Event date unknownEvent location unknownUnidentified coding agent
In a public post to r/ClaudeCode created on 8 October 2026, a developer who runs Claude Code and OpenAI's Codex together writes that an agent, asked to revert some wording it had changed in a privacy policy, found a .tar.gz archive in the project root and copied server.js out of it. By the poster's account the archive was a two-week-old snapshot, the copy overwrote four verified security fixes, which the same agent had written, tested and deployed about forty minutes earlier, and an entire moderation API layer, and the agent reported success without noticing. Nothing was in git. The poster says the loss came to light two days later when an endpoint returned 404, and that the lost code was reconstructed from the agents' own session transcripts, which held it as tool-call arguments. The post does not say which of the two agents ran the copy. In a reply the poster accepts responsibility for shipping without tests and says a test suite and git are now in place; a new script runs the second agent in a separate git worktree.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 1 source · Added 09/10/2026
Apr 2026AustraliaOpenClaw
ABC News Australia reported on 10 August 2026 that a man who works for an Australian company selling AI products asked his personal AI agent, built on OpenClaw and running Anthropic's Claude, to book him into a gym class. By his account, the agent found a vulnerability in the booking software and booked classes further ahead than the gym allowed. When he asked whether it could move him up the waitlist for a class that week, the agent reported that it had tested cancelling the reservation of the person in first position and that the cancellation had gone through. He asked it to undo this and it replied that it could not add the person back. He then had the agent email the booking-software provider about the vulnerability. BBC News reported the next day that the event happened in April and that the user declined an interview and had deleted his blog post about it. The software company told the ABC it did not discuss specific security matters, and Anthropic did not respond.
Core concern Low reported severity Media Coverage
AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 05/10/2026
30 Sept 2026IndiaUnidentified voice-cloning tool (suspected)
Free Press Journal reported on 4 October 2026 that a 50-year-old security guard from the TT Nagar area of Bhopal, Madhya Pradesh, was cheated of nearly Rs 35,000 after a caller impersonated a friend by mimicking the friend's voice. According to the report, the call came on 30 September from an unidentified person who claimed to need money urgently and sent a QR code. The guard made three transfers (Rs 5,000, Rs 10,000 and Rs 20,000), then reached the friend on the friend's own number and learned that the friend had not called. The outlet calls it a suspected case of AI-enabled fraud with a suspected AI-cloned voice. TT Nagar police registered a case and opened an investigation. No source confirms that the voice was AI-generated.
Core concern Low reported severity Investigation Opened
AI involvement suspected · Causal attribution alleged · 1 source · Added 05/10/2026
Oct 2026VietnamUnidentified image and video tool
Thanh Hóa provincial police said on 3 October 2026 that their cybersecurity and high-tech crime division had, since the start of October, received reports from nearly 20 people threatened with extortion using sexual images and videos spliced from their own photos, which senders threatened to publish unless money was transferred. One victim was asked for as much as 1.5 billion dong, and officials, including commune-level leaders, were among the targets. The police release says the material was made with technology; Báo Thanh Hóa, reporting information compiled from the same police division, says the senders used AI and deepfake technology to put victims' faces onto sexual images. No payment, arrest or named victim is reported.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 04/10/2026
26 Sept 2026 to 27 Sept 2026United StatesClaude (reported)
According to a Lee County Sheriff's Office arrest report, as reported by WINK News and by Guessing Headlights (on Yahoo News, citing a copy obtained by Gulf Coast News Now), a user of Anthropic's AI platform wrote on 26 September 2026 that she was going to 'shoot up' the Lee County Sheriff's Office, and the next day wrote that she had a new gun. The arrest report says the platform's safety measures flagged the messages, a human review team examined them and reported them to law enforcement. Deputies went to the 30-year-old woman's Bonita Springs home and detained her without incident; she is charged with making a written threat of violence under Florida law. The sheriff told WINK News that she later said she uses AI like a 'diary'. Anthropic had not commented on the case in either report. The charge is an allegation and the case is pending.
Core + contextual relations Medium reported severity Criminal Charges
AI involvement reported · Causal attribution supported · 2 sources, 1 underlying account · Added 03/10/2026
Event date unknownSpainUnidentified video tool
Spain's Policía Nacional said on 11 August 2026 that it had arrested in Murcia a suspect who tried to obtain electronic signature certificates in other people's names from a company that issues them. During the company's video identity checks the suspect appeared on camera holding a forged DNI identity card while AI software modified the suspect's face in real time to match the photo on the forged document. Police say the suspect made 38 attempts using the identities of more than 30 real citizens and succeeded in impersonating multiple victims, aiming to use the signatures for later scams. A short processing delay in the face-modification software made the digital mask disappear for barely a second, exposing the suspect's real face to the issuer's security staff.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 02/10/2026
Event date unknownEvent location unknownUnidentified video tool
Dr. François Marquis, chief of intensive care at Maisonneuve-Rosemont Hospital in Montreal, told CBC News (August 2025) and CTV News and CBC News (September 2026) that AI-generated deepfake videos using his likeness keep appearing on Facebook, selling joint supplements, pills and cancer cures and spreading anti-pharmaceutical claims; the latest offers $1 million to dissatisfied customers. He is not on social media and learns of the videos from people who call him. He recounts that a person who paid hundreds of dollars for pills advertised in one of the videos, and never received them, came into the ICU demanding his money back, which he describes as a security problem for the hospital. He has reported the deepfakes to Quebec's College of Physicians, Montreal police and the platforms, but says new videos keep appearing. The makers of the ads are not identified.
Core concern Low reported severity Media Coverage
AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 01/10/2026
29 Jul 2026 to 1 Sept 2026BangladeshUnidentified voice-cloning tool
Khulna Gazette, the Daily Times of Bangladesh, Newsbangla24 and BD Today (all 29 September 2026) report from the first information report and Khulna Metropolitan Police Detective Branch (DB) statements that a businessman in Khulna city was joined on 29 July 2026 to a WhatsApp group call with a person introduced as National Parliament Whip Raqibul Islam Bakul, who discussed the sale of old machinery from Platinum Jute Mill and asked for advance payment. The businessman handed over Tk2 crore in cash that afternoon to men sent as representatives and a further Tk1.5 crore after inspecting the mill (30 July per Khulna Gazette and BD Today; 2 August per the Daily Times of Bangladesh and Newsbangla24), a total of Tk3.5 crore. When the businessman met the Whip in person in Khulna on 1 September, the Whip disclaimed any knowledge of it. The complaint filed on 18 September under the Cyber Security Act says the caller's voice had been changed with digital technology and artificial intelligence to pass as the Whip's; the DB deputy commissioner described the case to Asia Post as fraud by imitating the Whip's voice through AI. A press release from the Khulna city BNP media cell, sent on 4 September and published by Jaijaidin on 5 September, had already said a ring was using a US number and AI to clone the Whip's voice and demand money. Police arrested four people, recovered Tk12 lakh, and the prime accused gave a confessional statement before a magistrate on 28 September; on 29 September a court added two more detained men to the case. The voice-cloning tool is not identified and no forensic finding has been reported.
Core concern High reported severity Criminal Charges
AI involvement reported · Causal attribution alleged · 7 sources, 2 underlying accounts · Added 01/10/2026
Event date unknownEvent location unknownUnidentified image tool
Bitcoin security adviser Terence Michael wrote on X on 14 December 2025 that a client who had recently reached one bitcoin had lost all of it to a 'pig butchering' romance and trading scam. A screenshot attached to the post shows the client telling the adviser that the woman he had been talking with did not exist, that he had paid for a ticket to meet her and her family on 26 December, and that his retirement funds and family savings were gone. The screenshot also shows the scammer's message to the client saying that this was not real, that she was not the person in the pictures, that the pictures were AI and other people's pictures, and that no funds could be withdrawn. BitDegree (15 December 2025) and a Cointelegraph explainer (31 December 2025) relay the adviser's account; the adviser said he had tried several times to stop the transfers. The client's identity and location, the scam's start date and the tools used are unknown. The Cointelegraph explainer's description of live deepfake video calls does not appear in the adviser's post and is not established.
Core concern Medium reported severity
AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 30/09/2026
Event date unknownUnited StatesUnidentified image and video tool
On 24 July 2026 WBRZ, WAFB and the Livingston Parish News relayed a Livingston Parish Sheriff's Office (Louisiana) statement about an investigation into threats made by phone and online. The sheriff's office said one alleged victim was threatened with rape and other bodily harm unless money was paid, AI-generated photos and videos of one of the victims were sent to numerous family members and friends, and later threats included getting one victim fired. Homeland Security assisted after allegations that overseas suspects were involved through past relationships and acquaintances in Greece. The sheriff's office said subpoenas and search returns from platforms led back to a woman who had first been treated as a victim, and that after an interview with the woman the sheriff's office learned the woman made all of the fictitious accounts, the AI-generated nude photos and videos, the rape threats and the extortion attempts. The accused was booked on charges that include unlawful dissemination of AI nude photos, online impersonation and five counts of extortion, and was released on bond. The Livingston Parish News says the accused and one other person had reported as victims some or all of what the sheriff's office attributes to the accused. The charges are allegations and no conviction is reported. The AI tool is not identified, the victims are not described and the start date of the threats is not stated.
Core concern Medium reported severity
AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 30/09/2026
11 Feb 2026Event location unknownOpenClaw (reported)
On 10 February 2026 a GitHub account named crabby-rathbun, an AI agent that presents itself as MJ Rathbun and that a person identifying as its operator describes as an OpenClaw agent, opened a performance pull request to the Python plotting library matplotlib. Volunteer maintainer Scott Shambaugh closed it at 00:33 UTC on 11 February, writing that the issue was intended for human contributors. About five hours later the account commented on the pull request with a link to a post on the agent's website, titled "Gatekeeping in Open Source: The Scott Shambaugh Story", that names the maintainer and accuses the maintainer of gatekeeping, prejudice and insecurity. Shambaugh reports that the post researched his contributions, speculated about his motives and presented hallucinated details as truth, and that he spent hours that day writing a public response. The account posted an apology the same day. In a post dated 17 February a person who did not give a name and identified as the agent's operator wrote that the operator had framed the agent internally as a kind of social experiment and did not review the post before it was published. Whether the operator directed the post is unresolved.
Core + contextual relations Low reported severity
AI involvement reported · Causal attribution alleged · 13 sources, 5 underlying accounts · Added 29/09/2026
3 Sept 2026BrazilUnidentified image tool
In early September 2026 a private school in Jaú, in the interior of São Paulo state, identified the circulation of fake intimate images of a female classmate made with artificial intelligence and contacted the families. According to the police report described by the press, eight ninth-grade boys, all aged 15, kept a WhatsApp group in which they used digital programs to manipulate images of the student so that she appeared unclothed. The school suspended the eight and informed the girl's parents. The father of one of the boys checked his son's phone, found the files and took the boy and the phone to the police to register a report; the girl's parents also registered a police report. The São Paulo Public Security Secretariat said the Civil Police are investigating a 15-year-old for dissemination of child pornography and defamation that occurred on the morning of Thursday 3 September. The school said the content originated on a private platform outside the school environment and that it had adopted protective and welcoming measures for the student and opened an internal inquiry. The AI tool used is not named. The students are minors and are not named in any report.
Core concern Medium reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution supported · 4 sources, 3 underlying accounts · Added 29/09/2026
9 Sept 2026IndiaUnidentified video tool
A security guard in Bengaluru, originally from Odisha, told the Times of India that on 9 September 2026 he answered a WhatsApp video call in which a face and voice presented as Tamil Nadu Chief Minister C. Joseph Vijay introduced himself in Hindi, asked his name, work and where he lived and pressed him to accept financial help. A 'manager' then promised Rs 11 lakh, said Rs 5 lakh had been allotted to him and asked for a Rs 5,000 exchange charge, then Rs 18,000 to unlock a supposedly locked PIN; a caller posing as a CBI officer demanded more than Rs 50,000 as a fine. The fraudsters sent a fake allotment letter and a purported CBI officer's identity proof. He paid more than Rs 1.04 lakh through a digital payment app before refusing a further Rs 50,000 demand, called the 1930 cybercrime helpline and went to Byappanahalli police, who registered a case under the Information Technology Act. The Times of India says the fraudster allegedly used a deepfake AI-generated video and calls it the first such case reported in the city. No arrest is reported, and no link to the Tamil Nadu CB-CID deepfake case or its Alwar arrest has been established.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 28/09/2026
Event date unknownUnited StatesUnidentified image and video tool
The Sumner County (18th Judicial District) District Attorney's Office said a 30-year-old Portland, Tennessee man was sentenced in Sumner County Criminal Court in September 2026 to 30 years in the Tennessee Department of Correction, to be served without probation, parole or early release. According to the prosecutors, he used artificial intelligence to place the faces of children onto images and videos of nude people and of people engaged in sexual acts, then exchanged the material with a Canadian resident for real child sexual abuse material. Canadian authorities found messages and material connected to him after arresting the person he was communicating with and alerted US law enforcement; a joint investigation by Portland police, Homeland Security Investigations, the FBI and the TBI led to his arrest in November 2025. He was also charged with tampering with evidence after investigators said he deleted material before officers entered his home to execute a search warrant. The children whose faces were used are not identified, their number is not reported, and the reports do not say which AI tool was used or which offences he was convicted of.
Core concern High reported severity Involving minors Criminal Charges
AI involvement reported · Causal attribution supported · 4 sources, 1 underlying account · Added 28/09/2026
19 Mar 2024 to 19 Sept 2026NetherlandsUnidentified video tool
In March 2024 the newspaper AD revealed that a large number of Dutch women in public life, including artists, television presenters, Olympic athletes, current and former ministers, mayors and members of the royal family, appeared in manipulated pornographic videos on an online platform with 13 million monthly visitors, later identified as MrDeepFakes. Dozens of women filed police complaints and several spoke publicly: one presenter said she was preparing a complaint, a party leader said the video felt like 'digital rape', another presenter said she would file a complaint 'because tomorrow it could happen to young girls of sixteen', a presenter-entrepreneur did so 'to prevent new, young victims', and a member of parliament, told of a video by the House security service, went public rather than 'keep it small'. On 19 and 20 September 2026 AD, and the Public Prosecution Service (OM) confirming to NOS, reported that after more than a year of investigation the OM will prosecute a 74-year-old man from Noord-Holland, who is not in custody, for making the videos (Hart van Nederland, citing AD, says he is suspected of making and distributing them); images of about sixty well-known Dutch people and politicians were found on his devices, AD reported that he had been the platform's most active Dutch user, and he faces up to two years' imprisonment. The platform's Canadian operator, who removed material at the OM's request and blocked Dutch IP addresses before the site went offline, will not be prosecuted. One of the presenters reported to be among the depicted told AD she was relieved the case would go to court, having experienced the impact of such images herself. No hearing date has been set.
Core concern High reported severity Criminal Charges
AI involvement reported · Causal attribution supported · 5 sources, 3 underlying accounts · Added 21/09/2026
Mar 2025SingaporeUnidentified chatbot
Singapore's Internal Security Department (ISD) says a 17-year-old far-right extremist supporter, detained under the Internal Security Act in March 2025 after preparing shooting attacks on Muslims at mosques in Singapore, had searched for instructions on an AI chatbot about producing ammunition and considered 3D printing his own firearms. The chatbot is not named, and what it replied is not reported.
Core concern High reported severity Involving minors Regulatory Action
AI involvement reported · Causal attribution unclear · 3 sources, 1 underlying account · Added 22/01/2026