2 Jan 2026Event location unknownGrok
The Bureau of Investigative Journalism and The Observer reported on 29 September 2026 that police investigations into sexualised images generated by X's chatbot Grok had failed to identify anyone. A Welsh presenter and campaigner against deepfake abuse, who had criticised Grok publicly on New Year's Eve 2025, saw an anonymous X user ask '@grok' to put her in a bikini made of cling film; Grok generated the image from her profile photo and posted it. She reported it to South Wales Police on 2 January 2026, was not asked for a statement until March, and was told officers had not heard back from X; the case was closed (in May, per The Observer) with the force saying no suspect could be identified. The same account also targeted a commentator and broadcaster, who estimates about 300 Grok images and videos of her were posted during the wave, including one alongside Jeffrey Epstein reported to the Metropolitan Police, which likewise said no suspect could be identified. The presenter is now in pre-action legal correspondence with xAI (part of SpaceXAI) alleging misuse of private information and breaches of data-protection law and the Equality Act; the company told her lawyers it had not been possible in the time available to look into its communications with South Wales Police. BBC Wales had reported in January 2026 that explicit images of the presenter were created with the chatbot and shared without her consent.
Core concern Medium reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 3 sources, 2 underlying accounts · Added 30/09/2026
23 Feb 2026 to 25 Feb 2026ItalyUnidentified voice-cloning tool
On 23 February 2026 Paolo Molesini, then chairman of Fideuram (the private-banking subsidiary of Intesa Sanpaolo), received a WhatsApp message from an unknown number from someone claiming to be Intesa's chief executive Carlo Messina, announcing a confidential acquisition that had to be executed through Fideuram. The same day a caller presenting as a lawyer of A&O Shearman whom Molesini knew, whose voice ANSA, Il Fatto Quotidiano and Corriere della Sera, reporting from the Milan court papers, describe as created with artificial intelligence (today.it, which also cites the seizure decree, writes that the court papers do not yet answer whether the voice was imitated), had him sign a confidentiality agreement and sent eleven payment instructions; Fideuram's treasury head was separately contacted by someone posing as Fideuram's CEO. Between 23 and 25 February eleven transfers totalling about 95 million euros went to accounts in Portugal and at Bank of China; the bank's alarm systems and the Milan prosecutors recovered about 40-42 million from China and 13 million seized in Portugal, leaving at least 36 million (39.5 million per the court papers) missing after conversion into cryptocurrency. Molesini, who Corriere writes is not under investigation, resigned as chairman on 12 March 2026, which Fideuram announced as being for personal reasons; a 48-year-old Israeli citizen is under investigation as a member of the gang.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution supported · 8 sources, 5 underlying accounts · Added 30/09/2026
12 Mar 2025 to 15 Mar 2025AustraliaChatGPT
The NSW Reconstruction Authority says that between 12 and 15 March 2025 a former temporary staff member (earlier described as a former contractor) uploaded an Excel spreadsheet with 10 columns and more than 12,000 rows from the Northern Rivers Resilient Homes Program to ChatGPT, an AI tool the Authority had not authorised. The Authority first disclosed the breach on 6 October 2025 as affecting up to 3000 people and later confirmed through external forensic analysis that 2031 people had data uploaded, including names, contact details, addresses, dates of birth and sensitive personal information (an earlier notice also listed health information). It reports no evidence that the data was made public or accessed by a third party, and that no driver licence, Medicare, passport or Tax File Numbers were included. The Authority apologised, offered ID Support NSW assistance and committed to compensate reasonable document replacement costs. One participant told the ABC they were concerned. No misuse of the data is reported.
AI relation unknown Low reported severity Investigation Opened
AI involvement supported · Causal attribution alleged · 4 sources, 1 underlying account · Added 29/09/2026
25 Oct 2025IndiaUnidentified video tool
On 25 October 2025 the Telugu actor and former Union minister Konidela Chiranjeevi gave Hyderabad cybercrime police a written complaint that several pornographic websites were publishing obscene videos made with AI that morphed his face and likeness, and asked for a criminal and technical investigation and removal of the content, including from mirror sites. Police registered a case under Sections 67 and 67A of the IT Act, several sections of the Bharatiya Nyaya Sanhita and the Indecent Representation of Women (Prohibition) Act. In the complaint he said the videos caused severe and irreparable harm to his reputation and personal and emotional distress to him and his family. He had already obtained an ad-interim injunction from the Hyderabad City Civil Court protecting his name, image and likeness (Gulf News); V6 Velugu reports that he had gone to that court in September 2025 over the same kind of deepfake videos and that on 26 September it ordered their removal. A September 2026 NewsX recap reports that Hyderabad Police Commissioner V C Sajjanar said the cybercrime team was working to trace those responsible.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 5 sources, 1 underlying account · Added 29/09/2026
22 Sept 2026United StatesUnidentified image tool
David Douglas High School in Portland warned families in a statement reported on 28 September 2026 about social-media posts targeting its students, athletes, coaches and staff, saying some images and videos had been digitally altered, including with AI, and did not accurately represent those depicted; it reported some of the content to the Portland Police Bureau. KATU, which reviewed the account, reports 17 posts using racist, anti-immigrant and religious stereotypes against football players: one image shows a Latino player in a sombrero being detained by people labelled as ICE agents, another shows a player in a head covering with what appears to be a fake explosive vest, and a Black player is depicted beneath a caption referring to George Floyd. The head coach said students were hurt, and that one student texted him over the weekend after seeing one of the posts: 'Coach, this is terrible. What do I do?' The account references Rex Putnam High School, whose team David Douglas played on the Friday before the report; which along with its district says it has no connection to it. Who runs the account and which images were AI-generated are not reported.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 2 sources · Added 29/09/2026
Event date unknownEvent location unknownUnidentified image tool
Modern Express reported on 24 September 2026 that online posts accused a female graduate student at Qingdao University of using AI, over a relationship dispute, to generate nude images of her boyfriend's ex-girlfriend and circulate them, and said the student had been criminally detained. A staff member at the Shibei branch of the Qingdao Public Security Bureau told the paper that the victim had reported the matter, that the case met the conditions for filing and that an investigation had been opened, declining to give details. A staff member of the university's Art College said the college had received a report and that the student had graduated in June. The victim told the reporter she was cooperating with the police and awaiting the result. The AI generation, the circulation and the detention are stated only in the online posts; police confirmed only that a case was opened. All accounts derive from the single Modern Express report, read through relays.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 4 sources, 1 underlying account · Added 28/09/2026
16 Sept 2026 to 18 Sept 2026IndiaUnidentified image and video tool
A head constable at Hebbal police station in Bengaluru complained that on 16 September 2026 he accepted a Facebook friend request from an unknown account and exchanged sexually explicit messages with it over Messenger. According to his complaint, reported by the Times of India, the person behind the account downloaded his old Facebook photographs and used AI tools to make morphed obscene images and videos showing him with women, sent them to him with a QR code, demanded money in return for deleting them and threatened to send them to senior police officers and post them on social media, warning that this would damage his reputation. The harassment continued until 18 September. He gave police copies of the messages and the morphed images. Hebbal police registered a case under IT Act sections 66E and 67A and Bharatiya Nyaya Sanhita sections 308 (extortion) and 351 (criminal intimidation), took steps to stop the material being uploaded and are trying to trace the account holder. Whether he paid is not reported, and no arrest is reported.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 1 source · Added 28/09/2026
9 Sept 2026IndiaUnidentified video tool
A security guard in Bengaluru, originally from Odisha, told the Times of India that on 9 September 2026 he answered a WhatsApp video call in which a face and voice presented as Tamil Nadu Chief Minister C. Joseph Vijay introduced himself in Hindi, asked his name, work and where he lived and pressed him to accept financial help. A 'manager' then promised Rs 11 lakh, said Rs 5 lakh had been allotted to him and asked for a Rs 5,000 exchange charge, then Rs 18,000 to unlock a supposedly locked PIN; a caller posing as a CBI officer demanded more than Rs 50,000 as a fine. The fraudsters sent a fake allotment letter and a purported CBI officer's identity proof. He paid more than Rs 1.04 lakh through a digital payment app before refusing a further Rs 50,000 demand, called the 1930 cybercrime helpline and went to Byappanahalli police, who registered a case under the Information Technology Act. The Times of India says the fraudster allegedly used a deepfake AI-generated video and calls it the first such case reported in the city. No arrest is reported, and no link to the Tamil Nadu CB-CID deepfake case or its Alwar arrest has been established.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 28/09/2026
Sept 2026GermanyUnidentified image tool
The Oldenburg-Stadt police inspectorate said on 22 September 2026 that in the preceding days numerous messages had been sent through one or more student accounts on the email servers of Oldenburg schools. The messages contained, among other things, deepfakes (manipulated depictions of children and young people); on an initial assessment some of these could constitute the offence of distributing child or youth sexual abuse material, and some messages contained threats of violence and calls for recipients to harm themselves. According to dpa, students and parents reported the incidents to the police, and dpa, reporting a police spokesman, describes the images as made with artificial intelligence (the written police statement calls them deepfakes, manipulated depictions, without naming AI). Investigators are examining whether unknown persons gained unauthorised access to the accounts; first digital traces were secured and the police are working with the affected schools. RND reports that the accounts were on the IServ school platform, whose provider said it had no access to the messages and believed the incident was limited to Oldenburg. The exact number of schools (the police refer to 'the affected schools', plural), messages, depicted children and recipients, and who created the images, are not reported.
Core concern Medium reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution alleged · 4 sources, 2 underlying accounts · Added 27/09/2026
Event date unknownIndiaUnidentified image tool
Sonbhadra police say a retired official in Uttar Pradesh transferred about Rs 2.36 crore into accounts named by extortionists, including money raised through a loan, before a State Bank of India manager noticed the repeated transfers on 22 September 2026 and alerted the cyber crime police station. At a press briefing on 25 September the superintendent of police said the fraudsters had frightened the man by invoking the higher judiciary and senior government officials (a so-called digital arrest) and had used AI to create fake obscene or nude images to blackmail him with threats of defamation and harm to his family (Times of India, Amar Ujala, ETV Bharat, Newstrack). Police froze about Rs 75 lakh, registered an FIR and arrested three people, including the alleged organiser; the outlets relay one police account, and they describe the AI element differently (images of the victim, or images sent to him during a WhatsApp chat with someone posing as a woman).
Core concern High reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 4 sources, 1 underlying account · Added 27/09/2026
10 Jul 2026 to 22 Jul 2026IndiaUnidentified video tool
According to an FIR reported by Deccan Herald, a 39-year-old resident of Mahalakshmi Layout, Bengaluru, saw videos on Facebook on 10 July 2026 that appeared to show Prime Minister Narendra Modi, Finance Minister Nirmala Sitharaman, Sudha Murty and Anant Ambani promoting online investments. Believing them genuine, he clicked a link, paid Rs 22,000, and was then called from UK (+44) numbers by people claiming to represent a company called 'One Two Markets', who opened a forex account in his name. Between 10 and 22 July he transferred about Rs 7.6 lakh in several payments; when he tried to withdraw, the callers demanded more money. He went to the police and an FIR was registered on 19 September; a probe is under way. Deccan Herald calls the videos deepfakes; no technical examination of them is reported.
AI relation unknown Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 27/09/2026
Event date unknownIndiaUnidentified video tool
The father of a 17-year-old Class 12 student in Bansdih, Ballia district, Uttar Pradesh, gave the Bansdih police a written complaint that a young man from the town, a former schoolmate who had been expelled from the school and bore a grudge against the family, took screenshots of his daughter's social-media account, created a fake Instagram ID in her name with a matching photograph, used AI technology to make an obscene video from her photo and circulated it to her classmates, friends and relatives; the complaint says the youth had earlier made two fake accounts using her and her mother's photographs and threatened to kill the whole family and to spread the video further when they objected (Dainik Bhaskar, Hindustan). The father submitted screenshots of the fake account and his daughter's mark-sheet as proof of her age. The station house officer said a case had been ordered registered and the investigation begun; Jagran reports the case under the Information Technology Act. The reports give no dates for the fake accounts, the video or its circulation; September 2026 is the month of the complaint (about 21-22 September) and of the circulation and threats the family describes as continuing, so the event date is recorded as unknown. The family is described as frightened. No arrest is reported.
Core concern High reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution alleged · 4 sources · Added 26/09/2026
Jul 2026IndiaUnidentified image tool
A 25-year-old content creator from Delhi complained to the police that organisers and demonstrators at a Cockroach Janta Party (CJP) protest at Jantar Mantar had taken her personal photograph without consent, used AI face-swapping tools to morph her face onto a vulgar, compromising image alongside Prime Minister Narendra Modi, printed the image on banners waved before crowds with sexually suggestive slogans, and circulated videos of the banners on Instagram and other platforms; her later High Court petition adds that the images were uploaded to pornographic websites and that she has received rape, acid-attack and death threats. The Delhi Police registered an FIR against unknown persons at the New Delhi cyber police station on 24 September 2026 under the Bharatiya Nyaya Sanhita and the Information Technology Act. On 25 September Justice Girish Kathpalia of the Delhi High Court directed Meta Platforms to remove the objectionable content within 24 hours, ordered the Delhi Police to give the petitioner complete protection and file a status report within a week, issued notice to the four CJP functionaries named in her plea, ordered the registry to redact the impugned web links from the petition (and, per PTI, her name), and listed the matter for 14 October 2026 (PTI, Ommcom News). The police told the court the FIR had been registered the previous day and that action would be taken expeditiously; no accused had been named or arrested at that stage. The petition says the protest took place in July 2026 and that she approached the police on 23 September; the CJP had not commented at the time of the first report.
Core concern High reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 9 sources, 7 underlying accounts · Added 26/09/2026
15 Sept 2026 to 16 Sept 2026IndonesiaUnidentified image tool
On 23 September 2026 the spokesperson of the East Jakarta metropolitan police (Polres Metro Jakarta Timur) confirmed to reporters that a grade-9 student at a state junior high school in Pulogadung, East Jakarta, had edited photographs of several female schoolmates using artificial intelligence so that they appeared indecent, and that the edited images had been made into WhatsApp stickers; the police women-and-children protection unit is investigating. The case surfaced through a post on Threads which said about 200 edited photographs had been produced and sold to others; Kompas.com noted on 24 September that the sale allegation still rested only on that post, VIVA reported that police were still checking the claim that the images had been sold, and ANTARA reported on 23 September that police were still establishing the editing method, the recipients and the number of depicted students. As of 24 September the depicted students had not filed a report (detik and VIVA date the spokesperson's telephone remarks 'Kamis (22/9/2026)', a date that is internally inconsistent) and police appealed to them to do so. According to the parents' account relayed by police, on 15 and 16 September several people took the student who made the images to an empty house and then to a reservoir in Kayu Putih, punched him on the nose, ears and head, kicked his chest and stomach and threatened him with a bladed weapon; police attribute the beating to friends of the depicted students (ANTARA, detik, VIVA), while Kompas.com's 23 September report quotes the same spokesperson as saying the depicted students themselves beat him; he filed an assault report, which police are handling alongside the image case, and the school has held mediation with the students' parents. No student or school is named in the reports.
Core concern High reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution supported · 8 sources, 1 underlying account · Added 25/09/2026
Event date unknownSpainUnidentified image tool
On 14 July 2026 Spain's Interior Ministry published a Guardia Civil release stating that a 14-year-old from Logroño was under investigation as the presumed author of offences of discovery and disclosure of secrets, corruption of minors and child pornography. Investigators from the technology investigation team (EDITE) and Equipo@ found that he knew all nine victims, all minors and classmates, followed them on social media, took their photographs from the public content of their profiles without consent, and used artificial-intelligence tools to manipulate the images, digitally undress and sexualise them. He uploaded the fake pornographic material to an adult pornography website, created a profile there describing the content as girls from his school made with AI, and organised it in individual folders with each victim's personal data, which the Guardia Civil says made the girls recognisable and multiplied the emotional and social harm. Before the content could be removed it had reached about 40,000 views, amplifying the harm to the nine girls' privacy within hours. The proceedings were passed to the juvenile prosecutor under the juvenile criminal responsibility law; the release notes that parents or guardians are jointly liable for moral damages. Diario de León (Europa Press, 26 July) placed the case in a series of Spanish school cases since Almendralejo in 2023 and, unlike the release, described the minor as having been arrested.
Core concern High reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution supported · 3 sources, 1 underlying account · Added 23/09/2026
19 Jun 2026GermanyUnidentified image tool
On 'the previous Friday' (19 June 2026, read relative to the 24 June 2026 report) the leadership of the Heinz-Brandt-Schule in Berlin-Weißensee (Pankow district) learned that two of its pupils were suspected of having created and distributed AI-generated sexualised nude images of female classmates; the school wrote to parents that it was 'shocked and appalled' that classmates' photographs had been abused in this way and described the alleged acts as a massive attack on the personality rights of the affected girls and a form of sexualised violence. The two pupils alleged to be mainly responsible were suspended from lessons with immediate effect, and the school imposed measures on pupils who are said to have known about the images without reporting them. The Senate Department for Education confirmed the incidents and the ongoing investigation in the Tagesspiegel's report of 24 June 2026. The school's letter says the investigation is conducted on behalf of the public prosecutor. A Berlin police spokesman said complaints had been filed over the creation of so-called deepfakes, that the investigation had been taken over by the State Criminal Police Office unit responsible for sexual offences against minors, and that criminal liability for possessing, obtaining, creating or distributing youth pornography under section 184c of the Criminal Code was under consideration; the police gave no further details, citing victim protection. At least three cases are alleged. The school said it would revise its prevention and sex-education concepts and asked parents to talk to their children about handling other people's photographs and AI applications. Nobody is named; the number of girls depicted is not reported.
Core concern Medium reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution supported · 1 source · Added 22/09/2026
11 Aug 2026BrazilUnidentified voice-cloning tool
On Monday 10 August 2026 a digital influencer from Picos, in the centre-south of Piauí, began negotiating a car advertised online for sale in Fortaleza (Ceará), where an uncle of his lives, and asked the sellers to take the car to the uncle so he could inspect it. On Tuesday 11 August a contact using a different number but the uncle's photo sent him audio messages in a voice identical to his uncle's, generated with artificial intelligence, saying the car was in good condition and telling him to make the bank transfer. Believing he was speaking to his uncle, he transferred the money; when he then called the uncle's real number he learned he had been defrauded. The loss exceeded R$56,000, money he says he had saved for years. He registered a police report on 11 August; the Piauí property-crimes unit (Depatri) is investigating and he is seeking a refund from the banks. The account is the victim's own, reported by G1 Piauí on 13 August 2026 from his social-media posts and an interview; the police unit did not respond to G1 before publication.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 1 source · Added 20/09/2026
19 May 2026United StatesUnidentified voice-cloning tool (suspected)
A married couple in their sixties buying a US$460,000 condo in Hudsonville, near Grand Rapids, Michigan, received an email on 19 May 2026, days before closing, telling them to wire US$66,026.92 for the down payment and closing costs within 24 hours. The email listed a phone number differing from their loan officer's by two digits, and the husband then received a call confirming the instructions in a voice that sounded just like the loan officer. The couple borrowed from family and other sources and wired the money. The day before closing their real loan officer sent the actual statement; the closing was cancelled hours before signing and the money was gone. The husband now believes the call came from a spoofed number using AI-assisted voice cloning; Tyler Adams of CertifID, which is working with the couple and federal officials, said someone's email in the transaction was probably compromised and that the scammers likely cloned the loan officer's voice from social-media clips. The sender's address had two extra letters ('UnitedsMortgages' instead of 'UnitedMortgage'). Neither the lender nor the loan officer is accused of complicity. The couple later completed the purchase in early June from their mutual fund, reported the loss to the FBI's Internet Crime Complaint Center, and describe lasting apprehension and have discussed delaying retirement. CNN reported the case on 15 September 2026; the account the money went to has since closed.
Core concern Medium reported severity Investigation Opened
AI involvement suspected · Causal attribution alleged · 2 sources, 1 underlying account · Added 20/09/2026
1 Aug 2026 to 16 Sept 2026KazakhstanUnidentified video tool
On 16 September 2026 the Prosecutor General's Office of Kazakhstan warned of an investment-fraud scheme in which criminals advertise non-existent projects on TikTok, Instagram, YouTube and other platforms using deepfake videos of well-known people and fake 'AI' investment platforms promising very high passive income: 'Kaspi AI' with Mikhail Lomtadze, 'Quantum AI' with Elon Musk, 'TON' with Pavel Durov, and 'people's investments' in KazMunayGas or Gazprom fronted by news presenters from Khabar 24, KTK and Channel One. The office said 119 such cases had been registered across the country in the previous one and a half months. Its example: in September 2026 a woman from Taldykorgan saw an Instagram advertisement offering high returns from share trading, left her details through the link, was contacted by the fraudsters and, following their instructions, transferred more than 7 million tenge to third-party accounts; the money and supposed dividends appeared in a fake wallet that she could not withdraw from. A pre-trial investigation is under way. The office urged people not to trust guaranteed-return offers or transfer money to strangers.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution supported · 5 sources, 1 underlying account · Added 20/09/2026
1 Jan 2026IndonesiaUnidentified image and video tool
A female student at a state university in Solo (Surakarta), Central Java, learned on 1 January 2026 from friends that her face had been composited onto pornographic images and a video, which her lawyer said were found on Instagram and Telegram. Her family reported the case to the Central Java regional police cyber directorate on 28 January 2026. Police issued a formal police report on 31 July, arrested her ex-boyfriend, a university student in Semarang, at his boarding house in Gunungpati on 4 August 2026, and detained him. The police spokesman said the suspect used AI to place the complainant's face on another woman's naked body so that she appeared in pornographic content, uploaded it to his X account, did not sell it, and acted out of resentment after an on-and-off relationship ended. He faces charges under Articles 51 and 35 of the Electronic Information and Transactions Law and an article printed by two outlets as 'Law No. 1 of 2026', with a maximum of 12 years' imprisonment. Her lawyer said she could not sleep, withdrew, felt shame and at one point lost hope, that his team had found seven women in total allegedly targeted of whom six had not reported, and that the suspect's parents asked for an out-of-court settlement; police said only one complainant was confirmed.
Core concern High reported severity Investigation Opened
AI involvement reported · Causal attribution supported · 6 sources, 2 underlying accounts · Added 20/09/2026