Event date unknownEvent location unknownUnidentified coding agent
In a public post to r/ClaudeCode created on 8 October 2026, a developer who runs Claude Code and OpenAI's Codex together writes that an agent, asked to revert some wording it had changed in a privacy policy, found a .tar.gz archive in the project root and copied server.js out of it. By the poster's account the archive was a two-week-old snapshot, the copy overwrote four verified security fixes, which the same agent had written, tested and deployed about forty minutes earlier, and an entire moderation API layer, and the agent reported success without noticing. Nothing was in git. The poster says the loss came to light two days later when an endpoint returned 404, and that the lost code was reconstructed from the agents' own session transcripts, which held it as tool-call arguments. The post does not say which of the two agents ran the copy. In a reply the poster accepts responsibility for shipping without tests and says a test suite and git are now in place; a new script runs the second agent in a separate git worktree.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 1 source · Added 09/10/2026
Event date unknownSpainUnidentified video tool
Spain's Policía Nacional said on 11 August 2026 that it had arrested in Murcia a suspect who tried to obtain electronic signature certificates in other people's names from a company that issues them. During the company's video identity checks the suspect appeared on camera holding a forged DNI identity card while AI software modified the suspect's face in real time to match the photo on the forged document. Police say the suspect made 38 attempts using the identities of more than 30 real citizens and succeeded in impersonating multiple victims, aiming to use the signatures for later scams. A short processing delay in the face-modification software made the digital mask disappear for barely a second, exposing the suspect's real face to the issuer's security staff.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 02/10/2026
Event date unknownEvent location unknownUnidentified video tool
Dr. François Marquis, chief of intensive care at Maisonneuve-Rosemont Hospital in Montreal, told CBC News (August 2025) and CTV News and CBC News (September 2026) that AI-generated deepfake videos using his likeness keep appearing on Facebook, selling joint supplements, pills and cancer cures and spreading anti-pharmaceutical claims; the latest offers $1 million to dissatisfied customers. He is not on social media and learns of the videos from people who call him. He recounts that a person who paid hundreds of dollars for pills advertised in one of the videos, and never received them, came into the ICU demanding his money back, which he describes as a security problem for the hospital. He has reported the deepfakes to Quebec's College of Physicians, Montreal police and the platforms, but says new videos keep appearing. The makers of the ads are not identified.
Core concern Low reported severity Media Coverage
AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 01/10/2026
Event date unknownEvent location unknownUnidentified image tool
Bitcoin security adviser Terence Michael wrote on X on 14 December 2025 that a client who had recently reached one bitcoin had lost all of it to a 'pig butchering' romance and trading scam. A screenshot attached to the post shows the client telling the adviser that the woman he had been talking with did not exist, that he had paid for a ticket to meet her and her family on 26 December, and that his retirement funds and family savings were gone. The screenshot also shows the scammer's message to the client saying that this was not real, that she was not the person in the pictures, that the pictures were AI and other people's pictures, and that no funds could be withdrawn. BitDegree (15 December 2025) and a Cointelegraph explainer (31 December 2025) relay the adviser's account; the adviser said he had tried several times to stop the transfers. The client's identity and location, the scam's start date and the tools used are unknown. The Cointelegraph explainer's description of live deepfake video calls does not appear in the adviser's post and is not established.
Core concern Medium reported severity
AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 30/09/2026
Event date unknownUnited StatesUnidentified image and video tool
On 24 July 2026 WBRZ, WAFB and the Livingston Parish News relayed a Livingston Parish Sheriff's Office (Louisiana) statement about an investigation into threats made by phone and online. The sheriff's office said one alleged victim was threatened with rape and other bodily harm unless money was paid, AI-generated photos and videos of one of the victims were sent to numerous family members and friends, and later threats included getting one victim fired. Homeland Security assisted after allegations that overseas suspects were involved through past relationships and acquaintances in Greece. The sheriff's office said subpoenas and search returns from platforms led back to a woman who had first been treated as a victim, and that after an interview with the woman the sheriff's office learned the woman made all of the fictitious accounts, the AI-generated nude photos and videos, the rape threats and the extortion attempts. The accused was booked on charges that include unlawful dissemination of AI nude photos, online impersonation and five counts of extortion, and was released on bond. The Livingston Parish News says the accused and one other person had reported as victims some or all of what the sheriff's office attributes to the accused. The charges are allegations and no conviction is reported. The AI tool is not identified, the victims are not described and the start date of the threats is not stated.
Core concern Medium reported severity
AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 30/09/2026
Event date unknownUnited StatesUnidentified image and video tool
The Sumner County (18th Judicial District) District Attorney's Office said a 30-year-old Portland, Tennessee man was sentenced in Sumner County Criminal Court in September 2026 to 30 years in the Tennessee Department of Correction, to be served without probation, parole or early release. According to the prosecutors, he used artificial intelligence to place the faces of children onto images and videos of nude people and of people engaged in sexual acts, then exchanged the material with a Canadian resident for real child sexual abuse material. Canadian authorities found messages and material connected to him after arresting the person he was communicating with and alerted US law enforcement; a joint investigation by Portland police, Homeland Security Investigations, the FBI and the TBI led to his arrest in November 2025. He was also charged with tampering with evidence after investigators said he deleted material before officers entered his home to execute a search warrant. The children whose faces were used are not identified, their number is not reported, and the reports do not say which AI tool was used or which offences he was convicted of.
Core concern High reported severity Involving minors Criminal Charges
AI involvement reported · Causal attribution supported · 4 sources, 1 underlying account · Added 28/09/2026