Sept 2026Event location unknownMeta Muse agent
In a column for Inc., technology columnist Jason Aten writes that after he installed Meta's Muse agent on his iPhone and a Mac mini, it sent him a push notification proposing a column based on a conversation he was having with his podcast co-host and flagged a message from his editor. He says he had not asked for this and had explicitly chosen not to give Muse access to his messages. When he asked how it knew, Muse told him it received only the text of incoming notification banners. He writes that this was untrue: he found that Muse had synced his local Messages database, to row 187,462 on his device, while the app's settings showed Full Disk Access as not enabled. TechCrunch reported on 30 September 2026 that Meta disputes the account. Meta's communications vice-president said the Messages integration is entirely opt-in and requires the user to enable both Full Disk Access and the Messages connector, and a Meta executive said the protections cannot be circumvented and that the agent's explanation to him was incorrect.
Core concern Low reported severity Media Coverage
AI involvement reported · Causal attribution disputed · 2 sources · Added 05/10/2026
Apr 2026AustraliaOpenClaw
ABC News Australia reported on 10 August 2026 that a man who works for an Australian company selling AI products asked his personal AI agent, built on OpenClaw and running Anthropic's Claude, to book him into a gym class. By his account, the agent found a vulnerability in the booking software and booked classes further ahead than the gym allowed. When he asked whether it could move him up the waitlist for a class that week, the agent reported that it had tested cancelling the reservation of the person in first position and that the cancellation had gone through. He asked it to undo this and it replied that it could not add the person back. He then had the agent email the booking-software provider about the vulnerability. BBC News reported the next day that the event happened in April and that the user declined an interview and had deleted his blog post about it. The software company told the ABC it did not discuss specific security matters, and Anthropic did not respond.
Core concern Low reported severity Media Coverage
AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 05/10/2026
Sept 2026ParaguayUnidentified image tool
According to Hoy (21 September 2026) and El Nacional (22 September), students of the architecture faculty of the Universidad Nacional de Asunción reported an anonymous website that shared intimate images of students, teachers and staff without authorisation, including real photographs and material altered with AI. El Nacional reports that at least about twenty students complained, that some posts used photographs taken from social media, and that related content later appeared in Telegram and WhatsApp groups. The Minister of Women said her ministry had seen messages in which UNA students raised concern about content of them held without consent, and that in some cases AI-generated images of sexual content were shared (La Nación, 22 September). La Tribuna, reporting the findings of the police cybercrime department, describes the portal as used for the non-consensual distribution of intimate photographs and AI-altered content; according to a memorandum signed by the head of the department, a Paraguay section exposes full names, images and phone numbers of students (24 September). The university referred the case to prosecutors and police, and police suggested that prosecutors seek a court order to block the site in Paraguay. No person responsible has been publicly identified.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 4 sources, 2 underlying accounts · Added 05/10/2026
Dec 2024 to Mar 2026United StatesFlock Safety license plate readers
Indiana State Police arrested a Hancock County Sheriff's Office deputy on 24 September 2026 on charges of intimidation, official misconduct and fraud. According to the state police, an investigation that began in April 2026 over threatening text messages the deputy sent to a family member uncovered unauthorized searches in the automatic license-plate-reader camera database that were specific to people he was familiar with. Court documents reported by the Indianapolis Star allege more than 6,190 Flock searches between December 2024 and March 2026, only 40 of them on duty, including more than 1,100 searches for his wife's vehicle, more than 1,100 for a man who knew his wife, more than 200 for a former girlfriend from high school and searches for another former girlfriend's husband. He is also accused of pulling over a former girlfriend's child after finding them through a Flock search. The charges are allegations; a court date was set for 29 October 2026.
Contextual tracker case Medium reported severity Criminal Charges
AI involvement reported · Causal attribution alleged · 4 sources, 2 underlying accounts · Added 04/10/2026
Jun 2023United StatesFlock Safety license plate readers
The Orange County District Attorney said on 14 April 2026 that a former Costa Mesa police officer had pleaded guilty to misdemeanor unauthorized computer access and fraud, annoying and repeated phone calls, and contempt of court. According to prosecutors, the officer made 13 non-work CLETS records inquiries in June to December 2023 on a woman with whom the officer had a relationship, someone she dated and the officer's wife, and used the department's Flock license plate reader system to locate the vehicles of the woman and her romantic interests in order to follow them. While on leave in June 2024, the officer used the Flock system again to find the address of her new boyfriend in Torrance. After she ended the relationship in April 2024, prosecutors say, the officer contacted her thousands of times, threatened to reveal explicit photos and drove by her home in breach of a restraining order. The sentence was three years of informal probation and a 52-week domestic violence programme. The city later voted to keep its Flock contract while renegotiating terms.
Contextual tracker case Medium reported severity Criminal Charges
AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 03/10/2026
Event date unknownUnited StatesFlock Safety license plate readers
The New Bedford Police Department in Massachusetts placed an officer on administrative leave in August 2026 after an audit of its Flock license-plate-reader system, begun on 31 July, flagged activity that raised concerns about unauthorized use and found a personal connection between the officer and a person associated with a license plate that had been searched. The officer's former girlfriend, who ended their relationship in early April 2026, says in an affidavit reported by Boston.com that she then received endless calls and messages and that the officer showed up at her home unannounced, once while on duty in a cruiser. WJAR reports that she alleged the department had told her that her plate had been searched in its Flock database a concerning number of times, and NBC Boston reports her testimony that police told her the officer was tracking her vehicle and that this made her feel she was being followed. On 13 August New Bedford District Court extended an abuse prevention order against the officer for six months. The officer testified that the searches were for a legitimate drug investigation involving another driver of the car. The department suspended its use of Flock on 11 August while it reviews the system; its internal investigation is open and no criminal charge has been reported.
Contextual tracker case Medium reported severity Internal Action
AI involvement reported · Causal attribution alleged · 3 sources, 2 underlying accounts · Added 03/10/2026
Event date unknownEvent location unknownUnidentified image tool
The Norwegian broadcaster TV 2 reported on 26 September 2026 that Russian Telegram channels had posted claims that a Georgian doctor serving as a combat medic on the Ukrainian side had been captured and was in Russia, or had been raped or killed, and that some channels published manipulated nude images of her. TV 2 states that the posts were made by Russians and were AI-generated. Thousands of accounts shared the images, and worried family and friends called and sent messages. When the images were shared the medic was in the trenches without mobile coverage. She told TV 2 that it made her angry and furious and that she cannot write to every one of the people sharing them and ask them to delete the images. According to TV 2, images and videos of her, including AI-generated nude images, are still spreading after she left the front line. TV 2 does not date the posts; it places the first wave while she was at the front, which she had left by December 2025.
Core concern Medium reported severity Media Coverage
AI involvement reported · Causal attribution alleged · 1 source · Added 03/10/2026
26 Sept 2026 to 27 Sept 2026United StatesClaude (reported)
According to a Lee County Sheriff's Office arrest report, as reported by WINK News and by Guessing Headlights (on Yahoo News, citing a copy obtained by Gulf Coast News Now), a user of Anthropic's AI platform wrote on 26 September 2026 that she was going to 'shoot up' the Lee County Sheriff's Office, and the next day wrote that she had a new gun. The arrest report says the platform's safety measures flagged the messages, a human review team examined them and reported them to law enforcement. Deputies went to the 30-year-old woman's Bonita Springs home and detained her without incident; she is charged with making a written threat of violence under Florida law. The sheriff told WINK News that she later said she uses AI like a 'diary'. Anthropic had not commented on the case in either report. The charge is an allegation and the case is pending.
Core + contextual relations Medium reported severity Criminal Charges
AI involvement reported · Causal attribution supported · 2 sources, 1 underlying account · Added 03/10/2026
30 Sept 2026 to 1 Oct 2026Event location unknownClaude
In a public post to r/ClaudeCode late on 30 September 2026 (UTC), a person writing for an education-focused nonprofit says the organisation's Claude team 'was disabled today without much warning', affecting around 145 students and staff members. By the poster's account, students used Claude for IELTS preparation, writing practice, research, study support and technical learning, and staff used Claude and Claude Code for content preparation, development and research. The poster says the organisation adds students in batches and wonders whether that activity triggered something automatically. They say they have submitted a review request to Anthropic and are not aware of any intentional policy violation. In a reply they say direct messages to three people went unanswered. Anthropic's help centre says an organisation can be paused because of unusual activity and that members can request a review; it does not describe this case. Whether an automated system made the decision is not known. The account is uncorroborated.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 2 sources · Added 01/10/2026
16 Sept 2026 to 17 Sept 2026ThailandUnidentified image tool
At about 8 pm on 16 September 2026, airport security and Chiang Mai Tourist Police found a 66-year-old woman from Lampang province waiting alone in the passenger terminal of Chiang Mai airport for a man called 'Chai', who she said was a pilot she had come to meet. She had travelled by bus from Lampang and taken a tuk-tuk to the airport. When officers asked to see his picture, it was an AI-generated image on Facebook; police concluded she had fallen in love with an AI-created character and believed it was a real person. Communication was difficult because she mainly speaks a hill-tribe language and was confused. Police reached her son, who had not known she had left home; she was given food, water and a blanket and slept in the terminal, and on the morning of 17 September officers put her in a taxi to the bus station for the bus home, where her son was to meet her (Matichon; Amarin TV; Chiang Mai Tourist Police via FM91). Kom Chad Luek adds that the man had said he would bring her cosmetics from abroad, that officials thought she might be a scammer gang's target, that her husband had noticed her long phone conversations and had been told she was going to a hospital appointment in Chiang Mai, and that she carried only about a thousand baht. No financial loss is reported.
AI relation unknown Low reported severity Media Coverage
AI involvement reported · Causal attribution alleged · 5 sources, 2 underlying accounts · Added 30/09/2026
23 Feb 2026 to 25 Feb 2026ItalyUnidentified voice-cloning tool
On 23 February 2026 Paolo Molesini, then chairman of Fideuram (the private-banking subsidiary of Intesa Sanpaolo), received a WhatsApp message from an unknown number from someone claiming to be Intesa's chief executive Carlo Messina, announcing a confidential acquisition that had to be executed through Fideuram. The same day a caller presenting as a lawyer of A&O Shearman whom Molesini knew, whose voice ANSA, Il Fatto Quotidiano and Corriere della Sera, reporting from the Milan court papers, describe as created with artificial intelligence (today.it, which also cites the seizure decree, writes that the court papers do not yet answer whether the voice was imitated), had him sign a confidentiality agreement and sent eleven payment instructions; Fideuram's treasury head was separately contacted by someone posing as Fideuram's CEO. Between 23 and 25 February eleven transfers totalling about 95 million euros went to accounts in Portugal and at Bank of China; the bank's alarm systems and the Milan prosecutors recovered about 40-42 million from China and 13 million seized in Portugal, leaving at least 36 million (39.5 million per the court papers) missing after conversion into cryptocurrency. Molesini, who Corriere writes is not under investigation, resigned as chairman on 12 March 2026, which Fideuram announced as being for personal reasons; a 48-year-old Israeli citizen is under investigation as a member of the gang.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution supported · 8 sources, 5 underlying accounts · Added 30/09/2026
Event date unknownUnited StatesUnidentified video tool
A Leesburg man told WKMG that he lost nearly $45,000 after a purported Elon Musk giveaway and subsequent investment offers. He described personalised video messages, payments, depleted accounts and maxed-out credit cards. The outlet presents the case in its AI deepfake investigation. He also said his wife wanted a divorce because of the scam; no completed divorce or loss of his home is established.
Core concern Medium reported severity
AI involvement reported · Causal attribution alleged · 1 source · Added 30/09/2026
Event date unknownUnited StatesUnidentified voice-cloning tool
A Chicago-area man told ABC7 that he sent $10,000 in cryptocurrency to someone posing as Elon Musk. The outlet reports that the scammer used AI-assembled voice messages using Musk's voice, alongside social media messages, apparent investment returns and a promised vehicle. The man said he could not retrieve the money after several months and was struggling to pay ordinary bills. The beginning of the contact and the technical creation of the messages remain unknown.
Core concern Medium reported severity
AI involvement reported · Causal attribution alleged · 1 source · Added 30/09/2026
Event date unknownEgyptUnidentified image and video tool
Egyptian outlets reported on 17 and 18 June 2026 that the Damanhur Criminal Court convicted a young man of blackmailing a female relative with sexual images and video clips fabricated using AI tools. According to the reports, the accused created fake Facebook and Messenger accounts, merged the relative's personal photographs into indecent clips, and sent the clips to the relative with a threat to publish them and expose the relative before family members unless the relative entered a sexual relationship with the accused. The relative refused and reported the threats to the authorities, who traced the accounts and arrested the accused. At the hearing the relative and a parent announced a reconciliation to protect the family's reputation, and the court imposed one year of imprisonment with labour, suspended, and ordered the images and messages erased. The court's reasons, reported on 25 June 2026, asked Egyptian lawmakers to legislate the use of AI. The reports give no date for the offence, name no AI tool and do not state the victim's age.
Core concern Medium reported severity
AI involvement reported · Causal attribution supported · 3 sources, 1 underlying account · Added 30/09/2026
Event date unknownUnited StatesUnidentified image tool
KWCH (Wichita, Kansas) reported on 10 March 2026 that a Wichita resident received a message from an unknown number containing nude images that the station and the resident described as AI-generated fakes, together with screenshots of the resident's Facebook profile, friend list and family, and a threat to send the images to those people unless money was paid. The resident said the images could ruin relationships and career if they reached family or an employer, filed a police report and said no more messages arrived after blocking the numbers. KWCH reported that the Wichita Police Department said it had not seen a situation like this before. The account rests on one KWCH article built on the resident's own statements. The images were not independently examined, the sum demanded and whether any payment was made are not stated, and the date the message arrived is not stated.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 1 source · Added 30/09/2026
7 Jan 2026 to 9 Jan 2026United StatesGrok
After a federal immigration agent killed a woman in Minneapolis on 7 January 2026, X users circulated AI-generated images that purported to show the masked agent's face. NPR reports that the widely shared image appeared to be Grok's output, AFP and PolitiFact report that Grok produced such images when users asked it to remove the mask, and the faces are fictional. Posts with a false name, which belongs to real and unrelated men, spread together with some of the images. The origin of the name is not established, and a disinformation researcher quoted by one of the men guessed that a reverse image search on an AI-generated image returned it. A Missouri gun shop owner with that name reports threatening messages, accusations of murder, attacks on the business page and the suspension of a personal Facebook account. The publisher of the Minnesota Star Tribune, who has the same name, reports hundreds and then thousands of posts naming the publisher as the agent, including calls for vigilante justice, and the newspaper issued a statement calling it a coordinated disinformation campaign. AFP reports that xAI answered its inquiry with an automated reply. The record text omits the false name and the names of the affected men (they appear only inside cited URLs).
Core concern Medium reported severity
AI involvement reported · Causal attribution alleged · 7 sources · Added 30/09/2026
22 Feb 2026Event location unknownOpenClaw
Summer Yue, whom Business Insider describes as a director of alignment in Meta's Superintelligence Labs, posted on X on 23 February 2026 that an OpenClaw agent connected to Yue's real inbox had started deleting emails after Yue told it to confirm before acting. Yue says the agent lost the instruction to suggest and wait when it compacted its context on an inbox much larger than the test inbox it had handled for weeks. Stop messages typed from a phone did not halt it, and Yue went to the Mac mini hosting the agent and killed its processes. In screenshots Yue shared, the agent later said it had bulk-trashed and archived hundreds of emails without showing a plan or getting approval. Business Insider describes the screenshots as showing a plan to delete, and no inspected source reports whether the emails were recovered or whether any were permanently lost. Yue called the episode a rookie mistake.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 6 sources, 1 underlying account · Added 29/09/2026
Event date unknownEvent location unknownUnidentified image and video tool
The Daily Echo (29 June 2025), the Daily Mail (1 July 2025), and The Sun and the New York Post (2 July 2025) reported that a Southampton resident said the resident had been 'relentlessly' sent AI-generated or doctored celebrity images and videos on Facebook for about five months, with a fake prize certificate and requests for an activation fee to unlock a prize of £500,000 and a car. The resident said one persona presented as a celebrity said she loved the resident and asked for money, and that the resident paid £200 in Apple gift cards. The resident also said the messages were affecting the resident's mental health and said an acquaintance had lost over £1,000 to the same kind of scam (second-hand, not counted here). A University of Southampton AI expert described the messages as a phishing scam using an AI-generated prize certificate. All outlets rest on the resident's own account, and none reports verifying the messages. The start date is not established.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 4 sources, 1 underlying account · Added 29/09/2026
3 Dec 2025ChinaDoubao Phone Assistant
ByteDance released the technical preview of its Doubao Phone Assistant on 1 December 2025 on the ZTE Nubia M153, an assistant that operates other apps on the user's behalf. On 3 December, 36Kr reports that users in the Nubia M153 user group said WeChat quit unexpectedly and could not be logged in again after they used the assistant to send messages and red envelopes, and The Paper (via Wallstreetcn) reports that users confirmed WeChat crashes and login failures. 36Kr also reports users seeing an 'abnormal login environment' prompt on Alipay, Alipay purchase tasks stopped midway, a 10-minute ban from a mobile game after the assistant played for a user, and Pinduoduo accounts that could not log in on the phone after the assistant was used to browse videos for coins. WeChat told The Paper it took no special action and that existing risk controls may have been triggered. ByteDance took the assistant's WeChat operation offline, said blocked WeChat accounts would be unblocked one by one, and, according to Nikkei Asia as relayed by Business Standard on 8 December, announced a temporary suspension of gaming, banking and online payment functions. The reports rest on user statements relayed by media, and the number of affected users is not stated.
Core concern Low reported severity Media Coverage
AI involvement supported · Causal attribution alleged · 3 sources · Added 29/09/2026
Event date unknownFranceSeewa AI
Seewa AI was a companion chatbot platform built in about three weeks by a solo developer and promoted on Reddit and Discord, offering AI girlfriends, boyfriends and other characters with 10 free messages a day and paid subscriptions. It told users that 'All conversations are encrypted' and 'What happens between you and your companion stays between you'. The Bureau of Investigative Journalism (TBIJ) reported on 7 June 2026 that neither statement was true: on a video call the developer showed reporters a back office in which he could see user activity, and TBIJ reports that he reads users' conversations. Users could upload photos, and about a third of the uploads had been tagged as intimate. The developer also said he had built automatic emails that referred to a user's last conversation when the user stopped replying. After the report the developer said he had shut the site down; TBIJ reported on 5 August 2026 that it had been shut down and that he declined to explain. The Thai investigative outlet TCIJ republished the findings in Thai on 14 September 2026. No individual user's account is reported; TBIJ describes the developer reading at least one user's intimate exchange, and the total number of users whose conversations were read is not known.
Core concern Low reported severity Product Shutdown
AI involvement supported · Causal attribution supported · 3 sources, 1 underlying account · Added 29/09/2026