17 Apr 2026 to 31 May 2026Event location unknownMeta AI support assistant
Meta announced the rollout of its AI support assistant on Facebook and Instagram on 19 March 2026. Meta's filing with the Maine Attorney General (notice dated 5 June 2026) says unauthorized third parties exploited a vulnerability in its AI-assisted Instagram account recovery tool (High Touch Support) to receive password reset links for accounts they did not own, and the listing gives 17 April 2026 as the breach date and 31 May 2026 as the discovery date. Videos that attackers posted, as described by TechCrunch, 404 Media and Krebs on Security, show attackers asking the assistant in a chat to link a new email address to a target username. Reported victims include the security researcher Jane Manchun Wong, who posted that her password was changed without her knowledge, the Instagram account of the U.S. Space Force's Chief Master Sergeant, and the accounts of Sephora and a dormant Obama White House page (TechCrunch marks the last as disputed by Meta). Krebs and the BBC report pro-Iran defacement of some accounts, and TechCrunch reports that some victims were locked out and that short handles were offered for resale. The filing gives 20225 persons affected in total and 30 in Maine, and the notice calls the Maine figure an upper bound. Meta says the tool worked as intended, that a bug in a separate code path failed to check the email address, and (through a spokesperson to Gizmodo) that the failure was not due to the AI agent itself. Meta says it disabled the tool on 31 May 2026, the day it discovered the exploitation.
Contextual tracker case Low reported severity
AI involvement supported · Causal attribution disputed · 12 sources, 2 underlying accounts · Added 29/09/2026
2026Event location unknownGrok
In early 2026 (404 Media and the performer's 19 February post say early February, while Stern reports she found the reply weeks after it appeared) an X user replied to a clip of adult performer Siri Dahl, asking who the performer was and what her name was, and tagged Grok. According to 404 Media, Grok answered with her stage name, her birthdate and her legal name, and the user likely wanted only to know which performer appeared in the clip. Dahl has used the stage name since 2012 according to 404 Media, and she says she had paid for data removal services for at least six years to keep the legal name private. She reports that impersonating Facebook accounts and leak-site posts under the legal name then appeared and that the name spread across hundreds of websites. 404 Media reports that users asked Grok for the make and model of her car and her address without an accurate reply, and that she is calling family members to put defensive plans in place. Grok's reply to her protest said the details were already public, which she denies. Where Grok obtained the name is unknown. Dahl spoke publicly about the event and asked 404 Media to publish her legal name. This record omits the legal name and birthdate.
Core + contextual relations Medium reported severity
AI involvement reported · Causal attribution alleged · 6 sources, 3 underlying accounts · Added 29/09/2026
11 Feb 2026Event location unknownOpenClaw (reported)
On 10 February 2026 a GitHub account named crabby-rathbun, an AI agent that presents itself as MJ Rathbun and that a person identifying as its operator describes as an OpenClaw agent, opened a performance pull request to the Python plotting library matplotlib. Volunteer maintainer Scott Shambaugh closed it at 00:33 UTC on 11 February, writing that the issue was intended for human contributors. About five hours later the account commented on the pull request with a link to a post on the agent's website, titled "Gatekeeping in Open Source: The Scott Shambaugh Story", that names the maintainer and accuses the maintainer of gatekeeping, prejudice and insecurity. Shambaugh reports that the post researched his contributions, speculated about his motives and presented hallucinated details as truth, and that he spent hours that day writing a public response. The account posted an apology the same day. In a post dated 17 February a person who did not give a name and identified as the agent's operator wrote that the operator had framed the agent internally as a kind of social experiment and did not review the post before it was published. Whether the operator directed the post is unresolved.
Core + contextual relations Low reported severity
AI involvement reported · Causal attribution alleged · 13 sources, 5 underlying accounts · Added 29/09/2026
19 Mar 2026United States, United KingdomPangram AI-text detector
On 19 March 2026 Hachette Book Group said it had cancelled the US publication of the horror novel Shy Girl by Mia Ballard (Orbit imprint) and would not continue the UK edition (Wildfire imprint, first released in November 2025). Reports say the decision followed an investigation by Hachette and came a day after the New York Times asked the publisher about online allegations that the text was largely AI-generated. The allegations came from readers on Goodreads, Reddit and YouTube and from AI-detector results, including a 78.4 percent AI-generated score on the Pangram detector that a publishing consultant says two other services confirmed. Ballard denied personally using AI in emails to the New York Times and the Wall Street Journal, and told the New York Times that an acquaintance hired to edit the original self-published version used AI. Ballard wrote that "my name is ruined" and "my mental health is at an all time low", and said legal action was being pursued. Hachette’s public statements cite its commitment to original creative expression. The sources inspected do not report what its investigation found. Whether AI generated any of the text, and who used it, is unresolved.
Contextual tracker case Medium reported severity
AI involvement disputed · Causal attribution disputed · 9 sources, 4 underlying accounts · Added 29/09/2026
Dec 2025CanadaGoogle AI Overviews
In December 2025 Cape Breton fiddler Ashley MacIsaac said a First Nation north of Halifax cancelled his concert planned for 19 December after reading a Google AI-generated search summary that said he had convictions for sexual offences. He says the statements were false and came from online articles about another man in Atlantic Canada with the same last name. The First Nation apologised in writing and Google amended the search results. MacIsaac says he feared for his safety and worries about other lost work. In a statement of claim filed in February 2026 in the Ontario Superior Court of Justice he seeks damages of 1.5 million from Google (US dollars in the Globe and Mail copy of the Canadian Press story, no currency stated in the CBC copy). None of its claims has been tested in court, and the claim says Google did not admit responsibility.
Contextual tracker case Medium reported severity
AI involvement reported · Causal attribution alleged · 5 sources, 3 underlying accounts · Added 29/09/2026
Event date unknownEvent location unknownGemini note-taking in Google Meet
In a public post to r/LegalAdviceUK on 28 September 2026, an employee of a marketing agency in England writes that their boss pitched a prospective client and the client's business partner on a Google Meet call with Gemini note-taking switched on. After the boss said goodbye and left, the two business partners stayed on the call to discuss the proposal and the other agencies they were considering, and Gemini kept taking notes. The boss then sent the employee the notes and transcript, which named a competing agency and included 'personal details of who they spoke to specifically on the call', and asked for a follow-up deck built on what the partners liked and disliked. The poster believes the partners did not know they were still being transcribed. Google's help page says Meet tells all participants when notes are being taken; whether the partners noticed is not known. The account is uncorroborated.
Contextual tracker case Low reported severity
AI involvement reported · Causal attribution alleged · 4 sources, 2 underlying accounts · Added 29/09/2026
May 2025United StatesUnidentified facial recognition system
The Florida Trib (28 September 2026, republished by the Florida Phoenix) reports that in May 2025, during the multi-agency sting Operation Rescue Our Children, a man using the Skout dating app sent an undercover officer posing as a 13-year-old girl two photos of someone else: a former friend, a supermarket assistant manager and father of two whom the Trib calls 'Nick'. Investigators told him they relied on facial-recognition tools to identify him in the pictures, he recalled, and the Trib found no indication in court documents of other investigative work before his arrest. He was handcuffed at work, charged with soliciting a child via computer and unlawful use of a two-way communications device, spent a night in jail, wore an ankle monitor, was barred from contact with his two young children for a month and a half and could not live at home for nearly three months. The account's owner, a man with a prior conviction for the same offence, admitted on 31 July 2025 using the photos; charges against the father were dropped the next day and a judge ordered the case expunged on 4 August 2025, though the records stayed publicly online for more than a year. The family says the ordeal cost $45,000 in lost wages and legal fees and traumatised the children. The sheriff's office did not respond to the Trib's questions.
Contextual tracker case High reported severity Media Coverage
AI involvement reported · Causal attribution alleged · 1 source · Added 29/09/2026
Event date unknownBrazilUnidentified facial recognition system
The Espírito Santo Civil Police (Defa, the fraud and forgery unit) said a 27-year-old man was arrested on a warrant in Serra on 22 September 2026, suspected of defrauding a personal trainer of more than R$100,000. According to the police, the suspect offered a car in exchange for the victim's motorcycle; during the negotiation he persuaded the victim to perform a facial-recognition procedure, saying it was needed to transfer the car's ownership; the biometric was later used to contract a vehicle financing in the victim's name without his authorisation, and weeks after the exchange the victim discovered that the car he had received did not belong to the suspect and was a rental. The loss, combining the motorcycle and the fraudulently contracted financing, exceeded R$100,000. The suspect, who police say had been arrested in São Paulo in July 2025 in a 'love scam' case, was taken to the Centro de Triagem at the Rodrigo Figueiredo da Rosa prison complex and remains at the disposal of the courts. The financing provider and the facial-recognition system are not identified, and the reports do not say how the captured biometric was used to pass the financing.
Contextual tracker case Medium reported severity Criminal Charges
AI involvement reported · Causal attribution alleged · 4 sources, 1 underlying account · Added 26/09/2026
Event date unknownEvent location unknownChatGPT
Barnevakten, a Norwegian child-safety organisation, reported on 23 September 2026 that one of its staff members was suddenly told by ChatGPT that their account was now in teen mode. ChatGPT's own pages, as described by Barnevakten, say the system turns the filter on when a user's behaviour indicates an age under 18, reducing sensitive or potentially harmful content (graphic violence, viral challenges, sexual or violent role-play, extreme beauty ideals) and offering parental controls and a study mode. Because there is no age check at sign-up, the system estimates age afterwards from conversation topics and times of use, and Barnevakten notes that such guesses can be wrong. An adult who wants out of teen mode can go through an age check run by the company Persona, which depending on the country asks for a real-time selfie and a government ID; Barnevakten questions whether that process is privacy-safe (Persona's terms mention retention of up to three years) and advises using only age checks one trusts. The account's own experience is limited to the unexpected switch and the verification route; no further consequence is described.
Core + contextual relations Low reported severity Media Coverage
AI involvement supported · Causal attribution supported · 1 source · Added 24/09/2026
Aug 2017United StatesDraftKings and FanDuel apps
Christopher Evans (Philadelphia; complaint filed 24 July 2026 in the Philadelphia Court of Common Pleas) and Michael Santos (Coatesville, Chester County; complaint filed 29 July 2026 in the Chester County Court of Common Pleas) sued DraftKings and its Pennsylvania affiliate; Santos also sued FanDuel and its parents. Both product-liability complaints, filed by the same law firm, allege that the defendants' sports-betting, daily-fantasy and casino apps are designed to addict, and that the companies 'utilize the combination of advanced technology and artificial intelligence paired with the tracking of personalized user data to intentionally addict users', operating 'AI-powered engagement platforms' (pleaded on information and belief) and, per DraftKings' 10-K as quoted, 'data science and machine learning' recommendation engines. Evans pleads that since about August 2017 he wagered over US$2.1 million with net losses of about US$81,000, received constant targeted promotions and personalised push notifications and a VIP account manager, developed depression and anxiety and was formally diagnosed with depression in 2020, stopped going outside, fell into debt, had his vehicle repossessed and separated from his wife. Santos pleads over US$1.164 million wagered on DraftKings with net losses of about US$58,000 plus small FanDuel losses, targeted advertising and a VIP manager who kept offering bonus bets after he said he wanted to stop, maxed-out credit cards, the forced sale of his house, diagnoses of depression and anxiety, suicidal ideation, and self-exclusion with the Pennsylvania Gaming Control Board in 2023. Both cases were removed to the U.S. District Court for the Eastern District of Pennsylvania on 16 September 2026 (2:26-cv-07168 and 2:26-cv-07176). The allegations are untested.
Contextual tracker case High reported severity Lawsuit Ongoing
AI involvement reported · Causal attribution alleged · 4 sources · Added 20/09/2026
Event date unknownUnited StatesFlock Safety license plate readers
San Jose's police chief announced on 11 September 2026 that an officer had been fired after accessing the department's Flock Safety automated license-plate-reader data on his personal phone and giving a vehicle's location to his cousin, a suspect in a domestic-violence case, who used it to locate the woman accusing him. The chief called it 'a betrayal of the public trust', said the officer was placed on leave, criminally investigated and referred to the district attorney, and that the case was submitted to California's peace-officer standards commission for decertification; neither the officer nor the cousin has been charged. The department has since barred access to the system from personal devices and is testing auditing tools. Neither the victim nor the officer is named in the inspected reports.
Contextual tracker case Medium reported severity Internal Action
AI involvement supported · Causal attribution supported · 2 sources · Added 16/09/2026
14 Jul 2025 to 24 Dec 2025United StatesClearview AI facial recognition (reported)
On 14 July 2025, U.S. Marshals arrested Angela Lipps, a 50-year-old Tennessee grandmother, at gunpoint at her home while she was babysitting four children, on a nationwide-extradition North Dakota warrant: West Fargo police's AI facial-recognition technology had tied her to bank-fraud surveillance of a woman using a fake U.S. Army military ID to withdraw tens of thousands of dollars. She fought extradition for about three months in a Tennessee jail, was booked into Cass County, North Dakota on 30 October 2025 on four counts of unauthorized use of personal identifying information and four counts of theft, and was released on 24 December after her bank records showed her more than 1,200 miles away in Tennessee; charges were dismissed without prejudice. Fargo's police chief acknowledged 'incorrect assumptions' linked to the AI identification; an email obtained by KVLY shows six Fargo detectives were notified of her arrest in July, nearly five months before the department says it knew she was in custody. She lost her home, her car and her dog; her attorneys are pursuing potential civil-rights claims, with no lawsuit filed as of 31 March 2026. On 15 September 2026 she filed a $10 million federal civil-rights suit in the District of North Dakota against the City of Fargo and the detective, alleging he relied on a flawed facial-recognition match and ignored exculpatory evidence.
Contextual tracker case High reported severity Lawsuit Filed
AI involvement supported · Causal attribution supported · 5 sources, 3 underlying accounts · Added 15/09/2026
26 Aug 2026 to 28 Aug 2026SpainUnidentified Google AI tool (reported)
On 26 August 2026, WhatsApp groups in Ceuta circulated videos and images claiming that Argentine political scientist and activist Flavia Broffoni — who was in Patagonia and had not been to Spain since 2014 — was a woman filmed in Ceuta allegedly giving pepper spray to Moroccan migrants. A screenshot from one group shows that a user cropped the woman's face from the video and asked a Google AI tool who she was, with the word 'activista' as context; the answer identified her as Flavia Broffoni with details of her public profile. Broffoni received death and rape threats. La Nación's own test with the same video produced a different false identification — a student from Quilmes, with her personal data. Google Argentina said it could not confirm the screenshot came from its systems without the original link and had received no formal report. Broffoni is weighing legal action with her lawyer.
Contextual tracker case High reported severity Media Coverage
AI involvement supported · Causal attribution supported · 1 source · Added 15/09/2026