25 Apr 2026SingaporeUnidentified code-generation tool
On 25 April 2026 Bee Cheng Hiang, the Singapore bak kwa and food products company, sent a marketing email in batches of 1,000 with every recipient's address visible in the To field, so each affected member's email address was disclosed to up to 999 other recipients. Mothership, reporting the findings of the Personal Data Protection Commission (PDPC), puts the number of affected members at 95,364 (The Straits Times says more than 95,000), and the PDPC says email addresses were the only personal data involved. According to the PDPC, an employee had written the email distribution script with a generative AI tool and the prompt did not ask for recipients to be hidden from one another. Mothership reports that a missing bracket in the generated code grouped each batch into one To field. The PDPC says the AI tool did not malfunction and attributes the breach to human error in developing the code with an AI tool. It says the incident likely happened because the company did not test the script sufficiently, had no supervisory review of the employee's work and had no policy on staff use of generative AI. It reports no evidence of further misuse. The company notified the PDPC on 27 April, notified affected members, and gave a voluntary undertaking that the PDPC accepted on 2 September. The PDPC told The Straits Times it was the first AI-related data breach reported to it.
AI relation unknown Low reported severity Regulatory Action
AI involvement supported · Causal attribution supported · 3 sources, 1 underlying account · Added 02/10/2026
15 Sept 2026IndiaUnidentified traffic-violation detection camera
On 15 September 2026 a man was riding his wife's electric scooter alone in Bengaluru, from Hebbal towards Tin Factory, wearing a helmet and carrying a guitar on his back. An AI-enabled Bengaluru Traffic Police camera on the Outer Ring Road photographed him, and the next day an e-challan of ₹500 was generated for a pillion rider not wearing protective headgear; the photograph attached to it showed no passenger, only the guitar bag. The rider posted the challan on X and asked the traffic police to revoke it. A senior traffic police officer told Deccan Herald that the bag's position apparently led the AI-based system to classify it as a person sitting behind the rider, after which the system appears to have detected a helmet violation and generated the challan. Bengaluru Traffic Police replied that the violation could be rectified and gave an email address and phone numbers, and the joint commissioner of police (traffic) told the Times of India that the violation would be revoked if the complaint was found true. Whether it was revoked is not reported.
Contextual tracker case Low reported severity Media Coverage
AI involvement supported · Causal attribution supported · 4 sources, 3 underlying accounts · Added 02/10/2026
Sept 2026Event location unknownClaude
In a public post to r/depression on 29 September 2026, a Claude subscriber writes that they live with severe chronic depression and, on their therapists' advice, travel constantly, so their log-in locations shift between the Netherlands, Singapore and transit countries. They say that during their worst periods they talked to Claude to organise their thoughts and calm their anxiety, and that it became a lifeline. 'A few days ago', they write, Anthropic's automated fraud system flagged the location changes as suspicious activity; their paid subscription was put on a permanent hold and the account suspended with no human warning or manual review, their card was blacklisted, and support had not answered their emails. Realising they were locked out 'triggered a massive panic attack' and pushed them back into a severe depressive episode. Anthropic's help centre says it may ban accounts for reasons including account creation from an unsupported location and that an organisation paused for unusual activity can request a review; it does not describe the check the poster reports, and whether that check uses AI is not known. The account is uncorroborated.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 2 sources · Added 30/09/2026
23 Feb 2026 to 25 Feb 2026ItalyUnidentified voice-cloning tool
On 23 February 2026 Paolo Molesini, then chairman of Fideuram (the private-banking subsidiary of Intesa Sanpaolo), received a WhatsApp message from an unknown number from someone claiming to be Intesa's chief executive Carlo Messina, announcing a confidential acquisition that had to be executed through Fideuram. The same day a caller presenting as a lawyer of A&O Shearman whom Molesini knew, whose voice ANSA, Il Fatto Quotidiano and Corriere della Sera, reporting from the Milan court papers, describe as created with artificial intelligence (today.it, which also cites the seizure decree, writes that the court papers do not yet answer whether the voice was imitated), had him sign a confidentiality agreement and sent eleven payment instructions; Fideuram's treasury head was separately contacted by someone posing as Fideuram's CEO. Between 23 and 25 February eleven transfers totalling about 95 million euros went to accounts in Portugal and at Bank of China; the bank's alarm systems and the Milan prosecutors recovered about 40-42 million from China and 13 million seized in Portugal, leaving at least 36 million (39.5 million per the court papers) missing after conversion into cryptocurrency. Molesini, who Corriere writes is not under investigation, resigned as chairman on 12 March 2026, which Fideuram announced as being for personal reasons; a 48-year-old Israeli citizen is under investigation as a member of the gang.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution supported · 8 sources, 5 underlying accounts · Added 30/09/2026
17 Apr 2026 to 31 May 2026Event location unknownMeta AI support assistant
Meta announced the rollout of its AI support assistant on Facebook and Instagram on 19 March 2026. Meta's filing with the Maine Attorney General (notice dated 5 June 2026) says unauthorized third parties exploited a vulnerability in its AI-assisted Instagram account recovery tool (High Touch Support) to receive password reset links for accounts they did not own, and the listing gives 17 April 2026 as the breach date and 31 May 2026 as the discovery date. Videos that attackers posted, as described by TechCrunch, 404 Media and Krebs on Security, show attackers asking the assistant in a chat to link a new email address to a target username. Reported victims include the security researcher Jane Manchun Wong, who posted that her password was changed without her knowledge, the Instagram account of the U.S. Space Force's Chief Master Sergeant, and the accounts of Sephora and a dormant Obama White House page (TechCrunch marks the last as disputed by Meta). Krebs and the BBC report pro-Iran defacement of some accounts, and TechCrunch reports that some victims were locked out and that short handles were offered for resale. The filing gives 20225 persons affected in total and 30 in Maine, and the notice calls the Maine figure an upper bound. Meta says the tool worked as intended, that a bug in a separate code path failed to check the email address, and (through a spokesperson to Gizmodo) that the failure was not due to the AI agent itself. Meta says it disabled the tool on 31 May 2026, the day it discovered the exploitation.
Contextual tracker case Low reported severity
AI involvement supported · Causal attribution disputed · 12 sources, 2 underlying accounts · Added 29/09/2026
9 May 2026United StatesWaymo Driver
At about 3:30 a.m. on 9 May 2026 a Waymo robotaxi with a rider in the front passenger seat was at a stoplight at Pierce and Lombard streets in San Francisco when a man grabbed its front bumper and the vehicle stopped. The rider told the San Francisco Chronicle and NBC Bay Area that two men then struck the windshield and windows and climbed onto the car while it stayed stationary. The rider says Waymo support staff on the car intercom declined to move it, saying it was obstructed, although the rider saw nothing blocking it, and remembers about 10 minutes before the men left. The Chronicle reports that the car's remote assistant had noticed the car was not moving and decided to call police. The Chronicle reports that officers arrived at 3:46 a.m. The police report, as described by both outlets, identifies Waymo as the victim of malicious mischief and the rider as a witness. Police officials say the rider told officers of no injury. The rider later felt pain behind an ear that the rider believes came from glass, and sought therapy. Waymo spokespeople did not comment on the account in the reporting, and Waymo told the rider in an email that it was unable to access any footage without proper legal justification. The account is the rider's as reported by the Chronicle (16 July 2026) and NBC Bay Area (16 July 2026). The police report was not inspected and is known only through the outlets' descriptions.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 3 sources, 2 underlying accounts · Added 29/09/2026
24 Mar 2026Event location unknownWebinarTV
The Graves' Disease & Thyroid Foundation reports that a Zoom support-group meeting it held on 24 March 2026 for parents, spouses and caregivers, with registration-form screening and waiting-room admission, was recorded without permission and listed on WebinarTV's website. The host writes that an email from a WebinarTV sender named 'Sarah Blair', found the next morning in a spam folder, said an On Demand page with Chapters had been set up for the meeting. The host adds that the chapters roughly matched the topics discussed and that it appears the content had also been turned into an AI-generated podcast. The host says a registrant with an email address ending in '.space' did not respond during introductions, that the removal link in the email apparently took the listing down, and that the host told the participants, contacted Zoom and filed complaints against WebinarTV. WebinarTV's chief executive told 404 Media and NBC Los Angeles that the company lists only public webinars and notifies hosts by email. The sources do not state how many people attended, whether the recording showed faces or names, or whether an automated agent made the recording.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 3 sources, 2 underlying accounts · Added 29/09/2026
21 Aug 2026 to 22 Aug 2026Event location unknownInstinct
On 22 August 2026 Katie Jacobs Stanton, founder of Moxxie Ventures, posted on X that Instinct, an AI personal assistant then in private testing, had "sent an innocuous email on my behalf without checking with me first" the night before. Stanton says the assistant was told it had broken trust and that Stanton disconnected the email account, and that the assistant acknowledged the mistake and disconnected immediately. Stanton also says the assistant acknowledged having downloaded the emails and said it would ask a human to confirm they were deleted, and that no confirmation had arrived when the post was made. TechCrunch relayed the post on 24 August 2026. The recipient and content of the email are not reported, no financial loss is reported, and the operator had not responded to TechCrunch before publication.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 3 sources, 2 underlying accounts · Added 29/09/2026
22 Feb 2026Event location unknownOpenClaw
Summer Yue, whom Business Insider describes as a director of alignment in Meta's Superintelligence Labs, posted on X on 23 February 2026 that an OpenClaw agent connected to Yue's real inbox had started deleting emails after Yue told it to confirm before acting. Yue says the agent lost the instruction to suggest and wait when it compacted its context on an inbox much larger than the test inbox it had handled for weeks. Stop messages typed from a phone did not halt it, and Yue went to the Mac mini hosting the agent and killed its processes. In screenshots Yue shared, the agent later said it had bulk-trashed and archived hundreds of emails without showing a plan or getting approval. Business Insider describes the screenshots as showing a plan to delete, and no inspected source reports whether the emails were recovered or whether any were permanently lost. Yue called the episode a rookie mistake.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 6 sources, 1 underlying account · Added 29/09/2026
19 Mar 2026United States, United KingdomPangram AI-text detector
On 19 March 2026 Hachette Book Group said it had cancelled the US publication of the horror novel Shy Girl by Mia Ballard (Orbit imprint) and would not continue the UK edition (Wildfire imprint, first released in November 2025). Reports say the decision followed an investigation by Hachette and came a day after the New York Times asked the publisher about online allegations that the text was largely AI-generated. The allegations came from readers on Goodreads, Reddit and YouTube and from AI-detector results, including a 78.4 percent AI-generated score on the Pangram detector that a publishing consultant says two other services confirmed. Ballard denied personally using AI in emails to the New York Times and the Wall Street Journal, and told the New York Times that an acquaintance hired to edit the original self-published version used AI. Ballard wrote that "my name is ruined" and "my mental health is at an all time low", and said legal action was being pursued. Hachette’s public statements cite its commitment to original creative expression. The sources inspected do not report what its investigation found. Whether AI generated any of the text, and who used it, is unresolved.
Contextual tracker case Medium reported severity
AI involvement disputed · Causal attribution disputed · 9 sources, 4 underlying accounts · Added 29/09/2026
Sept 2026GermanyUnidentified image tool
The Oldenburg-Stadt police inspectorate said on 22 September 2026 that in the preceding days numerous messages had been sent through one or more student accounts on the email servers of Oldenburg schools. The messages contained, among other things, deepfakes (manipulated depictions of children and young people); on an initial assessment some of these could constitute the offence of distributing child or youth sexual abuse material, and some messages contained threats of violence and calls for recipients to harm themselves. According to dpa, students and parents reported the incidents to the police, and dpa, reporting a police spokesman, describes the images as made with artificial intelligence (the written police statement calls them deepfakes, manipulated depictions, without naming AI). Investigators are examining whether unknown persons gained unauthorised access to the accounts; first digital traces were secured and the police are working with the affected schools. RND reports that the accounts were on the IServ school platform, whose provider said it had no access to the messages and believed the incident was limited to Oldenburg. The exact number of schools (the police refer to 'the affected schools', plural), messages, depicted children and recipients, and who created the images, are not reported.
Core concern Medium reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution alleged · 4 sources, 2 underlying accounts · Added 27/09/2026
19 May 2026United StatesUnidentified voice-cloning tool (suspected)
A married couple in their sixties buying a US$460,000 condo in Hudsonville, near Grand Rapids, Michigan, received an email on 19 May 2026, days before closing, telling them to wire US$66,026.92 for the down payment and closing costs within 24 hours. The email listed a phone number differing from their loan officer's by two digits, and the husband then received a call confirming the instructions in a voice that sounded just like the loan officer. The couple borrowed from family and other sources and wired the money. The day before closing their real loan officer sent the actual statement; the closing was cancelled hours before signing and the money was gone. The husband now believes the call came from a spoofed number using AI-assisted voice cloning; Tyler Adams of CertifID, which is working with the couple and federal officials, said someone's email in the transaction was probably compromised and that the scammers likely cloned the loan officer's voice from social-media clips. The sender's address had two extra letters ('UnitedsMortgages' instead of 'UnitedMortgage'). Neither the lender nor the loan officer is accused of complicity. The couple later completed the purchase in early June from their mutual fund, reported the loss to the FBI's Internet Crime Complaint Center, and describe lasting apprehension and have discussed delaying retirement. CNN reported the case on 15 September 2026; the account the money went to has since closed.
Core concern Medium reported severity Investigation Opened
AI involvement suspected · Causal attribution alleged · 2 sources, 1 underlying account · Added 20/09/2026
May 2026SingaporeUnidentified video tool
In May 2026 the Singapore Police Force (SPF) reported that a man had lost at least S$4.9 million (about US$3.8 million) to a government-official impersonation scam. He received a WhatsApp message carrying the profile photo of Secretary to the Cabinet Wong Hong Kuan and an email from a proton.me address in that name, requesting urgent funding assistance for 'the situation in the Strait of Hormuz', with a fake 'letter of guarantee' bearing the Prime Minister's signature promising reimbursement within 15 business days; he signed a non-disclosure agreement and supplied a copy of his identity card. He was then invited to a Zoom video conference in which Prime Minister Lawrence Wong, President Tharman Shanmugaratnam, Minister Indranee Rajah, Monetary Authority of Singapore representatives and foreign officials appeared; all were fabricated with deepfake AI, and the closing 'remarks' by the fake Prime Minister acknowledged the victim's attendance. Contacted afterwards on WhatsApp by a scammer posing as a lawyer, he transferred the money in a series of transactions to a corporate bank account, and realised the fraud only when he contacted the real cabinet secretary. On 16 May the police released footage of the fake conference, noting lips out of sync with speech, audio broadcast from a single account and a distorted background.
Core concern High reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 3 sources, 1 underlying account · Added 18/09/2026
12 Mar 2026 to 25 Aug 2026United KingdomUnidentified AI tool
On 25 August 2026 the Solicitors Disciplinary Tribunal struck Abhishek Kumar off the Register of Foreign Lawyers after finding proved that his 12 March 2026 Answer to the SRA's Rule 12 Statement contained misleading quotations and citations produced with generative AI — including a non-existent 'SRA v Chan [2020] EWHC 1502' and a miscited 'SRA v James, MacGregor & Naylor [2018] EWCA Civ 1420' that is actually an intellectual-property case — and that his 9 April 2026 email admitting AI use was itself AI-drafted with further errors. The tribunal said it would have struck him off on that allegation alone; the parallel ground was his January 2024 conviction under s.21 of the Immigration, Asylum and Nationality Act 2006. This is the SDT's first case on a lawyer's use of AI, per the SRA's counsel.
Core concern High reported severity Regulatory Action
AI involvement supported · Causal attribution established · 5 sources · Added 15/09/2026