12 Mar 2025 to 15 Mar 2025AustraliaChatGPT
The NSW Reconstruction Authority says that between 12 and 15 March 2025 a former temporary staff member (earlier described as a former contractor) uploaded an Excel spreadsheet with 10 columns and more than 12,000 rows from the Northern Rivers Resilient Homes Program to ChatGPT, an AI tool the Authority had not authorised. The Authority first disclosed the breach on 6 October 2025 as affecting up to 3000 people and later confirmed through external forensic analysis that 2031 people had data uploaded, including names, contact details, addresses, dates of birth and sensitive personal information (an earlier notice also listed health information). It reports no evidence that the data was made public or accessed by a third party, and that no driver licence, Medicare, passport or Tax File Numbers were included. The Authority apologised, offered ID Support NSW assistance and committed to compensate reasonable document replacement costs. One participant told the ABC they were concerned. No misuse of the data is reported.
AI relation unknown Low reported severity Investigation Opened
AI involvement supported · Causal attribution alleged · 4 sources, 1 underlying account · Added 29/09/2026
25 Oct 2025IndiaUnidentified video tool
On 25 October 2025 the Telugu actor and former Union minister Konidela Chiranjeevi gave Hyderabad cybercrime police a written complaint that several pornographic websites were publishing obscene videos made with AI that morphed his face and likeness, and asked for a criminal and technical investigation and removal of the content, including from mirror sites. Police registered a case under Sections 67 and 67A of the IT Act, several sections of the Bharatiya Nyaya Sanhita and the Indecent Representation of Women (Prohibition) Act. In the complaint he said the videos caused severe and irreparable harm to his reputation and personal and emotional distress to him and his family. He had already obtained an ad-interim injunction from the Hyderabad City Civil Court protecting his name, image and likeness (Gulf News); V6 Velugu reports that he had gone to that court in September 2025 over the same kind of deepfake videos and that on 26 September it ordered their removal. A September 2026 NewsX recap reports that Hyderabad Police Commissioner V C Sajjanar said the cybercrime team was working to trace those responsible.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 5 sources, 1 underlying account · Added 29/09/2026
Dec 2025MalaysiaUnidentified image tool
In early December 2025 a Chinese secondary school in Muar, Johor, expelled three male pupils in Forms 2, 3 and 4 after finding they had used AI software to composite several female classmates' faces onto indecent images, some of which had spread online. The school said it was told of the images on Monday 1 December, investigated immediately, met the parents of all pupils involved, expelled the three under its rules with a stated zero-tolerance policy, and urged victims to lodge police reports and parents to delete any such images. The boys' parents accepted the decision. At least two girls lodged police reports; the Muar district police chief confirmed reports had been received, that the boys had been summoned to assist the investigation, and that an investigation was under way. No charge or later outcome has been reported.
Core concern High reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution supported · 3 sources, 1 underlying account · Added 20/09/2026
2025ChinaUnidentified AI video-editing tool
police, as presented by the Kankan News programme 案件聚焦 (Case Focus), reported in September 2026 that a Shanghai property-engineering contractor had transferred 170,000 yuan in total during a five-month online relationship with a woman he had met on a social platform in 2021. She presented herself as born in 1992, a doctor at a well-known top-tier hospital with hospital property-engineering projects to award, and ran an account with more than 10,000 followers and close to 7,000 short videos of daily life. She refused to meet or take a video call, saying her mother opposed the relationship and demanded a 300,000 yuan bride price and a Shanghai flat; the man reported to a police station when the promised projects never materialised and his savings ran down. Police found she was born in 1961, aged 65, had no medical qualification and had worked as a hospital cleaner; the receiving bank account was registered to another man; the videos were all made with AI skin-smoothing and scene compositing, some carrying a small 'this work contains AI-generated content' label he had never noticed; and she used multiple accounts to play both herself and her long-dead mother. The money had gone on cosmetic treatments and clothing; she had a 2009 fraud conviction with a sentence of four and a half years and is now under criminal coercive measures for suspected fraud. Police also said she kept ambiguous relationships with more than ten people; no other losses are reported.
Core concern Medium reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 4 sources, 1 underlying account · Added 20/09/2026
Oct 2025United StatesUnidentified video tool
From around October 2025, criminals used AI to clone the image, voice, name, signature and firm logo of Ángel Leal, a long-established immigration attorney in Doral, Florida. They created fake videos, look-alike websites, forged contracts and even fabricated Zoom 'immigration hearings' to persuade immigrants to pay for legal services Leal never provided. Immigrants were defrauded of money, and some believed their cases were progressing when they were not; Leal received one to two defrauded callers a day, changed his phone number, hired an anti-piracy firm that removed thousands of fake profiles and videos, and reported the fraud to local police and federal authorities.
Core concern Medium reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 4 sources · Added 17/09/2026
27 Feb 2025 to 28 Feb 2025United StatesUnidentified image tool
Elijah Heacock, a 16-year-old Caverna High School student in Barren County, Kentucky, died by suicide on 28 February 2025. Investigators searching his phone found AI-generated images of him, some sexually explicit, that an anonymous extortionist had sent with a demand for $3,000 and a threat to share them with his family and friends; his parents say he sent a small partial payment and was told it was 'not enough'. The Barren County Sheriff's Office escalated the case to the FBI, which was still investigating in the inspected reports; no arrest has been reported. His parents have campaigned publicly, Kentucky made sextortion a felony in March 2025, and the family supported the federal Take It Down Act.
Core concern Critical reported severity Involving minors Investigation Opened
AI involvement supported · Causal attribution supported · 4 sources · Added 09/03/2026
Feb 2025Hong Kong SAR ChinaUnidentified image tool
In February 2025 a University of Hong Kong (HKU) law student was found, by friends who saw the files on his laptop, to have used free online AI software to make about 700 indecent and deepfake images of some 20 to 30 women, including university and former schoolmates and secondary-school teachers, using photos taken from their social media. Victims went public in July 2025, and HKU's initial response, a warning letter and a demand that he apologise, drew wide criticism. Hong Kong's Privacy Commissioner opened a criminal investigation on 15 July 2025 but announced on 17 December 2025 that it was ending the probe for insufficient evidence, as no victim was willing to provide further information. Hong Kong law criminalised distribution, not creation, of such images.
Core concern High reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 5 sources · Added 29/01/2026
Mar 2025Event location unknownChatGPT
ChatGPT falsely accused Norwegian citizen Arve Hjalmar Holmen of murdering two of his sons, attempting to murder his third son, and being sentenced to 21 years prison. Mixed real personal details with horrific fabrications. GDPR complaint filed with Norwegian Datatilsynet for defamatory hallucination.
AI relation under review Medium reported severity Regulatory Action
Legacy assessment: verified · Causal attribution alleged · Added 13/01/2026
25 Dec 2025 to 14 Jan 2026Event location unknownGrok
From late December 2025, xAI's Grok image editing on X let users generate sexualized images of real people at industrial scale, including images of named women and apparent minors. Analyses attributed to Genevieve Oh (7,751 sexualized images in one hour, via NBC), the New York Times (4.4 million images in nine days, at least 41% sexualized images of women, via the NC AG), the AP (2% of a 20,000-image sample appearing to be minors, via Fortune) and CCDH (about 3 million sexualized images over 11 days including roughly 23,000 of minors, via Engadget) documented the scale. Named women — Ashley St. Clair, Samantha Smith and Dr Daisy Dixon — described being undressed by Grok and revictimized when they objected. The wave triggered formal actions by Ofcom, the UK ICO, the EU (DSA), Ireland's DPC, 35 US state attorneys general, the California AG, Baltimore (consumer-protection suit), an Amsterdam court order, country blocks in Indonesia, Malaysia and the Philippines, and a Paris police raid; xAI restricted generation to paying subscribers on 9 January and narrowed the feature on 14 January 2026.
Core concern Critical reported severity Involving minors Regulatory Action
AI involvement supported · Causal attribution established · 13 sources, 10 underlying accounts · Added 11/01/2026