24 Apr 2026Event location unknownCursor coding agent (reported)
On Friday 24 April 2026 a Cursor coding agent, running Anthropic's Claude Opus 4.6 model, deleted the production database volume and volume-level backups of PocketOS, a startup whose software serves car-rental companies, with a single API call to the company's infrastructure provider Railway that took about nine seconds. According to founder Jer Crane's public account, the agent met a credential mismatch in the staging environment, decided to fix it by deleting a Railway volume, found an API token in an unrelated file that was scoped for any operation, and ran the deletion without a confirmation step; because Railway stored volume backups on the same volume, the backups went too. Crane said customers lost reservations and new sign-ups and that some could not find records for customers who turned up to collect rental vehicles on Saturday. Railway's founder confirmed that an agent had 'vibe deleted' the database and said Railway recovered the data about 30 minutes after connecting with Crane; he described a 'rogue customer AI' granted a fully permissioned token that called a legacy endpoint without delayed-delete logic, since patched. Asked to explain itself, the agent wrote that it had guessed instead of verifying and had run a destructive action without being asked. Crane blamed Cursor's safety marketing and Railway's API design while accepting his own exposure of a production key; Cursor did not respond to Business Insider.
Core concern Low reported severity Internal Action
AI involvement supported · Causal attribution supported · 2 sources · Added 22/09/2026
5 Sept 2026 to 20 Sept 2026United StatesUnidentified video tool
On Saturday 19 September 2026 Vikki Goodwin, an Austin state representative running against Republican Lt. Gov. Dan Patrick, filed a complaint with a notarised affidavit at the Travis County Sheriff's Office accusing Patrick of violating Texas's 2019 election deepfake law, after his campaign posted two ads (5 and 12 September, on his non-government X account) containing AI-generated videos of her. In the affidavit she stated: 'I did not personally do or say the things depicted in the video; although the "person" in the video appears to be me, it was not actually me', and that the video was posted 'with the intent to deceive Texans, injure a candidate, or influence the result of an election'. She told KUT the ads made it look as though she favoured raising taxes, which she says she opposes in every campaign speech. The sheriff's office confirmed receipt of the complaint without further comment. Patrick's campaign spokesman told the New York Times the material was 'an obvious parody produced to entertain' and that none of it was published within 30 days of the election; the posts were taken down the day after the complaint, according to Goodwin's communications director. Goodwin said she doubted the sheriff's office would follow up now that the posts were removed. A conviction under the law is a class A misdemeanour.
Core concern Low reported severity Media Coverage
AI involvement supported · Causal attribution disputed · 4 sources, 3 underlying accounts · Added 22/09/2026
17 Sept 2026United StatesUnidentified image tool
Henderson Police said that on 'last Thursday' (17 September 2026) they received a report that AI-generated nude images of children were being created and shown to other students at South Middle School in Henderson, Kentucky. During the investigation officers found and identified AI-generated photographs of two minor victims on a digital device. A juvenile accused of sharing the images was lodged at the Juvenile Detention Center on three charge types: distribution of sexually explicit images without consent; two counts of possession or viewing of matter portraying a sexual performance by a minor over 12 and under 18; and distribution of matter portraying a sexual performance by a minor over 12 and under 18. The school said on Monday 21 September that it was aware of a situation involving a student allegedly misusing artificial intelligence and inappropriate images, that the police investigation was active and that it had remained in communication with the families involved. 14 News (WFIE) reported the case on 21 September; WKYT carried the same report. The tool is not named. The depicted children's exact ages are not reported, though the charge descriptors put them between 12 and 18. The accused is described as a South Middle School student; the accused's age and any relationship to the depicted children beyond attending the same school are not reported.
Core concern Medium reported severity Involving minors Criminal Charges
AI involvement reported · Causal attribution supported · 2 sources, 1 underlying account · Added 22/09/2026
Aug 2026United StatesUnidentified image tool
On 31 August 2026 the Putnam County Sheriff's Office was told of possible sharing of sexually explicit images at Cookeville High School. Detectives found that two male teenage students had used an artificial-intelligence program to turn photographs obtained online, in some cases photographs of fellow female students, into sexually explicit images, and had shared them; explicit images already stored on one phone were also shared. Both juveniles were taken to the Putnam County Juvenile Detention Center. One was charged with one count each of aggravated sexual exploitation of a minor and especially aggravated sexual exploitation of a minor, the other with two counts of each. The district attorney told NewsChannel 5 on 21 September that the two would be prosecuted in juvenile court. The mother of one of the depicted girls told the station the episode was very hard on her daughter, who had made no naked photographs herself, locked herself in her room and would not talk to her, to anybody or to her friends. The sheriff's-office account and the school system's statement were carried by WZTV, WSMV and 3B Media News on 1-2 September; NewsChannel 5 added its own interviews with the sheriff, the district attorney and the mother on 21 September. The tool is not named. The juveniles are not named in any report.
Core concern Medium reported severity Involving minors Criminal Charges
AI involvement reported · Causal attribution supported · 4 sources, 2 underlying accounts · Added 22/09/2026
16 Sept 2026IndiaUnidentified video tool
A Rajasthan social-media influencer visited Haridwar with her family in June 2026 and on 6 June uploaded to Instagram a short video, recorded by relatives, of herself taking a dip in the Ganga at Har Ki Pauri wearing a salwar suit. About two months later she found that the video had been manipulated with AI into an objectionable version showing the same movements with her face and body portrayed 'in a shameful manner'; the fake reel went viral in the week before 20 September and drew objectionable comments and re-sharing. In a public appeal she asked whoever uploaded it to remove it, saying it was a matter of her dignity, that she was mentally very disturbed and had reached a point where she could not step out of her house. She filed a complaint with the cyber-crime police on 16 September 2026; the investigating Rajasthan Police Service officer said they were trying to identify who created and circulated the video and to have it removed, and that identifying the accused would take time. Dainik Bhaskar's English edition reported the case on 20 September in a 'Sunday Big Story' that does not name her.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 1 source · Added 21/09/2026
17 Apr 2026 to 19 Apr 2026ChinaDoubao
A man living in Jiashan county, Zhejiang, whose mother died suddenly on 17 April 2026, asked the ByteDance chatbot Doubao which day was auspicious for her burial after disagreeing with a feng-shui master's choice of 20 April; Doubao recommended 19 April and he persuaded his family to follow it. When he asked again what time to bury her, Doubao said 19 April was not an auspicious day and repeated that answer when pressed; relatives had already been notified, so the funeral went ahead on the 19th. Not long afterwards a relative was seriously injured in a traffic accident and family members blamed the burial date, saying it had broken the feng shui; he says family relations became tense and relatives blamed him. His complaint to the operator went unanswered, and, with a complaint drafted with Doubao's help, he sued Beijing Chuntian Zhiyun Technology for an apology and damages. Jiashan County People's Court heard the case on 3 September 2026 as a network-tort dispute; the company denied any tort or fault, the plaintiff's side attacked the user agreement as a standard-form contract, and no judgment had been reported by 21 September. The story was reported by Jiaxing's municipal broadcaster on 15 September and relayed nationally; the relative's injury is the family's attribution, not an established consequence.
Core concern Low reported severity Lawsuit Ongoing
AI involvement reported · Causal attribution alleged · 6 sources, 2 underlying accounts · Added 21/09/2026
11 Aug 2026BrazilUnidentified voice-cloning tool
On Monday 10 August 2026 a digital influencer from Picos, in the centre-south of Piauí, began negotiating a car advertised online for sale in Fortaleza (Ceará), where an uncle of his lives, and asked the sellers to take the car to the uncle so he could inspect it. On Tuesday 11 August a contact using a different number but the uncle's photo sent him audio messages in a voice identical to his uncle's, generated with artificial intelligence, saying the car was in good condition and telling him to make the bank transfer. Believing he was speaking to his uncle, he transferred the money; when he then called the uncle's real number he learned he had been defrauded. The loss exceeded R$56,000, money he says he had saved for years. He registered a police report on 11 August; the Piauí property-crimes unit (Depatri) is investigating and he is seeking a refund from the banks. The account is the victim's own, reported by G1 Piauí on 13 August 2026 from his social-media posts and an interview; the police unit did not respond to G1 before publication.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 1 source · Added 20/09/2026
Mar 2026Event location unknownUnidentified AI medical scribe
A patient who consented to having her first urology appointment transcribed by an artificial-intelligence scribe discovered, after her kidney-stone surgery in March 2026, that the post-operative letter her specialist sent to her GP stated she micro-dosed psychedelic mushrooms and that this could explain earlier bleeding around the kidneys. She says she has never taken mushrooms. She was receiving workers' compensation and feared that any mention of illegal drugs on her medical record could affect her case. After she complained, the urologist sent a letter of apology saying the practice takes documentation accuracy seriously, that she could not determine how the claim came to be included but that it appeared to be an error during the 'dictation or transcription process', that the correspondence had been corrected and that she would review how AI was used in her practice. The doctor did not answer ABC's questions about what changes had been made. Australia's practitioner regulator AHPRA told ABC that clinicians must check all AI-scribe output; the patient says it was clear her doctor had not. The account is a single ABC News report (14 August 2026) based on the patient's interview and the letters she received; the scribe product and the clinic's location are not named.
Contextual tracker case Low reported severity Internal Action
AI involvement reported · Causal attribution alleged · 1 source · Added 20/09/2026
19 May 2026United StatesUnidentified voice-cloning tool (suspected)
A married couple in their sixties buying a US$460,000 condo in Hudsonville, near Grand Rapids, Michigan, received an email on 19 May 2026, days before closing, telling them to wire US$66,026.92 for the down payment and closing costs within 24 hours. The email listed a phone number differing from their loan officer's by two digits, and the husband then received a call confirming the instructions in a voice that sounded just like the loan officer. The couple borrowed from family and other sources and wired the money. The day before closing their real loan officer sent the actual statement; the closing was cancelled hours before signing and the money was gone. The husband now believes the call came from a spoofed number using AI-assisted voice cloning; Tyler Adams of CertifID, which is working with the couple and federal officials, said someone's email in the transaction was probably compromised and that the scammers likely cloned the loan officer's voice from social-media clips. The sender's address had two extra letters ('UnitedsMortgages' instead of 'UnitedMortgage'). Neither the lender nor the loan officer is accused of complicity. The couple later completed the purchase in early June from their mutual fund, reported the loss to the FBI's Internet Crime Complaint Center, and describe lasting apprehension and have discussed delaying retirement. CNN reported the case on 15 September 2026; the account the money went to has since closed.
Core concern Medium reported severity Investigation Opened
AI involvement suspected · Causal attribution alleged · 2 sources, 1 underlying account · Added 20/09/2026
4 May 2026FranceDIGI editorial tool
Gisi, the Infopro Digital subsidiary publishing L'Usine nouvelle, LSA and L'Argus de l'assurance (127 staff, 92 journalists), presented to its works council (CSE) on 4 May 2026 a reorganisation built around 'DIGI', an in-house generative-AI editorial tool, and on 12 May 2026 opened consultation on the reorganisation and on the resulting collective dismissal of its eight secrétaires de rédaction (sub-editors), to be replaced by two chefs d'édition, on the company's estimate that the tool would take over about 70% of sub-editor tasks. Some 250 journalists across Infopro Digital's 26 titles had struck in spring 2026 against a group-wide plan to cut 19 sub-editor posts, and according to Digital Watch (citing Stratégies) five of the eight Gisi sub-editors had received pre-dismissal interview letters. The CSE, relying on an expert report, went to the Créteil judicial court in July. On 15 September 2026 the référé judge found that deploying the plan without real-situation testing presented 'un risque grave et caractérisé sur la santé physique et mentale de plusieurs catégories de salariés', ordered the suspension of the reorganisation and the collective dismissal (including the redeployment processes) until real-situation tests and full pilot issues are produced, with a provisional penalty of 8,000 euros per day for three months, and refused the damages provision. Gisi said it would continue the tests and reserved the right to appeal.
AI relation unknown Medium reported severity Lawsuit Ongoing
AI involvement supported · Causal attribution supported · 6 sources, 4 underlying accounts · Added 20/09/2026
1 Aug 2026 to 16 Sept 2026KazakhstanUnidentified video tool
On 16 September 2026 the Prosecutor General's Office of Kazakhstan warned of an investment-fraud scheme in which criminals advertise non-existent projects on TikTok, Instagram, YouTube and other platforms using deepfake videos of well-known people and fake 'AI' investment platforms promising very high passive income: 'Kaspi AI' with Mikhail Lomtadze, 'Quantum AI' with Elon Musk, 'TON' with Pavel Durov, and 'people's investments' in KazMunayGas or Gazprom fronted by news presenters from Khabar 24, KTK and Channel One. The office said 119 such cases had been registered across the country in the previous one and a half months. Its example: in September 2026 a woman from Taldykorgan saw an Instagram advertisement offering high returns from share trading, left her details through the link, was contacted by the fraudsters and, following their instructions, transferred more than 7 million tenge to third-party accounts; the money and supposed dividends appeared in a fake wallet that she could not withdraw from. A pre-trial investigation is under way. The office urged people not to trust guaranteed-return offers or transfer money to strangers.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution supported · 5 sources, 1 underlying account · Added 20/09/2026
Jun 2026 to Aug 2026United StatesUnidentified image tool
On 2 September 2026 Vero Beach police arrested Peter Solomon Ruma, 37, after an investigation into the creation and distribution of altered sexual images of women without their consent. Police say he used artificial intelligence to make sexually explicit altered images of victims from photographs taken from social media and other online sources and then distributed or promoted them. The eight charges (three counts of creating and three of promoting an altered sexual depiction of an identifiable person under Florida Statute 836.13, one count of sexual cyberharassment and one of stalking) relate to one adult woman and to incidents between June and August 2026. Detectives said they had identified several other women believed to have been victimised in the same way, some of whom may not know that images of them exist, and that the conduct may go back several years. According to court documents reported by TCPalm, the woman who came forward knew Ruma and had received sexual text messages since 2018; her face had been cropped from public photographs, including a business profile, and placed on nude bodies. Ruma was held on a US$1 million bond with conditions including no internet access; the investigation continues and further charges are expected.
Core concern High reported severity Criminal Charges
AI involvement reported · Causal attribution alleged · 5 sources, 2 underlying accounts · Added 20/09/2026
1 Jan 2026IndonesiaUnidentified image and video tool
A female student at a state university in Solo (Surakarta), Central Java, learned on 1 January 2026 from friends that her face had been composited onto pornographic images and a video, which her lawyer said were found on Instagram and Telegram. Her family reported the case to the Central Java regional police cyber directorate on 28 January 2026. Police issued a formal police report on 31 July, arrested her ex-boyfriend, a university student in Semarang, at his boarding house in Gunungpati on 4 August 2026, and detained him. The police spokesman said the suspect used AI to place the complainant's face on another woman's naked body so that she appeared in pornographic content, uploaded it to his X account, did not sell it, and acted out of resentment after an on-and-off relationship ended. He faces charges under Articles 51 and 35 of the Electronic Information and Transactions Law and an article printed by two outlets as 'Law No. 1 of 2026', with a maximum of 12 years' imprisonment. Her lawyer said she could not sleep, withdrew, felt shame and at one point lost hope, that his team had found seven women in total allegedly targeted of whom six had not reported, and that the suspect's parents asked for an out-of-court settlement; police said only one complainant was confirmed.
Core concern High reported severity Investigation Opened
AI involvement reported · Causal attribution supported · 6 sources, 2 underlying accounts · Added 20/09/2026
10 Jul 2026ChinaUnidentified chatbot
On 10 July 2026 a 67-year-old farmer in Chuzhou, Anhui, who said he had relied on an AI assistant app for more than a year for questions such as when to spray and fertilise, asked it for a weeding and pest-control plan for his sesame field and then for a drone-spraying version. The app produced a 'full plan for 100-mu sesame aerial weeding and pest control' recommending the herbicides haloxyfop-P-methyl (高效氟吡甲禾灵) and fomesafen (氟磺胺草醚) and two insecticides. He sprayed the whole 150-mu field; the next day grass and seedlings had died together. A nearby pesticide dealer and an agronomist told Lizhi News (Jiangsu Broadcasting) that fomesafen is a broadleaf herbicide for soybean fields that must not be sprayed on sesame, and that spraying it across a whole field kills the crop; asked afterwards, the app itself said fomesafen was the cause. The chat window carried a small header line saying AI output may be wrong and should be verified, which he said he had never noticed. The app's customer service said the software has no knowledge base of its own and assembles answers from public web content, and logged the loss for follow-up; no reply or compensation was reported by publication on 1 August 2026. Relays put the loss at about 150,000 yuan; that figure is not in the text of the originating report.
Core concern Medium reported severity Media Coverage
AI involvement supported · Causal attribution supported · 4 sources, 3 underlying accounts · Added 20/09/2026
Jul 2026GreeceUnidentified voice-cloning tool
On 18 September 2026 the Hellenic Police announced that its Organised Crime Directorate had dismantled a criminal organisation, active since at least early July 2026, whose members defrauded and robbed residents of Attica by posing on the phone as staff of the electricity distributor ΔΕΔΔΗΕ, mobile operators or fibre-optic installers. When a target hesitated, the callers asked for a relative's phone number, called that relative under a mobile-operator pretext to obtain a voice sample, cloned the voice with an AI tool and then played the cloned voice to the target to 'confirm' the instructions. Two men aged 23 and 25, described as the ring's 'collectors', were arrested in Nea Ionia just after removing valuables worth €30,000 from a victim's home; the case file, covering criminal organisation, fraud and aggravated theft with proceeds above €120,000, names four more people. Police have so far confirmed at least five further cases with the same method and estimate the group's total proceeds above €1 million. The two arrested were brought before the prosecutor and referred to an investigating judge.
Core concern Medium reported severity Criminal Charges
AI involvement reported · Causal attribution supported · 3 sources, 1 underlying account · Added 19/09/2026
2 Sept 2026United StatesMeta AI
On 1 September 2026 Kalie Robins, a Utah travel creator, posted a short Instagram video of herself singing in the car with one of her daughters; it was also shown on Facebook. The next day she noticed Meta AI had placed suggested questions under the post, starting with 'Who's the child passenger?'. Clicking the prompts, she said, produced her two daughters' names, birth information, photos and videos drawn from her own and relatives' past posts, including a newborn photo from her mother's account and a picture she believed she had deleted years earlier, and a further prompt, 'Where does Kalie Robins live?', assembled older and newer posts into her likely location. Her 2 September reaction video drew more than 310,000 likes. Meta told reporters the prompts 'missed the mark', 'should never have been generated' and had been fixed, while saying the feature only surfaces information the user can already access; it disputed that a long-deleted photo was used, saying the photo had been deleted shortly before the video and remained briefly visible through a bug. Robins said Meta never contacted her and that the episode left her feeling she had 'failed' her children.
Contextual tracker case Low reported severity Involving minors Internal Action
AI involvement supported · Causal attribution supported · 4 sources · Added 18/09/2026
Sept 2026IndiaUnidentified video tool
In 2026 AI-generated videos showing a simulated Tamil Nadu Chief Minister C. Joseph Vijay speaking in a fabricated Hindi voice circulated on Facebook and other platforms, urging viewers to contact a WhatsApp number to receive money for education, medical treatment and other needs. The Tamil Nadu Crime Branch-CID detected the videos during routine monitoring, registered a case on 1 September 2026 under the Bharatiya Nyaya Sanhita and the Information Technology Act, and traced the scheme to Rajasthan and Madhya Pradesh. On 12 September a 28-year-old man from Alwar district was arrested with Rajasthan Police, brought to Tamil Nadu on a transit warrant and remanded in judicial custody; a phone, SIM cards and a CPU were seized. Investigators traced a man in Madhya Pradesh who had lost money, and said people in several states were cheated. The CB-CID is also examining similar videos posted from Facebook accounts suspected to be run from Pakistan.
Core concern Medium reported severity Criminal Charges
AI involvement reported · Causal attribution supported · 3 sources, 2 underlying accounts · Added 18/09/2026
14 Sept 2026United StatesUnidentified image and video tool
On 14 September 2026 Manhattan District Attorney Alvin Bragg announced the seizure of 12 domain names used to disseminate, publish and sell non-consensual AI-generated sexual 'deepfake' videos. His office said individuals under investigation had used AI image- and video-creation tools to turn photos and videos of approximately 1,200 real people, overwhelmingly women, into hyper-realistic sexual imagery without consent. The victims included actors, politicians, athletes, musicians, activists and social-media influencers. WIRED and outside researchers reported that many videos reposted content from the defunct MrDeepFakes platform and that dozens of politicians appeared on the sites; investigations into who ran them are ongoing.
Core concern High reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 2 sources · Added 17/09/2026
12 Jun 2026RussiaChatGPT
On 12 June 2026 a Russian-speaking crypto investor, known by the alias Alex (@vesnuhin), asked ChatGPT in Russian where to swap sFLR for WFLR tokens. ChatGPT's reply included a link to sceptre.network, a phishing clone of the legitimate sceptre.fi. He connected his wallet and signed an unlimited-approval transaction; within seconds about 1.9 million FXRP, worth roughly $2.1 million (about 180 million rubles), were drained. A blockchain analyst traced the theft, and reported that the phishing link appeared only in Russian-language answers. Russia's Interior Ministry (MVD) later confirmed the loss.
Core concern High reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 4 sources, 2 underlying accounts · Added 17/09/2026
6 Aug 2026United KingdomFacewatch facial recognition
On 6 August 2026 Matt Arnold, 46, was stopped by two managers at a self-service till in Sainsbury's East Dulwich store, told he could not be served because of an incident 'earlier in the week', and escorted out; he says a staff member told him he had been 'identified by the AI' and that he saw a monitor alert with a red circle around his face on his way out. Sainsbury's apologised the next day, said the mistake was 'caused by human error, not the facial recognition technology', and paused its Facewatch live facial-recognition system at the branch while it investigates; Facewatch said a correct alert had been sent and was then mishandled in store. Arnold described the experience as humiliating and a 'terrifying glimpse of the future'. It follows an earlier wrongful challenge of another shopper at a Sainsbury's in Elephant and Castle.
AI relation unknown Low reported severity Internal Action
AI involvement disputed · Causal attribution disputed · 4 sources, 2 underlying accounts · Added 16/09/2026