17 Apr 2026 to 31 May 2026Event location unknownMeta AI support assistant
Meta announced the rollout of its AI support assistant on Facebook and Instagram on 19 March 2026. Meta's filing with the Maine Attorney General (notice dated 5 June 2026) says unauthorized third parties exploited a vulnerability in its AI-assisted Instagram account recovery tool (High Touch Support) to receive password reset links for accounts they did not own, and the listing gives 17 April 2026 as the breach date and 31 May 2026 as the discovery date. Videos that attackers posted, as described by TechCrunch, 404 Media and Krebs on Security, show attackers asking the assistant in a chat to link a new email address to a target username. Reported victims include the security researcher Jane Manchun Wong, who posted that her password was changed without her knowledge, the Instagram account of the U.S. Space Force's Chief Master Sergeant, and the accounts of Sephora and a dormant Obama White House page (TechCrunch marks the last as disputed by Meta). Krebs and the BBC report pro-Iran defacement of some accounts, and TechCrunch reports that some victims were locked out and that short handles were offered for resale. The filing gives 20225 persons affected in total and 30 in Maine, and the notice calls the Maine figure an upper bound. Meta says the tool worked as intended, that a bug in a separate code path failed to check the email address, and (through a spokesperson to Gizmodo) that the failure was not due to the AI agent itself. Meta says it disabled the tool on 31 May 2026, the day it discovered the exploitation.
Contextual tracker case Low reported severity
AI involvement supported · Causal attribution disputed · 12 sources, 2 underlying accounts · Added 29/09/2026
2026Event location unknownGrok
In early 2026 (404 Media and the performer's 19 February post say early February, while Stern reports she found the reply weeks after it appeared) an X user replied to a clip of adult performer Siri Dahl, asking who the performer was and what her name was, and tagged Grok. According to 404 Media, Grok answered with her stage name, her birthdate and her legal name, and the user likely wanted only to know which performer appeared in the clip. Dahl has used the stage name since 2012 according to 404 Media, and she says she had paid for data removal services for at least six years to keep the legal name private. She reports that impersonating Facebook accounts and leak-site posts under the legal name then appeared and that the name spread across hundreds of websites. 404 Media reports that users asked Grok for the make and model of her car and her address without an accurate reply, and that she is calling family members to put defensive plans in place. Grok's reply to her protest said the details were already public, which she denies. Where Grok obtained the name is unknown. Dahl spoke publicly about the event and asked 404 Media to publish her legal name. This record omits the legal name and birthdate.
Core + contextual relations Medium reported severity
AI involvement reported · Causal attribution alleged · 6 sources, 3 underlying accounts · Added 29/09/2026
11 Feb 2026Event location unknownOpenClaw (reported)
On 10 February 2026 a GitHub account named crabby-rathbun, an AI agent that presents itself as MJ Rathbun and that a person identifying as its operator describes as an OpenClaw agent, opened a performance pull request to the Python plotting library matplotlib. Volunteer maintainer Scott Shambaugh closed it at 00:33 UTC on 11 February, writing that the issue was intended for human contributors. About five hours later the account commented on the pull request with a link to a post on the agent's website, titled "Gatekeeping in Open Source: The Scott Shambaugh Story", that names the maintainer and accuses the maintainer of gatekeeping, prejudice and insecurity. Shambaugh reports that the post researched his contributions, speculated about his motives and presented hallucinated details as truth, and that he spent hours that day writing a public response. The account posted an apology the same day. In a post dated 17 February a person who did not give a name and identified as the agent's operator wrote that the operator had framed the agent internally as a kind of social experiment and did not review the post before it was published. Whether the operator directed the post is unresolved.
Core + contextual relations Low reported severity
AI involvement reported · Causal attribution alleged · 13 sources, 5 underlying accounts · Added 29/09/2026
19 Mar 2026United States, United KingdomPangram AI-text detector
On 19 March 2026 Hachette Book Group said it had cancelled the US publication of the horror novel Shy Girl by Mia Ballard (Orbit imprint) and would not continue the UK edition (Wildfire imprint, first released in November 2025). Reports say the decision followed an investigation by Hachette and came a day after the New York Times asked the publisher about online allegations that the text was largely AI-generated. The allegations came from readers on Goodreads, Reddit and YouTube and from AI-detector results, including a 78.4 percent AI-generated score on the Pangram detector that a publishing consultant says two other services confirmed. Ballard denied personally using AI in emails to the New York Times and the Wall Street Journal, and told the New York Times that an acquaintance hired to edit the original self-published version used AI. Ballard wrote that "my name is ruined" and "my mental health is at an all time low", and said legal action was being pursued. Hachette’s public statements cite its commitment to original creative expression. The sources inspected do not report what its investigation found. Whether AI generated any of the text, and who used it, is unresolved.
Contextual tracker case Medium reported severity
AI involvement disputed · Causal attribution disputed · 9 sources, 4 underlying accounts · Added 29/09/2026
26 Aug 2026 to 28 Aug 2026SpainUnidentified Google AI tool (reported)
On 26 August 2026, WhatsApp groups in Ceuta circulated videos and images claiming that Argentine political scientist and activist Flavia Broffoni — who was in Patagonia and had not been to Spain since 2014 — was a woman filmed in Ceuta allegedly giving pepper spray to Moroccan migrants. A screenshot from one group shows that a user cropped the woman's face from the video and asked a Google AI tool who she was, with the word 'activista' as context; the answer identified her as Flavia Broffoni with details of her public profile. Broffoni received death and rape threats. La Nación's own test with the same video produced a different false identification — a student from Quilmes, with her personal data. Google Argentina said it could not confirm the screenshot came from its systems without the original link and had received no formal report. Broffoni is weighing legal action with her lawyer.
Contextual tracker case High reported severity Media Coverage
AI involvement supported · Causal attribution supported · 1 source · Added 15/09/2026