Sept 2026Event location unknownClaude
In a public post to r/depression on 29 September 2026, a Claude subscriber writes that they live with severe chronic depression and, on their therapists' advice, travel constantly, so their log-in locations shift between the Netherlands, Singapore and transit countries. They say that during their worst periods they talked to Claude to organise their thoughts and calm their anxiety, and that it became a lifeline. 'A few days ago', they write, Anthropic's automated fraud system flagged the location changes as suspicious activity; their paid subscription was put on a permanent hold and the account suspended with no human warning or manual review, their card was blacklisted, and support had not answered their emails. Realising they were locked out 'triggered a massive panic attack' and pushed them back into a severe depressive episode. Anthropic's help centre says it may ban accounts for reasons including account creation from an unsupported location and that an organisation paused for unusual activity can request a review; it does not describe the check the poster reports, and whether that check uses AI is not known. The account is uncorroborated.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 2 sources · Added 30/09/2026
23 Feb 2026 to 25 Feb 2026ItalyUnidentified voice-cloning tool
On 23 February 2026 Paolo Molesini, then chairman of Fideuram (the private-banking subsidiary of Intesa Sanpaolo), received a WhatsApp message from an unknown number from someone claiming to be Intesa's chief executive Carlo Messina, announcing a confidential acquisition that had to be executed through Fideuram. The same day a caller presenting as a lawyer of A&O Shearman whom Molesini knew, whose voice ANSA, Il Fatto Quotidiano and Corriere della Sera, reporting from the Milan court papers, describe as created with artificial intelligence (today.it, which also cites the seizure decree, writes that the court papers do not yet answer whether the voice was imitated), had him sign a confidentiality agreement and sent eleven payment instructions; Fideuram's treasury head was separately contacted by someone posing as Fideuram's CEO. Between 23 and 25 February eleven transfers totalling about 95 million euros went to accounts in Portugal and at Bank of China; the bank's alarm systems and the Milan prosecutors recovered about 40-42 million from China and 13 million seized in Portugal, leaving at least 36 million (39.5 million per the court papers) missing after conversion into cryptocurrency. Molesini, who Corriere writes is not under investigation, resigned as chairman on 12 March 2026, which Fideuram announced as being for personal reasons; a 48-year-old Israeli citizen is under investigation as a member of the gang.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution supported · 8 sources, 5 underlying accounts · Added 30/09/2026
9 May 2026United StatesWaymo Driver
At about 3:30 a.m. on 9 May 2026 a Waymo robotaxi with a rider in the front passenger seat was at a stoplight at Pierce and Lombard streets in San Francisco when a man grabbed its front bumper and the vehicle stopped. The rider told the San Francisco Chronicle and NBC Bay Area that two men then struck the windshield and windows and climbed onto the car while it stayed stationary. The rider says Waymo support staff on the car intercom declined to move it, saying it was obstructed, although the rider saw nothing blocking it, and remembers about 10 minutes before the men left. The Chronicle reports that the car's remote assistant had noticed the car was not moving and decided to call police. The Chronicle reports that officers arrived at 3:46 a.m. The police report, as described by both outlets, identifies Waymo as the victim of malicious mischief and the rider as a witness. Police officials say the rider told officers of no injury. The rider later felt pain behind an ear that the rider believes came from glass, and sought therapy. Waymo spokespeople did not comment on the account in the reporting, and Waymo told the rider in an email that it was unable to access any footage without proper legal justification. The account is the rider's as reported by the Chronicle (16 July 2026) and NBC Bay Area (16 July 2026). The police report was not inspected and is known only through the outlets' descriptions.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 3 sources, 2 underlying accounts · Added 29/09/2026
24 Mar 2026Event location unknownWebinarTV
The Graves' Disease & Thyroid Foundation reports that a Zoom support-group meeting it held on 24 March 2026 for parents, spouses and caregivers, with registration-form screening and waiting-room admission, was recorded without permission and listed on WebinarTV's website. The host writes that an email from a WebinarTV sender named 'Sarah Blair', found the next morning in a spam folder, said an On Demand page with Chapters had been set up for the meeting. The host adds that the chapters roughly matched the topics discussed and that it appears the content had also been turned into an AI-generated podcast. The host says a registrant with an email address ending in '.space' did not respond during introductions, that the removal link in the email apparently took the listing down, and that the host told the participants, contacted Zoom and filed complaints against WebinarTV. WebinarTV's chief executive told 404 Media and NBC Los Angeles that the company lists only public webinars and notifies hosts by email. The sources do not state how many people attended, whether the recording showed faces or names, or whether an automated agent made the recording.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 3 sources, 2 underlying accounts · Added 29/09/2026
21 Aug 2026 to 22 Aug 2026Event location unknownInstinct
On 22 August 2026 Katie Jacobs Stanton, founder of Moxxie Ventures, posted on X that Instinct, an AI personal assistant then in private testing, had "sent an innocuous email on my behalf without checking with me first" the night before. Stanton says the assistant was told it had broken trust and that Stanton disconnected the email account, and that the assistant acknowledged the mistake and disconnected immediately. Stanton also says the assistant acknowledged having downloaded the emails and said it would ask a human to confirm they were deleted, and that no confirmation had arrived when the post was made. TechCrunch relayed the post on 24 August 2026. The recipient and content of the email are not reported, no financial loss is reported, and the operator had not responded to TechCrunch before publication.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 3 sources, 2 underlying accounts · Added 29/09/2026
22 Feb 2026Event location unknownOpenClaw
Summer Yue, whom Business Insider describes as a director of alignment in Meta's Superintelligence Labs, posted on X on 23 February 2026 that an OpenClaw agent connected to Yue's real inbox had started deleting emails after Yue told it to confirm before acting. Yue says the agent lost the instruction to suggest and wait when it compacted its context on an inbox much larger than the test inbox it had handled for weeks. Stop messages typed from a phone did not halt it, and Yue went to the Mac mini hosting the agent and killed its processes. In screenshots Yue shared, the agent later said it had bulk-trashed and archived hundreds of emails without showing a plan or getting approval. Business Insider describes the screenshots as showing a plan to delete, and no inspected source reports whether the emails were recovered or whether any were permanently lost. Yue called the episode a rookie mistake.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 6 sources, 1 underlying account · Added 29/09/2026
Sept 2026GermanyUnidentified image tool
The Oldenburg-Stadt police inspectorate said on 22 September 2026 that in the preceding days numerous messages had been sent through one or more student accounts on the email servers of Oldenburg schools. The messages contained, among other things, deepfakes (manipulated depictions of children and young people); on an initial assessment some of these could constitute the offence of distributing child or youth sexual abuse material, and some messages contained threats of violence and calls for recipients to harm themselves. According to dpa, students and parents reported the incidents to the police, and dpa, reporting a police spokesman, describes the images as made with artificial intelligence (the written police statement calls them deepfakes, manipulated depictions, without naming AI). Investigators are examining whether unknown persons gained unauthorised access to the accounts; first digital traces were secured and the police are working with the affected schools. RND reports that the accounts were on the IServ school platform, whose provider said it had no access to the messages and believed the incident was limited to Oldenburg. The exact number of schools (the police refer to 'the affected schools', plural), messages, depicted children and recipients, and who created the images, are not reported.
Core concern Medium reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution alleged · 4 sources, 2 underlying accounts · Added 27/09/2026
19 May 2026United StatesUnidentified voice-cloning tool (suspected)
A married couple in their sixties buying a US$460,000 condo in Hudsonville, near Grand Rapids, Michigan, received an email on 19 May 2026, days before closing, telling them to wire US$66,026.92 for the down payment and closing costs within 24 hours. The email listed a phone number differing from their loan officer's by two digits, and the husband then received a call confirming the instructions in a voice that sounded just like the loan officer. The couple borrowed from family and other sources and wired the money. The day before closing their real loan officer sent the actual statement; the closing was cancelled hours before signing and the money was gone. The husband now believes the call came from a spoofed number using AI-assisted voice cloning; Tyler Adams of CertifID, which is working with the couple and federal officials, said someone's email in the transaction was probably compromised and that the scammers likely cloned the loan officer's voice from social-media clips. The sender's address had two extra letters ('UnitedsMortgages' instead of 'UnitedMortgage'). Neither the lender nor the loan officer is accused of complicity. The couple later completed the purchase in early June from their mutual fund, reported the loss to the FBI's Internet Crime Complaint Center, and describe lasting apprehension and have discussed delaying retirement. CNN reported the case on 15 September 2026; the account the money went to has since closed.
Core concern Medium reported severity Investigation Opened
AI involvement suspected · Causal attribution alleged · 2 sources, 1 underlying account · Added 20/09/2026
May 2026SingaporeUnidentified video tool
In May 2026 the Singapore Police Force (SPF) reported that a man had lost at least S$4.9 million (about US$3.8 million) to a government-official impersonation scam. He received a WhatsApp message carrying the profile photo of Secretary to the Cabinet Wong Hong Kuan and an email from a proton.me address in that name, requesting urgent funding assistance for 'the situation in the Strait of Hormuz', with a fake 'letter of guarantee' bearing the Prime Minister's signature promising reimbursement within 15 business days; he signed a non-disclosure agreement and supplied a copy of his identity card. He was then invited to a Zoom video conference in which Prime Minister Lawrence Wong, President Tharman Shanmugaratnam, Minister Indranee Rajah, Monetary Authority of Singapore representatives and foreign officials appeared; all were fabricated with deepfake AI, and the closing 'remarks' by the fake Prime Minister acknowledged the victim's attendance. Contacted afterwards on WhatsApp by a scammer posing as a lawyer, he transferred the money in a series of transactions to a corporate bank account, and realised the fraud only when he contacted the real cabinet secretary. On 16 May the police released footage of the fake conference, noting lips out of sync with speech, audio broadcast from a single account and a distorted background.
Core concern High reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 3 sources, 1 underlying account · Added 18/09/2026
12 Mar 2026 to 25 Aug 2026United KingdomUnidentified AI tool
On 25 August 2026 the Solicitors Disciplinary Tribunal struck Abhishek Kumar off the Register of Foreign Lawyers after finding proved that his 12 March 2026 Answer to the SRA's Rule 12 Statement contained misleading quotations and citations produced with generative AI — including a non-existent 'SRA v Chan [2020] EWHC 1502' and a miscited 'SRA v James, MacGregor & Naylor [2018] EWCA Civ 1420' that is actually an intellectual-property case — and that his 9 April 2026 email admitting AI use was itself AI-drafted with further errors. The tribunal said it would have struck him off on that allegation alone; the parallel ground was his January 2024 conviction under s.21 of the Immigration, Asylum and Nationality Act 2006. This is the SDT's first case on a lawyer's use of AI, per the SRA's counsel.
Core concern High reported severity Regulatory Action
AI involvement supported · Causal attribution established · 5 sources · Added 15/09/2026