2 Jan 2026Event location unknownGrok
The Bureau of Investigative Journalism and The Observer reported on 29 September 2026 that police investigations into sexualised images generated by X's chatbot Grok had failed to identify anyone. A Welsh presenter and campaigner against deepfake abuse, who had criticised Grok publicly on New Year's Eve 2025, saw an anonymous X user ask '@grok' to put her in a bikini made of cling film; Grok generated the image from her profile photo and posted it. She reported it to South Wales Police on 2 January 2026, was not asked for a statement until March, and was told officers had not heard back from X; the case was closed (in May, per The Observer) with the force saying no suspect could be identified. The same account also targeted a commentator and broadcaster, who estimates about 300 Grok images and videos of her were posted during the wave, including one alongside Jeffrey Epstein reported to the Metropolitan Police, which likewise said no suspect could be identified. The presenter is now in pre-action legal correspondence with xAI (part of SpaceXAI) alleging misuse of private information and breaches of data-protection law and the Equality Act; the company told her lawyers it had not been possible in the time available to look into its communications with South Wales Police. BBC Wales had reported in January 2026 that explicit images of the presenter were created with the chatbot and shared without her consent.
Core concern Medium reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 3 sources, 2 underlying accounts · Added 30/09/2026
23 Feb 2026 to 25 Feb 2026ItalyUnidentified voice-cloning tool
On 23 February 2026 Paolo Molesini, then chairman of Fideuram (the private-banking subsidiary of Intesa Sanpaolo), received a WhatsApp message from an unknown number from someone claiming to be Intesa's chief executive Carlo Messina, announcing a confidential acquisition that had to be executed through Fideuram. The same day a caller presenting as a lawyer of A&O Shearman whom Molesini knew, whose voice ANSA, Il Fatto Quotidiano and Corriere della Sera, reporting from the Milan court papers, describe as created with artificial intelligence (today.it, which also cites the seizure decree, writes that the court papers do not yet answer whether the voice was imitated), had him sign a confidentiality agreement and sent eleven payment instructions; Fideuram's treasury head was separately contacted by someone posing as Fideuram's CEO. Between 23 and 25 February eleven transfers totalling about 95 million euros went to accounts in Portugal and at Bank of China; the bank's alarm systems and the Milan prosecutors recovered about 40-42 million from China and 13 million seized in Portugal, leaving at least 36 million (39.5 million per the court papers) missing after conversion into cryptocurrency. Molesini, who Corriere writes is not under investigation, resigned as chairman on 12 March 2026, which Fideuram announced as being for personal reasons; a 48-year-old Israeli citizen is under investigation as a member of the gang.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution supported · 8 sources, 5 underlying accounts · Added 30/09/2026
22 Sept 2026United StatesUnidentified image tool
David Douglas High School in Portland warned families in a statement reported on 28 September 2026 about social-media posts targeting its students, athletes, coaches and staff, saying some images and videos had been digitally altered, including with AI, and did not accurately represent those depicted; it reported some of the content to the Portland Police Bureau. KATU, which reviewed the account, reports 17 posts using racist, anti-immigrant and religious stereotypes against football players: one image shows a Latino player in a sombrero being detained by people labelled as ICE agents, another shows a player in a head covering with what appears to be a fake explosive vest, and a Black player is depicted beneath a caption referring to George Floyd. The head coach said students were hurt, and that one student texted him over the weekend after seeing one of the posts: 'Coach, this is terrible. What do I do?' The account references Rex Putnam High School, whose team David Douglas played on the Friday before the report; which along with its district says it has no connection to it. Who runs the account and which images were AI-generated are not reported.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 2 sources · Added 29/09/2026
16 Sept 2026 to 18 Sept 2026IndiaUnidentified image and video tool
A head constable at Hebbal police station in Bengaluru complained that on 16 September 2026 he accepted a Facebook friend request from an unknown account and exchanged sexually explicit messages with it over Messenger. According to his complaint, reported by the Times of India, the person behind the account downloaded his old Facebook photographs and used AI tools to make morphed obscene images and videos showing him with women, sent them to him with a QR code, demanded money in return for deleting them and threatened to send them to senior police officers and post them on social media, warning that this would damage his reputation. The harassment continued until 18 September. He gave police copies of the messages and the morphed images. Hebbal police registered a case under IT Act sections 66E and 67A and Bharatiya Nyaya Sanhita sections 308 (extortion) and 351 (criminal intimidation), took steps to stop the material being uploaded and are trying to trace the account holder. Whether he paid is not reported, and no arrest is reported.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 1 source · Added 28/09/2026
9 Sept 2026IndiaUnidentified video tool
A security guard in Bengaluru, originally from Odisha, told the Times of India that on 9 September 2026 he answered a WhatsApp video call in which a face and voice presented as Tamil Nadu Chief Minister C. Joseph Vijay introduced himself in Hindi, asked his name, work and where he lived and pressed him to accept financial help. A 'manager' then promised Rs 11 lakh, said Rs 5 lakh had been allotted to him and asked for a Rs 5,000 exchange charge, then Rs 18,000 to unlock a supposedly locked PIN; a caller posing as a CBI officer demanded more than Rs 50,000 as a fine. The fraudsters sent a fake allotment letter and a purported CBI officer's identity proof. He paid more than Rs 1.04 lakh through a digital payment app before refusing a further Rs 50,000 demand, called the 1930 cybercrime helpline and went to Byappanahalli police, who registered a case under the Information Technology Act. The Times of India says the fraudster allegedly used a deepfake AI-generated video and calls it the first such case reported in the city. No arrest is reported, and no link to the Tamil Nadu CB-CID deepfake case or its Alwar arrest has been established.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 28/09/2026
Sept 2026GermanyUnidentified image tool
The Oldenburg-Stadt police inspectorate said on 22 September 2026 that in the preceding days numerous messages had been sent through one or more student accounts on the email servers of Oldenburg schools. The messages contained, among other things, deepfakes (manipulated depictions of children and young people); on an initial assessment some of these could constitute the offence of distributing child or youth sexual abuse material, and some messages contained threats of violence and calls for recipients to harm themselves. According to dpa, students and parents reported the incidents to the police, and dpa, reporting a police spokesman, describes the images as made with artificial intelligence (the written police statement calls them deepfakes, manipulated depictions, without naming AI). Investigators are examining whether unknown persons gained unauthorised access to the accounts; first digital traces were secured and the police are working with the affected schools. RND reports that the accounts were on the IServ school platform, whose provider said it had no access to the messages and believed the incident was limited to Oldenburg. The exact number of schools (the police refer to 'the affected schools', plural), messages, depicted children and recipients, and who created the images, are not reported.
Core concern Medium reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution alleged · 4 sources, 2 underlying accounts · Added 27/09/2026
10 Jul 2026 to 22 Jul 2026IndiaUnidentified video tool
According to an FIR reported by Deccan Herald, a 39-year-old resident of Mahalakshmi Layout, Bengaluru, saw videos on Facebook on 10 July 2026 that appeared to show Prime Minister Narendra Modi, Finance Minister Nirmala Sitharaman, Sudha Murty and Anant Ambani promoting online investments. Believing them genuine, he clicked a link, paid Rs 22,000, and was then called from UK (+44) numbers by people claiming to represent a company called 'One Two Markets', who opened a forex account in his name. Between 10 and 22 July he transferred about Rs 7.6 lakh in several payments; when he tried to withdraw, the callers demanded more money. He went to the police and an FIR was registered on 19 September; a probe is under way. Deccan Herald calls the videos deepfakes; no technical examination of them is reported.
AI relation unknown Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 27/09/2026
Jul 2026IndiaUnidentified image tool
A 25-year-old content creator from Delhi complained to the police that organisers and demonstrators at a Cockroach Janta Party (CJP) protest at Jantar Mantar had taken her personal photograph without consent, used AI face-swapping tools to morph her face onto a vulgar, compromising image alongside Prime Minister Narendra Modi, printed the image on banners waved before crowds with sexually suggestive slogans, and circulated videos of the banners on Instagram and other platforms; her later High Court petition adds that the images were uploaded to pornographic websites and that she has received rape, acid-attack and death threats. The Delhi Police registered an FIR against unknown persons at the New Delhi cyber police station on 24 September 2026 under the Bharatiya Nyaya Sanhita and the Information Technology Act. On 25 September Justice Girish Kathpalia of the Delhi High Court directed Meta Platforms to remove the objectionable content within 24 hours, ordered the Delhi Police to give the petitioner complete protection and file a status report within a week, issued notice to the four CJP functionaries named in her plea, ordered the registry to redact the impugned web links from the petition (and, per PTI, her name), and listed the matter for 14 October 2026 (PTI, Ommcom News). The police told the court the FIR had been registered the previous day and that action would be taken expeditiously; no accused had been named or arrested at that stage. The petition says the protest took place in July 2026 and that she approached the police on 23 September; the CJP had not commented at the time of the first report.
Core concern High reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 9 sources, 7 underlying accounts · Added 26/09/2026
15 Sept 2026 to 16 Sept 2026IndonesiaUnidentified image tool
On 23 September 2026 the spokesperson of the East Jakarta metropolitan police (Polres Metro Jakarta Timur) confirmed to reporters that a grade-9 student at a state junior high school in Pulogadung, East Jakarta, had edited photographs of several female schoolmates using artificial intelligence so that they appeared indecent, and that the edited images had been made into WhatsApp stickers; the police women-and-children protection unit is investigating. The case surfaced through a post on Threads which said about 200 edited photographs had been produced and sold to others; Kompas.com noted on 24 September that the sale allegation still rested only on that post, VIVA reported that police were still checking the claim that the images had been sold, and ANTARA reported on 23 September that police were still establishing the editing method, the recipients and the number of depicted students. As of 24 September the depicted students had not filed a report (detik and VIVA date the spokesperson's telephone remarks 'Kamis (22/9/2026)', a date that is internally inconsistent) and police appealed to them to do so. According to the parents' account relayed by police, on 15 and 16 September several people took the student who made the images to an empty house and then to a reservoir in Kayu Putih, punched him on the nose, ears and head, kicked his chest and stomach and threatened him with a bladed weapon; police attribute the beating to friends of the depicted students (ANTARA, detik, VIVA), while Kompas.com's 23 September report quotes the same spokesperson as saying the depicted students themselves beat him; he filed an assault report, which police are handling alongside the image case, and the school has held mediation with the students' parents. No student or school is named in the reports.
Core concern High reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution supported · 8 sources, 1 underlying account · Added 25/09/2026
19 Jun 2026GermanyUnidentified image tool
On 'the previous Friday' (19 June 2026, read relative to the 24 June 2026 report) the leadership of the Heinz-Brandt-Schule in Berlin-Weißensee (Pankow district) learned that two of its pupils were suspected of having created and distributed AI-generated sexualised nude images of female classmates; the school wrote to parents that it was 'shocked and appalled' that classmates' photographs had been abused in this way and described the alleged acts as a massive attack on the personality rights of the affected girls and a form of sexualised violence. The two pupils alleged to be mainly responsible were suspended from lessons with immediate effect, and the school imposed measures on pupils who are said to have known about the images without reporting them. The Senate Department for Education confirmed the incidents and the ongoing investigation in the Tagesspiegel's report of 24 June 2026. The school's letter says the investigation is conducted on behalf of the public prosecutor. A Berlin police spokesman said complaints had been filed over the creation of so-called deepfakes, that the investigation had been taken over by the State Criminal Police Office unit responsible for sexual offences against minors, and that criminal liability for possessing, obtaining, creating or distributing youth pornography under section 184c of the Criminal Code was under consideration; the police gave no further details, citing victim protection. At least three cases are alleged. The school said it would revise its prevention and sex-education concepts and asked parents to talk to their children about handling other people's photographs and AI applications. Nobody is named; the number of girls depicted is not reported.
Core concern Medium reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution supported · 1 source · Added 22/09/2026
11 Aug 2026BrazilUnidentified voice-cloning tool
On Monday 10 August 2026 a digital influencer from Picos, in the centre-south of Piauí, began negotiating a car advertised online for sale in Fortaleza (Ceará), where an uncle of his lives, and asked the sellers to take the car to the uncle so he could inspect it. On Tuesday 11 August a contact using a different number but the uncle's photo sent him audio messages in a voice identical to his uncle's, generated with artificial intelligence, saying the car was in good condition and telling him to make the bank transfer. Believing he was speaking to his uncle, he transferred the money; when he then called the uncle's real number he learned he had been defrauded. The loss exceeded R$56,000, money he says he had saved for years. He registered a police report on 11 August; the Piauí property-crimes unit (Depatri) is investigating and he is seeking a refund from the banks. The account is the victim's own, reported by G1 Piauí on 13 August 2026 from his social-media posts and an interview; the police unit did not respond to G1 before publication.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 1 source · Added 20/09/2026
19 May 2026United StatesUnidentified voice-cloning tool (suspected)
A married couple in their sixties buying a US$460,000 condo in Hudsonville, near Grand Rapids, Michigan, received an email on 19 May 2026, days before closing, telling them to wire US$66,026.92 for the down payment and closing costs within 24 hours. The email listed a phone number differing from their loan officer's by two digits, and the husband then received a call confirming the instructions in a voice that sounded just like the loan officer. The couple borrowed from family and other sources and wired the money. The day before closing their real loan officer sent the actual statement; the closing was cancelled hours before signing and the money was gone. The husband now believes the call came from a spoofed number using AI-assisted voice cloning; Tyler Adams of CertifID, which is working with the couple and federal officials, said someone's email in the transaction was probably compromised and that the scammers likely cloned the loan officer's voice from social-media clips. The sender's address had two extra letters ('UnitedsMortgages' instead of 'UnitedMortgage'). Neither the lender nor the loan officer is accused of complicity. The couple later completed the purchase in early June from their mutual fund, reported the loss to the FBI's Internet Crime Complaint Center, and describe lasting apprehension and have discussed delaying retirement. CNN reported the case on 15 September 2026; the account the money went to has since closed.
Core concern Medium reported severity Investigation Opened
AI involvement suspected · Causal attribution alleged · 2 sources, 1 underlying account · Added 20/09/2026
1 Aug 2026 to 16 Sept 2026KazakhstanUnidentified video tool
On 16 September 2026 the Prosecutor General's Office of Kazakhstan warned of an investment-fraud scheme in which criminals advertise non-existent projects on TikTok, Instagram, YouTube and other platforms using deepfake videos of well-known people and fake 'AI' investment platforms promising very high passive income: 'Kaspi AI' with Mikhail Lomtadze, 'Quantum AI' with Elon Musk, 'TON' with Pavel Durov, and 'people's investments' in KazMunayGas or Gazprom fronted by news presenters from Khabar 24, KTK and Channel One. The office said 119 such cases had been registered across the country in the previous one and a half months. Its example: in September 2026 a woman from Taldykorgan saw an Instagram advertisement offering high returns from share trading, left her details through the link, was contacted by the fraudsters and, following their instructions, transferred more than 7 million tenge to third-party accounts; the money and supposed dividends appeared in a fake wallet that she could not withdraw from. A pre-trial investigation is under way. The office urged people not to trust guaranteed-return offers or transfer money to strangers.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution supported · 5 sources, 1 underlying account · Added 20/09/2026
1 Jan 2026IndonesiaUnidentified image and video tool
A female student at a state university in Solo (Surakarta), Central Java, learned on 1 January 2026 from friends that her face had been composited onto pornographic images and a video, which her lawyer said were found on Instagram and Telegram. Her family reported the case to the Central Java regional police cyber directorate on 28 January 2026. Police issued a formal police report on 31 July, arrested her ex-boyfriend, a university student in Semarang, at his boarding house in Gunungpati on 4 August 2026, and detained him. The police spokesman said the suspect used AI to place the complainant's face on another woman's naked body so that she appeared in pornographic content, uploaded it to his X account, did not sell it, and acted out of resentment after an on-and-off relationship ended. He faces charges under Articles 51 and 35 of the Electronic Information and Transactions Law and an article printed by two outlets as 'Law No. 1 of 2026', with a maximum of 12 years' imprisonment. Her lawyer said she could not sleep, withdrew, felt shame and at one point lost hope, that his team had found seven women in total allegedly targeted of whom six had not reported, and that the suspect's parents asked for an out-of-court settlement; police said only one complainant was confirmed.
Core concern High reported severity Investigation Opened
AI involvement reported · Causal attribution supported · 6 sources, 2 underlying accounts · Added 20/09/2026
May 2026SingaporeUnidentified video tool
In May 2026 the Singapore Police Force (SPF) reported that a man had lost at least S$4.9 million (about US$3.8 million) to a government-official impersonation scam. He received a WhatsApp message carrying the profile photo of Secretary to the Cabinet Wong Hong Kuan and an email from a proton.me address in that name, requesting urgent funding assistance for 'the situation in the Strait of Hormuz', with a fake 'letter of guarantee' bearing the Prime Minister's signature promising reimbursement within 15 business days; he signed a non-disclosure agreement and supplied a copy of his identity card. He was then invited to a Zoom video conference in which Prime Minister Lawrence Wong, President Tharman Shanmugaratnam, Minister Indranee Rajah, Monetary Authority of Singapore representatives and foreign officials appeared; all were fabricated with deepfake AI, and the closing 'remarks' by the fake Prime Minister acknowledged the victim's attendance. Contacted afterwards on WhatsApp by a scammer posing as a lawyer, he transferred the money in a series of transactions to a corporate bank account, and realised the fraud only when he contacted the real cabinet secretary. On 16 May the police released footage of the fake conference, noting lips out of sync with speech, audio broadcast from a single account and a distorted background.
Core concern High reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 3 sources, 1 underlying account · Added 18/09/2026
14 Sept 2026United StatesUnidentified image and video tool
On 14 September 2026 Manhattan District Attorney Alvin Bragg announced the seizure of 12 domain names used to disseminate, publish and sell non-consensual AI-generated sexual 'deepfake' videos. His office said individuals under investigation had used AI image- and video-creation tools to turn photos and videos of approximately 1,200 real people, overwhelmingly women, into hyper-realistic sexual imagery without consent. The victims included actors, politicians, athletes, musicians, activists and social-media influencers. WIRED and outside researchers reported that many videos reposted content from the defunct MrDeepFakes platform and that dozens of politicians appeared on the sites; investigations into who ran them are ongoing.
Core concern High reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 2 sources · Added 17/09/2026
Mar 2026IndiaUnidentified image and video tool
Indore police registered an FIR at Banganga police station on a first-year college student's complaint reported on 12 and 13 May 2026. She said she had met the accused, a young man from the Indore area, at her sister's wedding in 2024, where he took some photographs of her; he later pressed her to marry him and, when she refused, threatened to edit her photographs with AI into objectionable (Navbharat Times, Amar Ujala) or obscene (Patrika) images and post them online. Navbharat Times reports that he edited the pictures with AI, blackmailed her with them and, after her family arranged her engagement elsewhere, reached her fiancé and showed him the edited pictures, after which the families quarrelled and the engagement was broken; Patrika says he went to the fiancé's home and intimidated him into breaking the match; Amar Ujala says he also threatened to kill her and her family and sent edited pictures when her family tried to reason with him, and that when her engagement took place about two months earlier he went to her house and made false allegations about her character in front of the prospective fiancé, after which the engagement broke. She went into severe mental distress and, according to Amar Ujala, had resolved to take a suicidal step before telling her family, who took her to the police. The FIR was registered under the IT Act and sections on criminal intimidation and defamation; police were searching for the accused.
Core concern High reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 15/06/2026
Feb 2026 to Apr 2026BrazilUnidentified video tool
A humorist and tyre repairer from Lençóis Paulista, São Paulo state, who posts on YouTube, Instagram, Facebook and TikTok as an impersonator of a television presenter, used AI tools to turn photographs that young women and adolescent girls of the Congregação Cristã do Brasil (CCB) had posted from inside churches into videos in which they appear dancing sensually beside women in short skirts, with the presenter inserted and the influencer commenting on their clothes. A 16-year-old congregant and her parents went to the 8ª Delegacia de Defesa da Mulher in São Paulo in February 2026; g1 made the case public on 22 April 2026 and Folha de S.Paulo confirmed the investigation. The girl told g1 the photograph had been taken in 2025 in front of the altar of a CCB church, that she was very shy, had not wanted to be exposed and was afraid the exposure would affect her social life, and that she had stopped taking photographs of herself; her family sued for moral damages. On 30 April 2026 the mother of a second girl, aged 17, registered a police report at the 4ª DDM Norte; g1 reported that the exposure had affected the girl psychologically. The São Paulo Civil Police investigate under article 241-C of the Estatuto da Criança e do Adolescente (simulating a sex or pornography scene with a minor by digital means) and for defamation of adult women in the videos; the inquiry was sent at the prosecutor's request to Lençóis Paulista, where the suspect lives, and the total number of people depicted was still being established. The influencer admitted making the videos with AI, said through his lawyer that they were satire and criticism of customs in a context of humour, said he did not know some of those depicted were minors, denied in his police statement linking the adolescent's image to sexualised content and said he had taken her for an adult, and posted an apology video (dated 5 April by g1's first report, which says it does not mention the deepfakes; described as posted after his police statement in g1's second report). The CCB said it had identified him, was taking internal measures and supports legal measures by the authorities. No later development was found on 2026-09-22.
Core concern High reported severity Involving minors Investigation Opened
AI involvement supported · Causal attribution supported · 5 sources, 3 underlying accounts · Added 14/06/2026