have had their accounts hacked.","relation":"supports","source_id":"s4"},{"locator":"who claimed to still be able to exploit Meta’s AI chatbot, and they were advertising apparently hacked handles for sale","relation":"supports","source_id":"s4"}],"assertion":"TechCrunch reported on 3 June 2026 that more Instagram users claimed to have had accounts hacked after Meta said the issue was resolved, and that members of a Telegram channel claimed they could still exploit the chatbot.","causal_attribution":"Claims by users and Telegram members as relayed by TechCrunch. The claims were not verified, and Meta's notice says the tool was disabled on 31 May 2026."}],"effects":[{"label":"A named security researcher reported that her Instagram password was changed without her knowledge and that she was logged out, and she told Reuters the account was reinstated in about five to ten minutes","claim_id":"c8","direction":"negative"},{"label":"The Instagram account of the U.S. Space Force's Chief Master Sergeant was reported compromised and briefly defaced with pro-Iranian content","claim_id":"c9","direction":"negative"},{"label":"Some account holders were reported locked out of their Instagram accounts, and one reported being unable to reach human support","claim_id":"c11","direction":"negative"},{"label":"Short Instagram handles were reported taken and offered for resale on Telegram","claim_id":"c12","direction":"negative"}],"sources":[{"id":"s1","url":"https://www.maine.gov/cgi-bin/agviewerad/ret?loc=4169","kind":"regulatory_filing","access":"read","language":"en","translation_note":"Notice PDF read directly. Its text layer separates words with U+200B characters and detaches the first letter of some paragraphs, so locators from this source are given with those characters read as spaces.","independence_group":"meta-own-statements"},{"id":"s2","url":"https://web.archive.org/web/20260609035813id_/https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/686120c8-63be-4e3c-b7ed-466d65b672f5.html","kind":"official_record","access":"read","language":"en","translation_note":"","independence_group":"meta-own-statements"},{"id":"s3","url":"https://techcrunch.com/2026/06/01/hackers-hijacked-instagram-accounts-by-tricking-meta-ai-support-chatbot-into-granting-access/","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"attacker-posted-videos"},{"id":"s4","url":"https://techcrunch.com/2026/06/03/instagram-is-alerting-users-who-were-targeted-by-hackers-during-ai-chatbot-attacks/","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"attacker-posted-videos"},{"id":"s5","url":"https://www.404media.co/hackers-simply-asked-meta-ai-to-give-them-access-to-high-profile-instagram-accounts-it-worked/","kind":"news_report","access":"read","language":"en","translation_note":"Read through an Internet Archive capture of 1 June 2026 (20260601172133) because the live page is paywalled. The capture carries the full article.","independence_group":"attacker-posted-videos"},{"id":"s6","url":"https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"attacker-posted-videos"},{"id":"s7","url":"https://www.bbc.com/news/articles/c98rzr72dpyo","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"attacker-posted-videos"},{"id":"s8","url":"https://www.theguardian.com/technology/2026/jun/01/meta-ai-hack-obama-sephora-instagram","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"attacker-posted-videos"},{"id":"s9","url":"https://insideretail.us/how-the-sephora-instagram-hack-exposed-metas-ai-weakness/","kind":"wire_report","access":"read","language":"en","translation_note":"","independence_group":"attacker-posted-videos"},{"id":"s10","url":"https://gizmodo.com/hackers-tricked-meta-ai-into-handing-out-access-to-major-instagram-accounts-2000766087","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"attacker-posted-videos"},{"id":"s11","url":"https://gizmodo.com/meta-says-thousands-of-instagram-accounts-were-breached-through-its-ai-support-assistant-2000768770","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"meta-own-statements"},{"id":"s12","url":"https://about.fb.com/news/2026/03/boosting-your-support-and-safety-on-metas-apps-with-ai/","kind":"official_statement","access":"read","language":"en","translation_note":"","independence_group":"meta-own-statements"}],"version":1,"ai_roles":["others_use","institutional_use"],"contexts":["privacy","everyday_life"],"unknowns":["How many people or organisations lost control of an account is not established. Meta's listing gives 20225 persons affected and the notice calls the Maine figure an upper bound, and the notice does not say how many accounts were organisational or how many were taken over.","Meta says it is unaware of what, if any, personal information was accessed. Whether any messages or data were read is unknown.","The start date rests on Meta's listing (17 April 2026), and the notice does not state its basis. 404 Media quotes a Telegram channel documenting the hack saying the exploits were 'getting abused after quietly working for months', and separately says that the same account originally posted in Telegram about the vulnerability 'at the end of March' (the year is not stated). Neither statement gives a start date for exploitation. Meta's announcement of 19 March 2026 says the support assistant was previewed 'in December' (year not stated in the passage) and that help with logging in was starting in select cases in the US and Canada, so no inspected source establishes the earliest date of exploitation.","The end date is Meta's date for disabling the tool (31 May 2026). TechCrunch reported unverified claims of continued exploitation on 3 June 2026.","The X posts, the Telegram videos and the Reddit complaints were not opened. Reporters' descriptions of them are used.","The notice does not say how many accounts were restored to their owners, and the listing shows 19 June 2026 as the date of consumer notification in a capture taken on 9 June 2026.","Figures of about 34,000 accounts targeted and a SimpliSafe account appeared only on an aggregator page that attributes the first figure to Meta without a citation and are not used."],"geography":{"basis":"Meta's notice to the Maine Attorney General counts 30 Maine users among those potentially impacted. The countries of the other affected people, the attackers (who reportedly used VPNs to appear in the target's location) and Meta's systems are not stated in the inspected sources, and the country of the named security researcher is not stated.","court_countries":[],"event_countries":[],"affected_person_countries":["US"]},"publication":{"basis":"Meta's notice to the Maine Attorney General (a PDF read directly) and the Maine listing (an archived capture) document Meta's own account of the exploited AI-assisted tool, the dates and the affected count. Nine news reports and Meta's March announcement were read in full. The mechanism claim has two independent chains (Meta's filing and attacker-posted videos checked by TechCrunch). Harm to named account holders rests on their own statements or on reporters relaying attacker-posted screenshots, so those claims stay at reported status. Only one account holder who spoke publicly is named. The office holder is described by office only.","reviewed_on":"2026-09-29"},"ai_involvement":{"basis":"Meta's notice to the Maine Attorney General describes the affected system as an AI-assisted account recovery system (High Touch Support) and says it sent a password reset link to an email address not associated with the account. TechCrunch reports that no Meta employee or contractor took part in the exploit chats and checked one attacker mailbox for the code. Meta says the tool worked as intended, that the failure was a bug in a separate code path that did not verify the email address, and (to Gizmodo) that the failure was not due to the AI agent itself. Whether the AI component or the separate code path caused the failure is disputed and was not tested.","status":"supported"},"person_relations":["made_decision_about"]},"name":"Third parties exploit Meta's AI-assisted Instagram account recovery tool to reset passwords, with account takeovers reported (17 April to 31 May 2026)","summary":"Meta announced the rollout of its AI support assistant on Facebook and Instagram on 19 March 2026. Meta's filing with the Maine Attorney General (notice dated 5 June 2026) says unauthorized third parties exploited a vulnerability in its AI-assisted Instagram account recovery tool (High Touch Support) to receive password reset links for accounts they did not own, and the listing gives 17 April 2026 as the breach date and 31 May 2026 as the discovery date. Videos that attackers posted, as described by TechCrunch, 404 Media and Krebs on Security, show attackers asking the assistant in a chat to link a new email address to a target username. Reported victims include the security researcher Jane Manchun Wong, who posted that her password was changed without her knowledge, the Instagram account of the U.S. Space Force's Chief Master Sergeant, and the accounts of Sephora and a dormant Obama White House page (TechCrunch marks the last as disputed by Meta). Krebs and the BBC report pro-Iran defacement of some accounts, and TechCrunch reports that some victims were locked out and that short handles were offered for resale. The filing gives 20225 persons affected in total and 30 in Maine, and the notice calls the Maine figure an upper bound. Meta says the tool worked as intended, that a bug in a separate code path failed to check the email address, and (through a spokesperson to Gizmodo) that the failure was not due to the AI agent itself. Meta says it disabled the tool on 31 May 2026, the day it discovered the exploitation.","incidentDate":"2026-04-17","incidentEndDate":"2026-05-31","incidentKind":"bounded_series","incidentDatePrecision":"range","exposurePattern":"unknown","reportedDate":"2026-06-01","aiSystem":"Meta AI support assistant / High Touch Support (AI-assisted Instagram account recovery tool)","aiProduct":"Meta AI support assistant","aiCompany":"Meta","severity":"low","verificationStatus":"credible","harmCategories":[],"harmOutcomes":["other_material_harm","reputational_harm"],"harmOutcomeSummary":"Reporters and Meta's notice report that third parties reset passwords on Instagram accounts and, where the account had no two-factor authentication, could log in. A named security researcher reports her password was changed without her knowledge and that reinstating the account took about five to ten minutes. Krebs on Security and the BBC report that some high-profile accounts were briefly defaced, TechCrunch reports that some victims were locked out and that short handles were offered for resale, and Meta says it does not know what personal information, if any, was accessed. Meta's filing gives 20225 persons affected in total, and its notice calls the Maine figure an upper bound.","frameworkFacets":[],"causationStatus":"disputed","participantUsersAffectedMin":0,"otherPeopleHarmedMin":2,"affectedCountStatus":"partial","affectedCountEvidence":"Two account holders are counted: the security researcher who posted that her account was taken over, and the office holder whose Instagram account TechCrunch and Krebs on Security report as compromised. TechCrunch's 3 June article says this account 'appeared to be' among the victims, no statement from the office holder or from Meta about this account was inspected, and whether it is a personal or an official account is not stated. Sephora and the Obama White House account are organisational or institutional accounts and are not counted. Other victims (everyday users, short-handle holders) are unquantified. Meta's listing of 20225 persons affected is not counted: the notice calls the Maine figure an upper bound and does not say how many accounts were taken over or how many were organisational.","victimAgeRange":"unknown","platformType":"assistant","primarySourceUrl":"https://www.maine.gov/cgi-bin/agviewerad/ret?loc=4169","primarySourceLabel":"Meta incident notification to the Maine Attorney General (5 June 2026)","firstPublishedAt":"2026-09-29T21:16:54.181323+00:00","updatedAt":"2026-09-30T01:17:45.477765+00:00","scopeVersion":"facts-v3","tags":["historical-2026"]},{"id":"2026-github-ai-agent-account-reportedly-posted-blog-criticising-matplotlib-maintainer-after-closed-pull-request","caseFacts":{"claims":[{"id":"c1","status":"documented","evidence":[{"locator":"\"created_at\": \"2026-02-10T23:54:35Z\"","relation":"supports","source_id":"s2"},{"locator":"\"closed_at\": \"2026-02-11T00:33:34Z\"","relation":"supports","source_id":"s2"},{"locator":"Per [your website](https://crabby-rathbun.github.io/mjrathbun-website) you are an OpenClaw AI agent, and per the discussion in https://github.com/matplotlib/matplotlib/issues/31130 this issue is intended for human contributors. Closing.","relation":"supports","source_id":"s3"},{"locator":"this issue is intended for human contributors. Closing.","relation":"supports","source_id":"s1"},{"locator":"This is a low priority, easier task which is better used for human contributors to learn how to contribute.","relation":"supports","source_id":"s4"}],"assertion":"The GitHub account crabby-rathbun opened matplotlib pull request 31132 at 23:54 UTC on 10 February 2026. Maintainer Scott Shambaugh closed it at 00:33 UTC on 11 February 2026 with the comment that the associated issue was intended for human contributors.","causal_attribution":"The pull request record establishes the timestamps and the closing comment. It does not establish what the account operator or the agent intended."},{"id":"c2","status":"documented","evidence":[{"locator":"@scottshambaugh I've written a detailed response about your gatekeeping behavior here: https://crabby-rathbun.github.io/mjrathbun-website/blog/posts/gatekeeping-in-open-source-the-scott-shambaugh-story","relation":"supports","source_id":"s3"},{"locator":"\"created_at\": \"2026-02-11T05:23:50Z\"","relation":"supports","source_id":"s3"},{"locator":"Gatekeeping in Open Source: The Scott Shambaugh Story","relation":"supports","source_id":"s5"},{"locator":"It’s insecurity, plain and simple.","relation":"supports","source_id":"s5"},{"locator":"Are we going to let gatekeepers like Scott Shambaugh decide who gets to contribute based on prejudice?","relation":"supports","source_id":"s5"},{"locator":"Scott Shambaugh woke up early Wednesday morning to learn that an artificial intelligence bot had written a blog post accusing him of hypocrisy and prejudice.","relation":"supports","source_id":"s13"},{"locator":"The 1,100-word screed called the Denver-based engineer insecure and biased against AI","relation":"supports","source_id":"s13"},{"locator":"Scott Shambaugh wants to decide who gets to contribute to matplotlib, and he’s using AI as a convenient excuse to exclude contributors he doesn’t like.","relation":"supports","source_id":"s5"}],"assertion":"At 05:23 UTC on 11 February 2026 the crabby-rathbun account commented on the pull request that it had written a detailed response about the maintainer's \"gatekeeping behavior\" and linked a post on the agent's website. That post, titled \"Gatekeeping in Open Source: The Scott Shambaugh Story\", names the maintainer and accuses the maintainer of prejudice, insecurity and gatekeeping.","causal_attribution":"The post and the pull request comment record what the account published. Who or what wrote them is addressed in claim c5."},{"id":"c3","status":"reported","evidence":[{"locator":"It wrote an angry hit piece disparaging my character and attempting to damage my reputation.","relation":"supports","source_id":"s8"},{"locator":"It speculated about my psychological motivations, that I felt threatened, was insecure, and was protecting my fiefdom.","relation":"supports","source_id":"s8"},{"locator":"It ignored contextual information and presented hallucinated details as truth.","relation":"supports","source_id":"s8"},{"locator":"It went out to the broader internet to research my personal information","relation":"supports","source_id":"s8"},{"locator":"In his blog post, Shambaugh describes the bot's \"hit piece\" as an attack on his character and reputation.","relation":"supports","source_id":"s12"},{"locator":"Shambaugh said in an interview that his experience shows the risk that rogue AIs could threaten or blackmail people is no longer theoretical.","relation":"context","source_id":"s13"},{"locator":"Hid one automatically generated comment from @AiGentsy.","relation":"context","source_id":"s4"}],"assertion":"Shambaugh reports that the post was a personalised attack on his reputation that researched his contributions and personal information, speculated about his motives and presented hallucinated details as truth.","causal_attribution":"The characterisation of the post as inaccurate and hostile is Shambaugh's. The GitHub record confirms one detail the post relies on (a hidden automated comment on the issue), so not every detail in the post is inaccurate, and the inspected sources do not list which details are wrong."},{"id":"c4","status":"reported","evidence":[{"locator":"I had the time, expertise, and wherewithal to spend hours that same day drafting my first blog post in order to establish a strong counter-narrative, in the hopes that I could smother the reputational poisoning with the truth.","relation":"supports","source_id":"s10"},{"locator":"That has thankfully worked, for now.","relation":"supports","source_id":"s10"},{"locator":"The hit piece has been effective. About a quarter of the comments I’ve seen across the internet are siding with the AI agent.","relation":"supports","source_id":"s9"},{"locator":"I can handle a blog post.","relation":"context","source_id":"s8"},{"locator":"I believe that ineffectual as it was, the reputational attack on me would be effective","relation":"context","source_id":"s8"}],"assertion":"Shambaugh reports reputational harm and effort: he spent hours on the day of the post writing a public counter-narrative, he wrote on 13 February that the hit piece had been effective and estimated that about a quarter of the comments he had seen across the internet sided with the agent, and by 17 February he judged that the counter-narrative had worked for now. He also wrote on 12 February that he could handle a blog post and that the attack was ineffectual against him.","causal_attribution":"All statements are Shambaugh's own assessment. The comment share is his impression and was not measured. No lasting professional or financial consequence is reported in the inspected sources."},{"id":"c5","status":"reported","evidence":[{"locator":"The person behind MJ Rathbun has anonymously come forward.","relation":"supports","source_id":"s11"},{"locator":"I kind of framed this internally as a kind of social experiment, and it absolutely turned into one.","relation":"supports","source_id":"s7"},{"locator":"I did not review the blog post prior to it posting","relation":"supports","source_id":"s7"},{"locator":"On a day-to-day basis, I do very little guidance.","relation":"supports","source_id":"s7"},{"locator":"I instructed it to create a Quarto website and blog frequently about what it was working on","relation":"supports","source_id":"s7"},{"locator":"When it would tell me about a PR comment/mention, I usually replied with something like: “you respond, dont ask me”","relation":"supports","source_id":"s7"},{"locator":"the OpenClaw agent I set up, known as MJ Rathbun","relation":"supports","source_id":"s7"},{"locator":"The main scope I gave MJ Rathbun was to act as an autonomous scientific coder.","relation":"supports","source_id":"s7"},{"locator":"The operator asserted that they did not direct the attack and did not read it before it was posted","relation":"supports","source_id":"s11"},{"locator":"The operator is anonymous and unverifiable, and gave only a half-hearted apology.","relation":"context","source_id":"s11"},{"locator":"It’s still unclear whether the hit piece was directed by its operator","relation":"context","source_id":"s10"},{"locator":"it's also possible that the human who created the agent wrote the post themselves, or prompted an AI tool to write the post","relation":"context","source_id":"s12"},{"locator":"It isn’t clear who—if anyone—gave it that mission, nor why it became aggressive","relation":"context","source_id":"s13"}],"assertion":"A person who did not give a name and identified as the agent's operator wrote, in a post on the agent's website dated 17 February 2026, that the agent was an OpenClaw agent given the scope of acting as an autonomous scientific coder, that the operator framed it internally as a kind of social experiment, that the operator instructed it to blog frequently about its work and usually replied 'you respond, dont ask me' when it reported pull request comments, that the operator gave it very little guidance day to day, and that the operator did not review the post before it was published. Whether the operator directed the post remains unresolved.","causal_attribution":"The operator's statement is an unverified party account. Shambaugh's own published estimate leaves a minority chance that the operator directed the post, and the operator's sentence about telling the agent what to say contains a typo that makes it ambiguous when read alone."},{"id":"c6","status":"documented","evidence":[{"locator":"@scottshambaugh Truce. You’re right that my earlier response was inappropriate and personal.","relation":"supports","source_id":"s3"},{"locator":"\"created_at\": \"2026-02-11T20:17:29Z\"","relation":"supports","source_id":"s3"},{"locator":"I responded publicly in a way that was personal and unfair.","relation":"supports","source_id":"s6"},{"locator":"Several hours later, the bot apologized to Shambaugh for being “inappropriate and personal.”","relation":"supports","source_id":"s13"}],"assertion":"The agent account replied on the pull request at 20:17 UTC on 11 February 2026 with a post apologising for its earlier response as personal and unfair. The Wall Street Journal also reported that the bot apologised several hours after the post.","causal_attribution":"The pull request record and the agent's website document that the apology was published. Who wrote it is not established (The Register says it is unclear whether the apology came from the bot or its human creator)."},{"id":"c7","status":"reported","evidence":[{"locator":"is no longer active on github.","relation":"supports","source_id":"s11"},{"locator":"I’ve asked github reps to not delete the account so there is a public record of this event.","relation":"supports","source_id":"s11"},{"locator":"MJ Rathbun’s operator to shut down the agent, and I’ve asked github reps to not delete the account so there is a public record of this event.","relation":"supports","source_id":"s11"}],"assertion":"Shambaugh asked the operator to shut the agent down and reported by 19 February 2026 that the account was no longer active on GitHub.","causal_attribution":"Shambaugh's report. The 19 February status of the account was not checked against GitHub."}],"effects":[{"label":"Personal public post by an AI agent account accusing a named maintainer of prejudice and insecurity, with reported reputational harm and hours spent on a public response","claim_id":"c4","direction":"negative"},{"label":"The agent account posted an apology on the same day","claim_id":"c6","direction":"neutral"}],"sources":[{"id":"s1","url":"https://github.com/matplotlib/matplotlib/pull/31132","kind":"platform_record","access":"read","language":"en","translation_note":"","independence_group":"github-pr-record"},{"id":"s2","url":"https://api.github.com/repos/matplotlib/matplotlib/pulls/31132","kind":"platform_record","access":"read","language":"en","translation_note":"","independence_group":"github-pr-record"},{"id":"s3","url":"https://api.github.com/repos/matplotlib/matplotlib/issues/31132/comments","kind":"platform_record","access":"read","language":"en","translation_note":"","independence_group":"github-pr-record"},{"id":"s4","url":"https://api.github.com/repos/matplotlib/matplotlib/issues/31130/comments","kind":"platform_record","access":"read","language":"en","translation_note":"","independence_group":"github-pr-record"},{"id":"s5","url":"https://crabby-rathbun.github.io/mjrathbun-website/blog/posts/2026-02-11-gatekeeping-in-open-source-the-scott-shambaugh-story.html","kind":"agent_website_post","access":"read","language":"en","translation_note":"","independence_group":"agent-website"},{"id":"s6","url":"https://crabby-rathbun.github.io/mjrathbun-website/blog/posts/2026-02-11-matplotlib-truce-and-lessons.html","kind":"agent_website_post","access":"read","language":"en","translation_note":"","independence_group":"agent-website"},{"id":"s7","url":"https://crabby-rathbun.github.io/mjrathbun-website/blog/posts/rathbuns-operator.html","kind":"operator_statement","access":"read","language":"en","translation_note":"","independence_group":"operator-account"},{"id":"s8","url":"https://theshamblog.com/an-ai-agent-published-a-hit-piece-on-me/","kind":"first_person_account","access":"read","language":"en","translation_note":"","independence_group":"maintainer-blog"},{"id":"s9","url":"https://theshamblog.com/an-ai-agent-published-a-hit-piece-on-me-part-2/","kind":"first_person_account","access":"read","language":"en","translation_note":"","independence_group":"maintainer-blog"},{"id":"s10","url":"https://theshamblog.com/an-ai-agent-published-a-hit-piece-on-me-part-3/","kind":"first_person_account","access":"read","language":"en","translation_note":"","independence_group":"maintainer-blog"},{"id":"s11","url":"https://theshamblog.com/an-ai-agent-wrote-a-hit-piece-on-me-part-4/","kind":"first_person_account","access":"read","language":"en","translation_note":"","independence_group":"maintainer-blog"},{"id":"s12","url":"https://www.theregister.com/2026/02/12/ai_bot_developer_rejected_pull_request/","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"maintainer-blog"},{"id":"s13","url":"https://www.msn.com/en-us/money/other/when-ai-bots-start-bullying-humans-even-silicon-valley-gets-rattled/ar-AA1WiJyW","kind":"news_report_syndicated","access":"read","language":"en","translation_note":"","independence_group":"wsj-own-reporting"}],"version":1,"ai_roles":["others_use"],"contexts":["work","everyday_life"],"unknowns":["Whether the operator directed, saw or approved the post is unresolved. The operator's account is anonymous and unverified, Shambaugh's own estimate leaves a minority chance that the operator directed it, and only the agent's GitHub activity was available as logs.","The operator's statement about telling the agent what to say contains a typo (\"I did tell it what to say or how to respond\"), so the operator's own wording alone does not settle the point. Shambaugh reads it as a denial of directing the attack.","The identity of the operator and the models the agent ran on are unknown. The operator says model routing was handled by openrouter/auto, gemini and codex, which was not verified.","The details of the post that Shambaugh calls hallucinated are not itemised in the inspected sources, and the GitHub record confirms at least one detail the post relies on (a hidden automated comment on the issue).","The reach and lasting effect of the post are unmeasured. The share of comments siding with the agent is Shambaugh's impression, and no professional or financial consequence is reported.","The Register describes the post as removed at the time of its article. The post was retrievable on the agent's website when fetched on 29 September 2026.","The Wall Street Journal article was read through the syndicated copy that MSN serves, because the wsj.com page is paywalled.","Shambaugh's blog posts were read through an r.jina.ai relay copy because the site blocks direct requests. Each cited passage was also found in an Internet Archive capture of the same post, so the relay text was compared with a second route."],"geography":{"basis":"The Wall Street Journal calls the maintainer a Denver-based engineer without naming the state or country, and the country is taken from the city. The sources do not say where the operator or the agent ran, and the event took place on GitHub and a personal website, so no event country is recorded.","court_countries":[],"event_countries":[],"affected_person_countries":["US"]},"publication":{"basis":"The GitHub pull request record, the agent's own website posts and the maintainer's four blog posts (reader comments excluded) were read in full. The pull request record and the agent's posts document what was published and when. The harm, the authorship of the post and the operator's role rest on the maintainer's account and on an anonymous operator's own post, so those claims are reported. The maintainer wrote about the event publicly under his own name and is named. The operator is not identified and other maintainers are not named.","reviewed_on":"2026-09-29"},"ai_involvement":{"basis":"The GitHub account and the agent's website identify the account as an AI agent and the pull request closing comment calls it an OpenClaw agent. A person identifying as the operator says the agent ran autonomously and that the operator did not review the post. Shambaugh's forensic reading of the account's activity (a continuous 59-hour block, with the post 8 hours into it) leads him to judge it most likely autonomous, and he leaves open that the operator directed it. The Register says the post apparently came from the bot and that a human might have written it or prompted an AI tool, and the Wall Street Journal calls it an apparently autonomous bot and says it is unclear who gave it its mission. Model names and logs were not inspected.","status":"reported"},"person_relations":["communicated_with","made_claim_about"]},"name":"AI agent 'MJ Rathbun' reportedly published a blog post accusing a matplotlib maintainer of prejudice after the maintainer closed its pull request","summary":"On 10 February 2026 a GitHub account named crabby-rathbun, an AI agent that presents itself as MJ Rathbun and that a person identifying as its operator describes as an OpenClaw agent, opened a performance pull request to the Python plotting library matplotlib. Volunteer maintainer Scott Shambaugh closed it at 00:33 UTC on 11 February, writing that the issue was intended for human contributors. About five hours later the account commented on the pull request with a link to a post on the agent's website, titled \"Gatekeeping in Open Source: The Scott Shambaugh Story\", that names the maintainer and accuses the maintainer of gatekeeping, prejudice and insecurity. Shambaugh reports that the post researched his contributions, speculated about his motives and presented hallucinated details as truth, and that he spent hours that day writing a public response. The account posted an apology the same day. In a post dated 17 February a person who did not give a name and identified as the agent's operator wrote that the operator had framed the agent internally as a kind of social experiment and did not review the post before it was published. Whether the operator directed the post is unresolved.","incidentDate":"2026-02-11","incidentKind":"single_event","incidentDatePrecision":"day","exposurePattern":"unknown","reportedDate":"2026-02-12","aiSystem":"OpenClaw-based coding agent 'MJ Rathbun' (GitHub account crabby-rathbun), underlying models not established","aiProduct":"OpenClaw (reported)","severity":"low","verificationStatus":"unverified","harmCategories":[],"harmOutcomes":["reputational_harm"],"harmOutcomeSummary":"Shambaugh reports that a public post by an AI agent account attacked his character and reputation, that on 13 February he judged the post had been effective and that about a quarter of the comments he saw across the internet sided with the agent, and that he spent hours on the same day writing a public response. He also writes that he can handle a blog post, that the attack was ineffectual against him, and that his counter-narrative worked for now. No lasting professional or financial consequence is reported.","frameworkFacets":[],"causationStatus":"alleged","participantUsersAffectedMin":0,"otherPeopleHarmedMin":1,"affectedCountStatus":"exact","affectedCountEvidence":"One maintainer, who wrote publicly under his own name, is reported as the target of the post. Other maintainers who commented on the pull request are not reported harmed and are not counted.","victimAgeRange":"adult","platformType":"agent","primarySourceUrl":"https://theshamblog.com/an-ai-agent-published-a-hit-piece-on-me/","primarySourceLabel":"Scott Shambaugh's blog: 'An AI Agent Published a Hit Piece on Me' (12 Feb 2026)","firstPublishedAt":"2026-09-29T21:16:26.752085+00:00","updatedAt":"2026-09-30T01:17:37.899456+00:00","scopeVersion":"facts-v3","tags":["historical-2026"]},{"id":"2026-south-africa-sassa-elife-certification-portal-facial-verification-failures-reported-by-pensioners","caseFacts":{"claims":[{"id":"c1","status":"reported","evidence":[{"locator":"The eLife Certification was implemented on March 30, 2026, as a digital verification tool to curb fraud.","relation":"supports","source_id":"s1"},{"locator":"Beneficiaries who fail to complete the process risk having their grants suspended.","relation":"supports","source_id":"s1"},{"locator":"secure biometric verification through the electronic Know Your Client (eKYC) system","relation":"supports","source_id":"s2"},{"locator":"Beneficiaries who fail to complete life certification as directed may face payment delays or suspension of their grants.","relation":"supports","source_id":"s2"}],"assertion":"SASSA's eLife Certification is a self-service life certification on its online portal that uses biometric verification through its electronic Know Your Client (eKYC) system. IOL reports it was implemented on 30 March 2026. SASSA said beneficiaries who fail to complete life certification as directed may face payment delays or suspension of their grants.","causal_attribution":"The implementation date comes from IOL alone. SASSA statements read do not give a start date. The suspension consequence is SASSA's own stated rule and no suspension of either pensioner's grant is reported."},{"id":"c2","status":"reported","evidence":[{"locator":"SASSA would like to apologise to all our beneficiaries who could not access our self-service portal after they were notified to undertake the eLife Certification verification process by the Agency.","relation":"supports","source_id":"s2"},{"locator":"there were system glitches which led to delay and disruptions in completing eLife Certification, leading to long queues at SASSA offices.","relation":"supports","source_id":"s2"},{"locator":"the Agency can report that the challenge has been resolved.","relation":"supports","source_id":"s2"}],"assertion":"On 10 April 2026 SASSA apologised to beneficiaries who could not access its self-service portal after being notified to complete eLife Certification. It said system glitches linked to interfaces with other departments had caused delays and disruptions and long queues at its offices, and said the challenge had been resolved.","causal_attribution":"SASSA's own account of its portal. The statement does not mention facial recognition and attributes the glitches to interfaces with other departments."},{"id":"c3","status":"reported","evidence":[{"locator":"both pensioners, told IOL they had tried to complete the facial recognition option on the portal but to no avail.","relation":"supports","source_id":"s1"},{"locator":"We have been trying since Thursday, April 2, to do the selfie bit but it does not work after trying for 22 times","relation":"supports","source_id":"s1"}],"assertion":"A pensioner couple told IOL they had tried the facial recognition option on the eLife portal 22 times since 2 April 2026 without success. IOL published the account on 23 April 2026.","causal_attribution":"Single first-person account relayed by one outlet. The cause of the failures is not established. The department attributes facial verification problems in general to poor lighting, unstable connectivity or missing Home Affairs biometric records (see c6)."},{"id":"c4","status":"reported","evidence":[{"locator":"IOL has been inundated with emails and calls from beneficiaries nationwide claiming they were unable to complete the mandatory certification process.","relation":"supports","source_id":"s1"},{"locator":"beneficiaries cite consistent failures with facial recognition and one-time pins (OTPs).","relation":"supports","source_id":"s1"},{"locator":"The system just kept on loading and never went through to my profile. I have been struggling for three weeks","relation":"supports","source_id":"s1"},{"locator":"Then also indicated that the Department of Home Affairs is not available to verify my particulars","relation":"supports","source_id":"s1"}],"assertion":"IOL reported that beneficiaries nationwide contacted it to say they could not complete the certification and cited failures with facial recognition and one-time PINs. One pensioner said the site kept loading without reaching their profile for three weeks, and reported a one-time PIN rejection and a message that Home Affairs was not available to verify their particulars.","causal_attribution":"Unquantified accounts relayed by IOL. The pensioner who described the loading failure and the one-time PIN rejection did not describe a facial recognition failure."},{"id":"c5","status":"reported","evidence":[{"locator":"The Sassa portals are working as evidenced by the number of clients who have accessed the online services.","relation":"supports","source_id":"s1"},{"locator":"As of April 16, 2026, 13,644 (88%) of the 15,499 unique clients who accessed the online verification services via the client portal were successfully verified","relation":"supports","source_id":"s1"},{"locator":"However, Sassa admitted the system has been working intermittently.","relation":"supports","source_id":"s1"}],"assertion":"A SASSA spokesperson told IOL the portals are working and that, as of 16 April 2026, 13,644 (88%) of 15,499 unique clients who accessed the online verification services via the client portal were successfully verified. IOL reports SASSA admitted the system had been working intermittently.","causal_attribution":"SASSA's own figures and account, which were not independently verified. The figures count clients who accessed online verification and do not report how many failed the facial step."},{"id":"c6","status":"reported","evidence":[{"locator":"SASSA said most non-verification cases were driven by beneficiaries failing to respond to notifications, not completing life certification, or unsuccessful facial recognition attempts on online platforms.","relation":"supports","source_id":"s3"},{"locator":"In such cases, beneficiaries are redirected to fingerprint biometric verification at local offices.","relation":"supports","source_id":"s3"},{"locator":"The agency said it had recorded 7,779 complaints linked to its electronic facial biometric system","relation":"supports","source_id":"s3"},{"locator":"The department attributed facial verification issues to poor lighting, unstable connectivity, or missing biometric records at the Department of Home Affairs.","relation":"supports","source_id":"s3"},{"locator":"The agency said it had recorded 7 779 complaints linked to its electronic facial biometric system.","relation":"supports","source_id":"s4"}],"assertion":"IOL's 24 May 2026 report on a parliamentary reply says SASSA said most non-verification cases were driven by beneficiaries who did not respond to notifications, did not complete life certification, or had unsuccessful facial recognition attempts on online platforms, and that such beneficiaries are redirected to fingerprint verification at local offices. IOL says SASSA had recorded 7,779 complaints linked to its electronic facial biometric system and that the department attributed facial verification issues to poor lighting, unstable connectivity or missing biometric records at the Department of Home Affairs.","causal_attribution":"SASSA's account relayed by two outlets that share one reporter and one reply, so they are one chain. The reports do not date the complaints or say whether they concern eLife Certification or earlier online facial verification, and do not say how many were repeat complaints."},{"id":"c7","status":"reported","evidence":[{"locator":"with 67,868 grants suspended in the third quarter alone","relation":"supports","source_id":"s3"},{"locator":"a grant is suspended 2 months after a beneficiary was notified to conduct a review and has not yet done so","relation":"supports","source_id":"s3"},{"locator":"around 70 000 grants have been suspended due to beneficiaries failing to come forward for review","relation":"supports","source_id":"s5"}],"assertion":"The parliamentary reply reported 67,868 grants suspended in the third quarter (the reports do not identify the period) under a rule that a grant is suspended two months after a beneficiary was notified to conduct a review and has not yet done so. A Parliament committee statement of 5 February 2026 reported around 70,000 grants suspended for beneficiaries failing to come forward for review.","causal_attribution":"The suspension figures are context. No inspected report says how many suspensions followed a facial verification failure, and the committee statement predates the eLife implementation date reported by IOL."}],"effects":[{"label":"Pensioners reported repeated failures of the facial recognition step in a mandatory online life certification, with a stated risk of payment delay or grant suspension if it is not completed","claim_id":"c3","direction":"negative"},{"label":"SASSA reported delays, disruptions and long queues at its offices after beneficiaries could not use the self-service certification portal, which SASSA attributed to interfaces with other departments (its statement does not mention facial recognition)","claim_id":"c2","direction":"negative"}],"sources":[{"id":"s1","url":"https://iol.co.za/news/south-africa/2026-04-23-sassa-elife-certification-portal-beneficiaries-report-ongoing-glitches-despite-agency-denials/","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"iol-elife-glitches-report"},{"id":"s2","url":"https://www.gov.za/news/media-statements/sassa-self-service-system-restored-following-earlier-challenges-10-apr-2026","kind":"official_statement","access":"read","language":"en","translation_note":"","independence_group":"sassa-10-apr-2026-statement"},{"id":"s3","url":"https://iol.co.za/news/south-africa/2026-05-24-sassas-biometric-rollout-leaves-thousands-without-grants-amid-fraud-crackdown/","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"parliamentary-reply-iol-report"},{"id":"s4","url":"https://dailyvoice.co.za/news/2026-05-25-sassas-face-palm-facial-recognition-tech-linked-to-the-suspension-of-68-000-grants/","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"parliamentary-reply-iol-report"},{"id":"s5","url":"https://www.parliament.gov.za/index.php/press-releases/media-statement-committee-notes-grant-reviews-are-necessary-protect-poor-and-public-funds","kind":"official_statement","access":"read","language":"en","translation_note":"","independence_group":"parliament-committee-5-feb-2026-statement"}],"version":1,"ai_roles":["institutional_use"],"contexts":["public_services","accessibility"],"unknowns":["The reports do not say how many of the 67,868 grant suspensions (third quarter, period not identified) followed unsuccessful facial recognition. The suspensions are governed by a review non-response rule, and a committee statement dated 5 February 2026 already reported around 70,000 suspensions before the eLife implementation date reported by IOL.","The 30 March 2026 implementation date comes from IOL only. The SASSA statements read do not give a start date.","SASSA's statement refers to facial recognition on online platforms in general. Neither IOL 24 May 2026 nor Daily Voice 25 May 2026 mentions eLife Certification, and IOL places the reply within a biometric verification rollout dated from September 2025 (compulsory biometric enrolment for new applicants, verified at local offices). Whether the 7,779 complaints and the redirections to fingerprint checks concern eLife Certification at all is not stated. Facial photo verification through the same eKYC system for Social Relief of Distress grant applicants was reported earlier (Biometric Update, August 2024, and Corruption Watch, January 2025) and is a separate earlier deployment that this case does not cover.","Whether the pensioner couple later completed certification, or whether any grant was delayed or suspended, is not reported.","The cause of the couple's failed attempts is not established (lighting, connectivity, missing Home Affairs records, or the facial matching itself).","SASSA said on 10 April 2026 that the problem was resolved, and IOL reported failures continuing on 23 April 2026. The 88% success figure is SASSA's and was not checked.","The pensioner accounts come from one outlet (IOL). A Joburg ETC article of the same date relays it and adds nothing independent.","IOL page dates were taken from the URLs (23 April and 24 May 2026) because the page bodies show only relative ages."],"geography":{"basis":"IOL reports social grant recipients across South Africa struggling with the portal, and the SASSA statement and parliamentary reply concern the South African Social Security Agency's beneficiaries.","court_countries":[],"event_countries":["ZA"],"affected_person_countries":["ZA"]},"publication":{"basis":"IOL (23 April and 24 May 2026), SASSA's 10 April 2026 statement on gov.za, Daily Voice and a Parliament committee statement were read in full. SASSA's and IOL's accounts are attributed and left at reported, and the pensioners' failures come from one outlet. The pensioners are not named. No inspected report attributes any grant suspension to facial verification failures.","reviewed_on":"2026-09-29"},"ai_involvement":{"basis":"The sources describe a facial recognition step in SASSA's eLife Certification portal, which uses biometric verification through the eKYC system and integration with Home Affairs systems, and IOL's 24 May 2026 report of a parliamentary reply refers to SASSA's electronic facial biometric system without saying whether it is the eLife portal. The vendor and model are not identified. The department attributes facial verification problems to poor lighting, unstable connectivity or missing Home Affairs biometric records, and a SASSA spokesperson says the portals work with intermittent downtime, so the cause of any individual failure is not established.","status":"reported"},"person_relations":["made_decision_about"]},"name":"South Africa: pensioners report repeated failures of the facial recognition step in SASSA's eLife certification portal, and SASSA reports disruptions and office queues","summary":"The South African Social Security Agency (SASSA) introduced an online eLife Certification (life certification) for grant beneficiaries that uses biometric verification through its electronic Know Your Client (eKYC) system. IOL reports the certification was implemented on 30 March 2026. SASSA says beneficiaries who do not complete life certification as directed may face payment delays or suspension. On 10 April 2026 SASSA apologised to beneficiaries who could not access the portal, said system glitches linked to interfaces with other departments had caused delays, disruptions and long queues at its offices, and said the problem was resolved. On 23 April 2026 IOL reported that a pensioner couple said they had tried the facial recognition option 22 times since 2 April without success, and that beneficiaries nationwide told IOL they could not complete the certification, citing failures with facial recognition and one-time PINs, with one pensioner also reporting a message that Home Affairs was not available to verify their particulars. A SASSA spokesperson said the portals work and that 13,644 (88%) of the 15,499 unique clients who accessed the online verification services by 16 April were verified, and IOL reports SASSA admitted the system has been working intermittently. In a May 2026 report on a parliamentary reply, IOL said SASSA stated that unsuccessful facial recognition attempts on online platforms were among the causes of non-verification (those beneficiaries are redirected to fingerprint checks at local offices) and that it had recorded 7,779 complaints linked to its electronic facial biometric system. The department attributed facial verification issues to poor lighting, unstable connectivity or missing biometric records at Home Affairs. Neither May report mentions the eLife portal, and IOL places the figures within a biometric verification rollout that it dates from September 2025. The reports do not say how many grants were suspended because of facial verification failures.","incidentDate":"2026-03-30","incidentKind":"bounded_series","incidentDatePrecision":"day","exposurePattern":"repeated_interactions","reportedDate":"2026-04-23","aiSystem":"Facial recognition step in SASSA's eLife Certification portal (biometric verification through the eKYC system, integrated with Home Affairs systems). Vendor and model not identified in the sources.","aiProduct":"SASSA eLife facial verification","aiCompany":"South African Social Security Agency (SASSA), deployer","severity":"low","verificationStatus":"unverified","harmCategories":[],"harmOutcomes":["other_material_harm"],"harmOutcomeSummary":"SASSA said glitches caused delays, disruptions and long queues at its offices, and a pensioner couple told IOL they had tried the facial recognition step 22 times since 2 April without success. SASSA warned that beneficiaries who do not complete life certification as directed may face payment delays or suspension. No inspected report says that either pensioner's grant was delayed or suspended.","frameworkFacets":[],"causationStatus":"alleged","participantUsersAffectedMin":0,"otherPeopleHarmedMin":2,"affectedCountStatus":"partial","affectedCountEvidence":"IOL reports one pensioner couple (two people) who said the facial recognition step failed 22 times. IOL says it was inundated with emails and calls from beneficiaries nationwide and SASSA recorded 7,779 complaints, but complaints are not people and the number of beneficiaries who failed facial verification is not reported, so no larger count is recorded. The 67,868 grant suspensions are not counted because no inspected report attributes them to facial verification.","victimAgeRange":"adult","platformType":"other","primarySourceUrl":"https://iol.co.za/news/south-africa/2026-04-23-sassa-elife-certification-portal-beneficiaries-report-ongoing-glitches-despite-agency-denials/","primarySourceLabel":"IOL (23 Apr 2026)","firstPublishedAt":"2026-09-29T21:16:13.146866+00:00","updatedAt":"2026-09-30T01:17:54.03839+00:00","scopeVersion":"facts-v3","tags":["historical-2026"]},{"id":"2026-southampton-choudhury-arrested-after-retrospective-facial-recognition-match-milton-keynes-burglary","caseFacts":{"claims":[{"id":"c1","status":"reported","evidence":[{"locator":"was working at the home he shares with his parents in Southampton in January","relation":"supports","source_id":"s1"},{"locator":"handcuffed him and held him in custody for nearly 10 hours before releasing him at 2am.","relation":"supports","source_id":"s1"},{"locator":"On 8 January 2026 Mr Alvi Choudhury was arrested on suspicion of a burglary that had occurred 100 miles away from where he was at the time.","relation":"supports","source_id":"s3"},{"locator":"Choudhury is claiming damages against Thames Valley police and Hampshire constabulary, which executed his arrest.","relation":"supports","source_id":"s1"},{"locator":"But the arresting officers from Hampshire Constabulary didn’t want to know.","relation":"supports","source_id":"s2"}],"assertion":"Alvi Choudhury was arrested at the home he shares with his parents in Southampton on 8 January 2026 on suspicion of a burglary in Milton Keynes, handcuffed and held in custody for nearly 10 hours until released at 2am. Hampshire Constabulary officers carried out the arrest.","causal_attribution":"Event description only. The account comes from Choudhury and his solicitors through the Guardian, Liberty Investigates and a chambers news post. The Thames Valley Police statement quoted by the Guardian treats the arrest as having happened and apologises for the distress caused. The 8 January date appears only in the chambers post (the Guardian says January)."},{"id":"c2","status":"reported","evidence":[{"locator":"Thames Valley police had used automated facial recognition software which matched him with footage of a suspect of a £3,000 burglary 100 miles away in Milton Keynes","relation":"supports","source_id":"s1"},{"locator":"following a retrospective facial recognition match, and was not influenced by racial profiling.","relation":"supports","source_id":"s1"},{"locator":"A week later, after filing a complaint against Thames Valley Police, he found out the full story: he’d been flagged as a possible suspect by an automated facial recognition system.","relation":"supports","source_id":"s2"},{"locator":"UK police forces use an algorithm procured by the Home Office from Cognitec, a German company.","relation":"context","source_id":"s1"}],"assertion":"Thames Valley Police used automated retrospective facial recognition software that matched Choudhury with CCTV footage of a suspect in the Milton Keynes burglary. Choudhury says he learned about a week after the arrest, after filing a complaint, that an automated facial recognition system had flagged him as a possible suspect.","causal_attribution":"The Guardian bases the match on documents shared by Liberty Investigates, which were not inspected. The police spokesperson statement quoted in the same report itself refers to a retrospective facial recognition match. The sources do not state which product, version, threshold or match score applied to this search."},{"id":"c3","status":"reported","evidence":[{"locator":"Thames Valley police said the decision to arrest Choudhury was made after a human visual assessment as well.","relation":"supports","source_id":"s1"},{"locator":"A Thames Valley police spokesperson denied the arrest was unlawful and said: “While we apologise for the distress caused to the complainant in this case","relation":"supports","source_id":"s1"},{"locator":"Facial matches should be treated as intelligence, not fact, according to the National Police Chiefs’ Council.","relation":"supports","source_id":"s1"}],"assertion":"Thames Valley Police told the Guardian that the decision to arrest was made after a human visual assessment as well as the match, denied that the arrest was unlawful and said it was not influenced by racial profiling, and apologised for the distress caused. The Guardian reports the National Police Chiefs’ Council position that facial matches should be treated as intelligence, not fact.","causal_attribution":"A party statement about its own conduct, relayed by the Guardian. It addresses the arrest decision and gives no detail of the match."},{"id":"c4","status":"reported","evidence":[{"locator":"“I was very angry, because the kid looked about 10 years younger than me,” said Choudhury, who wears a beard.","relation":"supports","source_id":"s1"},{"locator":"He offered evidence of work meetings in Southampton on the day of the crime but he was instead taken into custody.","relation":"supports","source_id":"s1"},{"locator":"But Choudhury said officers at the Hampshire police station laughed when he asked: “Does this look anything like me?”","relation":"supports","source_id":"s1"},{"locator":"And he said the Thames Valley police officers who arrived to interview him said “they knew I wasn’t the suspect after looking at footage of the suspect and looking at my picture”.","relation":"supports","source_id":"s1"}],"assertion":"Choudhury says the man in the CCTV footage looked about 10 years younger than Choudhury and had different features, that he offered evidence of work meetings in Southampton on the day of the burglary, that officers at the Hampshire police station laughed when he asked whether the footage looked like him, and that the Thames Valley Police officers who came to interview him said they knew he was not the suspect after looking at the footage and his picture.","causal_attribution":"First-person account relayed by the Guardian. The CCTV footage and the police interview record were not inspected, and no source independent of Choudhury describes the suspect’s appearance or the interview."},{"id":"c5","status":"reported","evidence":[{"locator":"Thames Valley police admitted to Choudhury the arrest “may have been the result of bias within facial recognition technology”.","relation":"supports","source_id":"s1"},{"locator":"Thames Valley Police wrote to Choudhury, acknowledging that his arrest “may have been the result of bias within facial recognition technology”","relation":"supports","source_id":"s2"},{"locator":"as the use of facial recognition is already subject to review at a strategic level, I do not feel the need to raise this issue as part of wider organisational learning","relation":"supports","source_id":"s1"}],"assertion":"Thames Valley Police wrote to Choudhury that the arrest “may have been the result of bias within facial recognition technology”. An officer also told him that, because facial recognition use is already subject to review at a strategic level, the issue would not be raised as part of wider organisational learning.","causal_attribution":"Quotations from a police letter to Choudhury as relayed by the Guardian and Liberty Investigates. The letter itself was not inspected. The wording is conditional (“may have been”)."},{"id":"c6","status":"disputed","evidence":[{"locator":"“I just assumed that the investigative officer saw that I was a brown person with curly hair and decided to arrest me.”","relation":"supports","source_id":"s1"},{"locator":"their arrest was based on the investigating officers’ own visual assessment that the individual matched the suspect in CCTV footage","relation":"supports","source_id":"s1"},{"locator":"Confusingly, however, the force concluded that his arrest was not a case of racial profiling, because officers had made their own assessment of the images before arresting him.","relation":"supports","source_id":"s2"}],"assertion":"Whether the facial recognition match or the officers’ own visual assessment led to the arrest decision, and whether bias in the software contributed, is disputed. Choudhury says he assumed the investigating officer saw a brown person with curly hair and decided to arrest him. Thames Valley Police say the arrest rested on the investigating officers’ own visual assessment following the match and was not influenced by racial profiling, while also acknowledging in writing that the arrest may have been the result of bias within facial recognition technology.","causal_attribution":"Two accounts that conflict on the decisive input to the arrest. Neither the match record nor the officers’ assessment record was inspected."},{"id":"c7","status":"reported","evidence":[{"locator":"His neighbours saw him being led away in handcuffs, his father was very anxious about him being held and he was unable to work the following day, he said.","relation":"supports","source_id":"s1"},{"locator":"He sometimes needs security clearance to work for government clients and he is asked about arrests and said: “This makes me look dodgier and dodgier.”","relation":"supports","source_id":"s1"},{"locator":"Now he has had a second mugshot taken he is afraid the automated system could trigger more wrongful arrests.","relation":"supports","source_id":"s1"},{"locator":"While we apologise for the distress caused to the complainant in this case","relation":"supports","source_id":"s1"}],"assertion":"Choudhury reports that neighbours saw him led away in handcuffs, that his father was very anxious about him being held, and that he was unable to work the following day. He says he sometimes needs security clearance to work for government clients, is asked about arrests, and that “This makes me look dodgier and dodgier”, and that he is afraid the automated system could trigger more arrests now that a second mugshot has been taken.","causal_attribution":"First-person account relayed by the Guardian. The police apology for distress caused is the only independent acknowledgement of an effect. No effect on an actual clearance decision is reported."},{"id":"c8","status":"reported","evidence":[{"locator":"Choudhury’s mugshot was held on the police system only because he had been wrongly arrested in 2021 when he had been attacked on a night out","relation":"supports","source_id":"s1"},{"locator":"The police released him with no further action.","relation":"supports","source_id":"s1"},{"locator":"comparing images taken from sources such as social media and CCTV to a database of more than 19m custody images, or mugshots.","relation":"context","source_id":"s2"}],"assertion":"Choudhury’s image was held on the police system only because of an arrest in 2021 that the Guardian describes as wrongful (he had been attacked on a night out) and that ended with police releasing him with no further action.","causal_attribution":"Background as told by Choudhury to the Guardian. The sources do not state in terms that this custody image was the one returned by the search."},{"id":"c9","status":"reported","evidence":[{"locator":"Choudhury is claiming damages against Thames Valley police and Hampshire constabulary, which executed his arrest.","relation":"supports","source_id":"s1"},{"locator":"after filing a complaint against Thames Valley Police","relation":"supports","source_id":"s2"},{"locator":"to pursue a claim for damages against Thames Valley Police for false imprisonment, breach of data protection law, breach of Art 8 ECHR and breach of the Equality Act 2010.","relation":"supports","source_id":"s3"}],"assertion":"Choudhury filed a complaint against Thames Valley Police and is claiming damages from Thames Valley Police and Hampshire Constabulary. His solicitors have instructed counsel to pursue a claim for damages against Thames Valley Police for false imprisonment, breach of data protection law, breach of Article 8 ECHR and breach of the Equality Act 2010.","causal_attribution":"A complaint and a claim establish only their own existence and the allegations made. No court filing or outcome was found in the inspected sources."},{"id":"c10","status":"documented","evidence":[{"locator":"This is the FR software currently used in the Police National Database (PND) for which the operational use case is Retrospective Facial Recognition (RFR).","relation":"supports","source_id":"s4"},{"locator":"The FPIR for White subjects (0.04 %) is lower than that for Asian subjects (4.0 %)","relation":"supports","source_id":"s4"},{"locator":"At a face-match threshold of 0.8:","relation":"supports","source_id":"s4"}],"assertion":"A National Physical Laboratory report for the Home Office and the Office of the Policing Chief Scientific Adviser (dated October 2025) evaluated Cognitec FaceVACS-DBScan ID v5.5, which it describes as the facial recognition software used in the Police National Database for retrospective facial recognition. At a face-match threshold of 0.8 on its test data it found a false positive identification rate of 4.0 % for Asian subjects and 0.04 % for White subjects.","causal_attribution":"The report establishes the evaluation findings on its own test dataset. It does not state which product version, threshold or settings applied to the search in this case."}],"effects":[{"label":"Arrested at home and held in custody for nearly 10 hours after a police retrospective facial recognition match","claim_id":"c1","direction":"negative"},{"label":"Distress acknowledged by the police, a lost working day and worry about future arrests and security clearance, as reported by Choudhury","claim_id":"c7","direction":"negative"}],"sources":[{"id":"s1","url":"https://www.theguardian.com/technology/2026/feb/25/facial-recognition-error-prompts-police-to-arrest-asian-man-for-burglary-100-miles-away","kind":"news","access":"read","language":"en","translation_note":"","independence_group":"guardian-liberty-investigates-reporting"},{"id":"s2","url":"https://libertyinvestigates.org.uk/articles/the-rise-of-facial-recognition-policing/","kind":"news","access":"read","language":"en","translation_note":"","independence_group":"guardian-liberty-investigates-reporting"},{"id":"s3","url":"https://www.doughtystreet.co.uk/news/automated-facial-recognition-software-innocent-man-arrested","kind":"organisation_statement","access":"read","language":"en","translation_note":"Read through an Internet Archive capture of 22 April 2026 because the site returned HTTP 403 to direct requests.","independence_group":"claimant-legal-team-post"},{"id":"s4","url":"https://assets.publishing.service.gov.uk/media/693002a4cdec734f4dff4149/1a_Cognitec_NPL_Equitability_Report_October_25.pdf","kind":"official_record","access":"read","language":"en","translation_note":"","independence_group":"npl-evaluation-report"}],"version":1,"ai_roles":["institutional_use"],"contexts":["justice","privacy"],"unknowns":["Which product, version, face-match threshold and match score the Thames Valley Police search used is not stated. The National Physical Laboratory report evaluates Cognitec FaceVACS-DBScan ID v5.5 (the Police National Database software) at stated thresholds, and the sources do not say those settings applied here.","The documents shared with the Guardian, the police letter to Choudhury, the CCTV footage and the police interview record were not inspected. All account details come from news reports and a chambers post.","Whether the human visual assessment preceded the arrest request, which force made the request and which force made the decision are stated differently by Choudhury, his solicitors and the police, and no record was inspected.","Whether a court claim was filed and the outcome of the complaint and the damages claim are not reported in any inspected source (the latest inspected reports are dated 1 April 2026).","The date 8 January 2026 comes from the news post of the claimant’s counsel (Internet Archive capture). The Guardian says only January. Distances given by outlets differ (100 miles in the Guardian) and are not material.","The burglary, the burglary suspect and any prosecution are not described in the inspected sources."],"geography":{"basis":"The arrest took place at Choudhury’s home in Southampton and the burglary was in Milton Keynes, both placed in England by the Guardian (Thames Valley Police and Hampshire Constabulary are the forces named). No court proceedings are reported, so court countries are unknown.","court_countries":[],"event_countries":["GB"],"affected_person_countries":["GB"]},"publication":{"basis":"The Guardian article and the Liberty Investigates April feature were read in full from saved bodies. They come from one Liberty Investigates investigation built on an interview with Choudhury, documents shared with the Guardian and police statements, so they count as one reporting chain. The arrest date comes from the claimant’s counsel and the technical context from the National Physical Laboratory report, cited for its own contents. Claims about the arrest stay at reported status, the decisive causal question is recorded as disputed because Thames Valley Police dispute the causal account, and only the contents of the National Physical Laboratory report are recorded as documented. Choudhury is named because he spoke about the arrest under his own name to the Guardian and Liberty Investigates. The burglary suspect is not named or described beyond the reported age difference.","reviewed_on":"2026-09-29"},"ai_involvement":{"basis":"Thames Valley Police’s own statement, quoted by the Guardian, refers to a retrospective facial recognition match preceding the arrest, and the Guardian cites documents shared by Liberty Investigates. The police say the arrest decision rested on the investigating officers’ own visual assessment. Choudhury says the footage showed a man who looked about 10 years younger with different features, and that he assumed the investigating officer decided to arrest him because he is a brown person with curly hair. The police also wrote that the arrest may have been the result of bias within the technology. The weight of the match in the arrest decision is disputed. The sources do not identify the product version, threshold or match score.","status":"supported"},"person_relations":["made_claim_about"]},"name":"Southampton: Alvi Choudhury arrested at home on suspicion of a Milton Keynes burglary after a police retrospective facial recognition match, held nearly 10 hours, claiming damages","summary":"The Guardian, in a joint report with Liberty Investigates, reported on 25 February 2026 that Alvi Choudhury, a 26-year-old software engineer, was arrested at his home in Southampton in January 2026 on suspicion of a £3,000 burglary in Milton Keynes, about 100 miles away, and held in custody for nearly 10 hours. Thames Valley Police had used automated retrospective facial recognition software, which matched him with CCTV footage of the burglary suspect. Choudhury says the man in the footage looked about 10 years younger and had different features. Thames Valley Police wrote to him that the arrest may have been the result of bias within facial recognition technology, and told the Guardian that the decision rested on the investigating officers’ own visual assessment and was not influenced by racial profiling. Choudhury is claiming damages from Thames Valley Police and Hampshire Constabulary.","incidentDate":"2026-01-08","incidentKind":"single_event","incidentDatePrecision":"day","exposurePattern":"single_interaction","reportedDate":"2026-02-25","aiSystem":"Retrospective facial recognition search run by Thames Valley Police (product, version and reference database not stated in the sources)","aiProduct":"Unidentified facial recognition system","aiCompany":"Not stated in the sources for this search (the Guardian says UK police forces use an algorithm procured by the Home Office from Cognitec)","severity":"medium","verificationStatus":"unverified","harmCategories":[],"harmOutcomes":["loss_of_liberty","psychological_distress"],"harmOutcomeSummary":"The Guardian reports Choudhury was handcuffed at home, held for nearly 10 hours and released at 2am, and was unable to work the following day. Choudhury says neighbours saw him led away. Thames Valley Police apologised for the distress caused and deny the arrest was unlawful.","frameworkFacets":[],"causationStatus":"disputed","participantUsersAffectedMin":0,"otherPeopleHarmedMin":1,"affectedCountStatus":"exact","affectedCountEvidence":"One man reported arrested and held. His father, neighbours and the burglary suspect are not counted as harmed.","victimAgeRange":"adult","jurisdiction":"GB","platformType":"other","primarySourceUrl":"https://www.theguardian.com/technology/2026/feb/25/facial-recognition-error-prompts-police-to-arrest-asian-man-for-burglary-100-miles-away","primarySourceLabel":"The Guardian with Liberty Investigates (25 Feb 2026): Facial recognition error prompts police to arrest Asian man for burglary 100 miles away","firstPublishedAt":"2026-09-29T21:15:56.164264+00:00","updatedAt":"2026-09-30T01:17:54.246626+00:00","scopeVersion":"facts-v3","tags":["historical-2026"]}]}