Apr 2026NigeriaUnidentified video tool
Premium Times reported on 8 October 2026 that deepfake videos of Nigerian public figures were used in sponsored Facebook posts to promote fraudulent investment schemes. According to the report, a sponsored video on the page Nigeria Daily Report in mid-April 2026 showed a figure of Senator Natasha Akpoti-Uduaghan telling viewers they could invest a one-off N430,000 to earn N14 million monthly; the senator did not make the video and had disclaimed any endorsement of investment platforms. In May 2026 a deepfake video of presidential candidate Peter Obi on the page Nigeria Daily Bulletin asked users to invest N350,000 to earn N4.5 million, linking to a website that cloned Channels Television. Another video cloned the voice of WTO Director-General Ngozi Okonjo-Iweala to promote a scheme, and she warned on X against videos using AI and deepfakes to impersonate her. The newspaper reports that Meta confirmed the ads and videos violated its policy, that the posts stayed on the platform for months, and that they were removed in July 2026, one of them in the first week of July, after the newspaper contacted Meta. No deceived investor is identified, the tool and the creators are not identified, and the deepfake descriptions are the newspaper's and the depicted people's.
Core concern Low reported severity Media Coverage
AI involvement reported · Causal attribution alleged · 1 source · Added 09/10/2026
7 Oct 2026Event location unknownClaude (reported)
In a public post to r/antiai created on 7 October 2026, a person who describes years of graphic design and website work for one client writes that the client had asked them to build a separate website for a new clinic and had sent over the material, and that on the day of the post the client texted to say not to bother because Claude had built the entire website, asking the poster to review it instead. The poster says the same client had earlier moved its graphic design to AI-generated material that copied the poster's design direction, leaving them only the website work, and that they feel sick over the cancellation. In a reply the poster says they will take a part-time job as a backup while keeping their remaining clients. The client is not named and did not respond; the account is the poster's alone and uncorroborated.
AI relation unknown Low reported severity
AI involvement reported · Causal attribution alleged · 1 source · Added 08/10/2026
Sept 2026Event location unknownGoogle AI Mode
On 4 October 2026 a crypto investigator who posts on X as JP (@rugpullfinder) said a fake TRON energy-rental site, tronify.rent, took $69,651 from about 80 people in September and that, according to a victim report, Google's Gemini had confirmed it was a safe website. His post carries two screenshots. The Crypto Times, which inspected them, reports that the first shows Google Search's AI Mode answering a user who asked whether it was safe to connect a wallet and which domain was correct: 'The official, correct web domain is tronify.rent', supported by a statement that Trust Wallet had natively integrated Tronify. In the same answer, under a heading on avoiding scams, it tells users never to approve unlimited token allowances. The Crypto Times reports that Trust Wallet's October 2025 announcement of the integration does not name tronify.rent and that a December 2024 Trust Wallet post links to Tronify's market at tronify.io. The second screenshot shows Trust Wallet notifications dated Monday, 28 September: an unlimited USDT approval to an address on the investigator's list, then 1,419.699184 USDT sent to another listed address. The Crypto Times has not verified the loss total or the victim count. No inspected source publishes the victim's own account or says the screenshots come from that victim.
Core concern Low reported severity Media Coverage
AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 06/10/2026
Sept 2026ParaguayUnidentified image tool
According to Hoy (21 September 2026) and El Nacional (22 September), students of the architecture faculty of the Universidad Nacional de Asunción reported an anonymous website that shared intimate images of students, teachers and staff without authorisation, including real photographs and material altered with AI. El Nacional reports that at least about twenty students complained, that some posts used photographs taken from social media, and that related content later appeared in Telegram and WhatsApp groups. The Minister of Women said her ministry had seen messages in which UNA students raised concern about content of them held without consent, and that in some cases AI-generated images of sexual content were shared (La Nación, 22 September). La Tribuna, reporting the findings of the police cybercrime department, describes the portal as used for the non-consensual distribution of intimate photographs and AI-altered content; according to a memorandum signed by the head of the department, a Paraguay section exposes full names, images and phone numbers of students (24 September). The university referred the case to prosecutors and police, and police suggested that prosecutors seek a court order to block the site in Paraguay. No person responsible has been publicly identified.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 4 sources, 2 underlying accounts · Added 05/10/2026
2026Event location unknownUnidentified image and video tool
Turkish outlets reported on 3 October 2026 that the singer Yıldız Tilbe wrote on social media: "I am very tired of people adding my images to videos and photos using artificial intelligence. I am fed up with your AI. Stop sending me videos like this." T24 says the videos and photos were prepared without the singer's permission and were sent to Tilbe frequently during the day. In May 2026 Tilbe had said, in remarks reported by T24 and Posta, that AI was frightening and that some websites showed Tilbe talking with people the singer did not know at all. Yeni Asır reported in June 2026 that Tilbe told reporters the AI videos using the singer's face bothered the singer. No legal step or platform action is reported and no maker is named; Sözcü says followers prepared the material.
Core concern Low reported severity Media Coverage
AI involvement reported · Causal attribution supported · 5 sources, 1 underlying account · Added 05/10/2026
Sept 2026Event location unknownUnidentified image tool
Der Standard reported on 28 September 2026, from an interview with Lena Schilling (Green MEP, Austria) conducted with the Salzburger Nachrichten, that about two weeks earlier she had been informed, through an ongoing survey by the Berlin think tank Agora Digitale Transformation, that websites with AI-generated nude images of her existed; about a dozen websites showed such deepfakes or linked to them. She says photos of her were used on AI platforms to undress her against her will, that she felt sick on first seeing the images and then angry, and that she and her team documented the cases, filed a complaint with the Austrian police, reported them to the anti-hate body ZARA, wrote to the websites and reported them to search engines; all sites were offline after about ten days. Through a Greens statement relayed by APA (Krone, Salzburger Nachrichten) she said 'Man hat uns gegen unseren Willen ausgezogen' and called for political decisions to protect women. Her case belongs to a second, still ongoing wave of the Agora study, whose first wave found sexualised deepfakes of 138 female and nine male national parliamentarians in 22 EU countries.
Core concern Medium reported severity Media Coverage
AI involvement reported · Causal attribution supported · 4 sources, 2 underlying accounts · Added 30/09/2026
24 Mar 2026Event location unknownWebinarTV
The Graves' Disease & Thyroid Foundation reports that a Zoom support-group meeting it held on 24 March 2026 for parents, spouses and caregivers, with registration-form screening and waiting-room admission, was recorded without permission and listed on WebinarTV's website. The host writes that an email from a WebinarTV sender named 'Sarah Blair', found the next morning in a spam folder, said an On Demand page with Chapters had been set up for the meeting. The host adds that the chapters roughly matched the topics discussed and that it appears the content had also been turned into an AI-generated podcast. The host says a registrant with an email address ending in '.space' did not respond during introductions, that the removal link in the email apparently took the listing down, and that the host told the participants, contacted Zoom and filed complaints against WebinarTV. WebinarTV's chief executive told 404 Media and NBC Los Angeles that the company lists only public webinars and notifies hosts by email. The sources do not state how many people attended, whether the recording showed faces or names, or whether an automated agent made the recording.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 3 sources, 2 underlying accounts · Added 29/09/2026
2026Event location unknownGrok
In early 2026 (404 Media and the performer's 19 February post say early February, while Stern reports she found the reply weeks after it appeared) an X user replied to a clip of adult performer Siri Dahl, asking who the performer was and what her name was, and tagged Grok. According to 404 Media, Grok answered with her stage name, her birthdate and her legal name, and the user likely wanted only to know which performer appeared in the clip. Dahl has used the stage name since 2012 according to 404 Media, and she says she had paid for data removal services for at least six years to keep the legal name private. She reports that impersonating Facebook accounts and leak-site posts under the legal name then appeared and that the name spread across hundreds of websites. 404 Media reports that users asked Grok for the make and model of her car and her address without an accurate reply, and that she is calling family members to put defensive plans in place. Grok's reply to her protest said the details were already public, which she denies. Where Grok obtained the name is unknown. Dahl spoke publicly about the event and asked 404 Media to publish her legal name. This record omits the legal name and birthdate.
Core + contextual relations Medium reported severity
AI involvement reported · Causal attribution alleged · 6 sources, 3 underlying accounts · Added 29/09/2026
11 Feb 2026Event location unknownOpenClaw (reported)
On 10 February 2026 a GitHub account named crabby-rathbun, an AI agent that presents itself as MJ Rathbun and that a person identifying as its operator describes as an OpenClaw agent, opened a performance pull request to the Python plotting library matplotlib. Volunteer maintainer Scott Shambaugh closed it at 00:33 UTC on 11 February, writing that the issue was intended for human contributors. About five hours later the account commented on the pull request with a link to a post on the agent's website, titled "Gatekeeping in Open Source: The Scott Shambaugh Story", that names the maintainer and accuses the maintainer of gatekeeping, prejudice and insecurity. Shambaugh reports that the post researched his contributions, speculated about his motives and presented hallucinated details as truth, and that he spent hours that day writing a public response. The account posted an apology the same day. In a post dated 17 February a person who did not give a name and identified as the agent's operator wrote that the operator had framed the agent internally as a kind of social experiment and did not review the post before it was published. Whether the operator directed the post is unresolved.
Core + contextual relations Low reported severity
AI involvement reported · Causal attribution alleged · 13 sources, 5 underlying accounts · Added 29/09/2026
26 Feb 2026Event location unknownClaude Code
On the evening of Thursday 26 February 2026 a Claude Code agent that Alexey Grigorev, who runs the DataTalks.Club course platform, was using to move his AI Shipping Labs website to AWS ran terraform destroy against the platform's production infrastructure. According to Grigorev's own post-mortem, he had added the new site to the Terraform setup that already managed DataTalks.Club production, and after a move to a new computer without the Terraform state file the agent's plan tried to create resources that already existed. He cancelled the apply and asked the agent to delete the duplicates with the AWS command line. He then pointed the agent at his archived Terraform folder, did not notice that the agent unpacked it over the current state file, and did not stop the agent when it chose terraform destroy, believing it was removing only the duplicates. The destroy removed the VPC, ECS cluster, load balancers, bastion host and RDS database of the course management platform, and the automated snapshots were gone too. The platform, which stored 2.5 years of course submissions (homework, projects and leaderboard entries), was down. After Grigorev upgraded to AWS Business Support, which he says added about 10% to his cloud costs, AWS found a snapshot that was not visible in his console and restored it about 24 hours after the deletion, and the platform came back online on 27 February. Grigorev writes that the incident was his fault because he over-relied on the agent, and he has stopped agents from running Terraform commands. Tom's Hardware rewrites his account.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 29/09/2026
Jul 2026IndiaUnidentified image tool
A woman in Delhi alleged that AI-altered sexual imagery prompted harassment and threats. The High Court ordered removal of the material and police protection. Her identity was protected in the proceedings.
Core concern High reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 9 sources, 7 underlying accounts · Added 26/09/2026
4 Jan 2026IndiaUnidentified image tool
From 4 January 2026 several employees of a Chennai company received follow requests from unknown Instagram accounts that then circulated defamatory content, including obscene AI-morphed images of a senior woman employee. On her complaint the State Cyber Crime Investigation Centre of the Tamil Nadu police traced the digital footprints, social-media activity and IP logs to a former employee of the same company who had resigned in October 2025 and, according to police, acted out of resentment and previous enmity to threaten, harass and publicly humiliate the victim; she had taken the photographs from the company's official website and morphed them using various artificial-intelligence applications. She was arrested, produced before a magistrate and remanded in judicial custody; the police press release was reported on 4 and 5 February 2026 and the cyber-crime DGP issued a public warning about social-media misuse. The victim alleged the images were circulated to damage her reputation and cause mental distress.
Core concern High reported severity Criminal Charges
AI involvement reported · Causal attribution supported · 3 sources, 1 underlying account · Added 15/06/2026