2 Jan 2026Event location unknownGrok
The Bureau of Investigative Journalism and The Observer reported on 29 September 2026 that police investigations into sexualised images generated by X's chatbot Grok had failed to identify anyone. A Welsh presenter and campaigner against deepfake abuse, who had criticised Grok publicly on New Year's Eve 2025, saw an anonymous X user ask '@grok' to put her in a bikini made of cling film; Grok generated the image from her profile photo and posted it. She reported it to South Wales Police on 2 January 2026, was not asked for a statement until March, and was told officers had not heard back from X; the case was closed (in May, per The Observer) with the force saying no suspect could be identified. The same account also targeted a commentator and broadcaster, who estimates about 300 Grok images and videos of her were posted during the wave, including one alongside Jeffrey Epstein reported to the Metropolitan Police, which likewise said no suspect could be identified. The presenter is now in pre-action legal correspondence with xAI (part of SpaceXAI) alleging misuse of private information and breaches of data-protection law and the Equality Act; the company told her lawyers it had not been possible in the time available to look into its communications with South Wales Police. BBC Wales had reported in January 2026 that explicit images of the presenter were created with the chatbot and shared without her consent.
Core concern Medium reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 3 sources, 2 underlying accounts · Added 30/09/2026
23 Feb 2026 to 25 Feb 2026ItalyUnidentified voice-cloning tool
On 23 February 2026 Paolo Molesini, then chairman of Fideuram (the private-banking subsidiary of Intesa Sanpaolo), received a WhatsApp message from an unknown number from someone claiming to be Intesa's chief executive Carlo Messina, announcing a confidential acquisition that had to be executed through Fideuram. The same day a caller presenting as a lawyer of A&O Shearman whom Molesini knew, whose voice ANSA, Il Fatto Quotidiano and Corriere della Sera, reporting from the Milan court papers, describe as created with artificial intelligence (today.it, which also cites the seizure decree, writes that the court papers do not yet answer whether the voice was imitated), had him sign a confidentiality agreement and sent eleven payment instructions; Fideuram's treasury head was separately contacted by someone posing as Fideuram's CEO. Between 23 and 25 February eleven transfers totalling about 95 million euros went to accounts in Portugal and at Bank of China; the bank's alarm systems and the Milan prosecutors recovered about 40-42 million from China and 13 million seized in Portugal, leaving at least 36 million (39.5 million per the court papers) missing after conversion into cryptocurrency. Molesini, who Corriere writes is not under investigation, resigned as chairman on 12 March 2026, which Fideuram announced as being for personal reasons; a 48-year-old Israeli citizen is under investigation as a member of the gang.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution supported · 8 sources, 5 underlying accounts · Added 30/09/2026
19 Aug 2026FranceUnidentified AI tool
According to Gossement Avocats, which quotes the order, and the court's vice-president on France Inter, an order of 19 August 2026 (n°2508168) of the tribunal administratif de Rennes rejected a claimant’s application contesting a VAT reassessment and fined the claimant 500 euros for an abusive application. As quoted by Gossement Avocats, the order says the application had manifestly been written with an artificial intelligence tool and that its grounds lacked the most elementary details needed to assess them. The court also found it inadmissible because no prior complaint to the tax service was shown, and noted that it repeated a request with substantially the same object rejected in October 2025. The court’s vice-president cited the case on France Inter; commentators stress that AI use alone was not the basis for the fine.
Core concern Low reported severity Regulatory Action
AI involvement reported · Causal attribution supported · 4 sources · Added 29/09/2026
3 Sept 2026BrazilUnidentified image tool
In early September 2026 a private school in Jaú, in the interior of São Paulo state, identified the circulation of fake intimate images of a female classmate made with artificial intelligence and contacted the families. According to the police report described by the press, eight ninth-grade boys, all aged 15, kept a WhatsApp group in which they used digital programs to manipulate images of the student so that she appeared unclothed. The school suspended the eight and informed the girl's parents. The father of one of the boys checked his son's phone, found the files and took the boy and the phone to the police to register a report; the girl's parents also registered a police report. The São Paulo Public Security Secretariat said the Civil Police are investigating a 15-year-old for dissemination of child pornography and defamation that occurred on the morning of Thursday 3 September. The school said the content originated on a private platform outside the school environment and that it had adopted protective and welcoming measures for the student and opened an internal inquiry. The AI tool used is not named. The students are minors and are not named in any report.
Core concern Medium reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution supported · 4 sources, 3 underlying accounts · Added 29/09/2026
22 Sept 2026United StatesUnidentified image tool
David Douglas High School in Portland warned families in a statement reported on 28 September 2026 about social-media posts targeting its students, athletes, coaches and staff, saying some images and videos had been digitally altered, including with AI, and did not accurately represent those depicted; it reported some of the content to the Portland Police Bureau. KATU, which reviewed the account, reports 17 posts using racist, anti-immigrant and religious stereotypes against football players: one image shows a Latino player in a sombrero being detained by people labelled as ICE agents, another shows a player in a head covering with what appears to be a fake explosive vest, and a Black player is depicted beneath a caption referring to George Floyd. The head coach said students were hurt, and that one student texted him over the weekend after seeing one of the posts: 'Coach, this is terrible. What do I do?' The account references Rex Putnam High School, whose team David Douglas played on the Friday before the report; which along with its district says it has no connection to it. Who runs the account and which images were AI-generated are not reported.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 2 sources · Added 29/09/2026
16 Sept 2026 to 18 Sept 2026IndiaUnidentified image and video tool
A head constable at Hebbal police station in Bengaluru complained that on 16 September 2026 he accepted a Facebook friend request from an unknown account and exchanged sexually explicit messages with it over Messenger. According to his complaint, reported by the Times of India, the person behind the account downloaded his old Facebook photographs and used AI tools to make morphed obscene images and videos showing him with women, sent them to him with a QR code, demanded money in return for deleting them and threatened to send them to senior police officers and post them on social media, warning that this would damage his reputation. The harassment continued until 18 September. He gave police copies of the messages and the morphed images. Hebbal police registered a case under IT Act sections 66E and 67A and Bharatiya Nyaya Sanhita sections 308 (extortion) and 351 (criminal intimidation), took steps to stop the material being uploaded and are trying to trace the account holder. Whether he paid is not reported, and no arrest is reported.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 1 source · Added 28/09/2026
9 Sept 2026IndiaUnidentified video tool
A security guard in Bengaluru, originally from Odisha, told the Times of India that on 9 September 2026 he answered a WhatsApp video call in which a face and voice presented as Tamil Nadu Chief Minister C. Joseph Vijay introduced himself in Hindi, asked his name, work and where he lived and pressed him to accept financial help. A 'manager' then promised Rs 11 lakh, said Rs 5 lakh had been allotted to him and asked for a Rs 5,000 exchange charge, then Rs 18,000 to unlock a supposedly locked PIN; a caller posing as a CBI officer demanded more than Rs 50,000 as a fine. The fraudsters sent a fake allotment letter and a purported CBI officer's identity proof. He paid more than Rs 1.04 lakh through a digital payment app before refusing a further Rs 50,000 demand, called the 1930 cybercrime helpline and went to Byappanahalli police, who registered a case under the Information Technology Act. The Times of India says the fraudster allegedly used a deepfake AI-generated video and calls it the first such case reported in the city. No arrest is reported, and no link to the Tamil Nadu CB-CID deepfake case or its Alwar arrest has been established.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 28/09/2026
Sept 2026GermanyUnidentified image tool
The Oldenburg-Stadt police inspectorate said on 22 September 2026 that in the preceding days numerous messages had been sent through one or more student accounts on the email servers of Oldenburg schools. The messages contained, among other things, deepfakes (manipulated depictions of children and young people); on an initial assessment some of these could constitute the offence of distributing child or youth sexual abuse material, and some messages contained threats of violence and calls for recipients to harm themselves. According to dpa, students and parents reported the incidents to the police, and dpa, reporting a police spokesman, describes the images as made with artificial intelligence (the written police statement calls them deepfakes, manipulated depictions, without naming AI). Investigators are examining whether unknown persons gained unauthorised access to the accounts; first digital traces were secured and the police are working with the affected schools. RND reports that the accounts were on the IServ school platform, whose provider said it had no access to the messages and believed the incident was limited to Oldenburg. The exact number of schools (the police refer to 'the affected schools', plural), messages, depicted children and recipients, and who created the images, are not reported.
Core concern Medium reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution alleged · 4 sources, 2 underlying accounts · Added 27/09/2026
Jul 2026IndiaUnidentified image tool
A 25-year-old content creator from Delhi complained to the police that organisers and demonstrators at a Cockroach Janta Party (CJP) protest at Jantar Mantar had taken her personal photograph without consent, used AI face-swapping tools to morph her face onto a vulgar, compromising image alongside Prime Minister Narendra Modi, printed the image on banners waved before crowds with sexually suggestive slogans, and circulated videos of the banners on Instagram and other platforms; her later High Court petition adds that the images were uploaded to pornographic websites and that she has received rape, acid-attack and death threats. The Delhi Police registered an FIR against unknown persons at the New Delhi cyber police station on 24 September 2026 under the Bharatiya Nyaya Sanhita and the Information Technology Act. On 25 September Justice Girish Kathpalia of the Delhi High Court directed Meta Platforms to remove the objectionable content within 24 hours, ordered the Delhi Police to give the petitioner complete protection and file a status report within a week, issued notice to the four CJP functionaries named in her plea, ordered the registry to redact the impugned web links from the petition (and, per PTI, her name), and listed the matter for 14 October 2026 (PTI, Ommcom News). The police told the court the FIR had been registered the previous day and that action would be taken expeditiously; no accused had been named or arrested at that stage. The petition says the protest took place in July 2026 and that she approached the police on 23 September; the CJP had not commented at the time of the first report.
Core concern High reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 9 sources, 7 underlying accounts · Added 26/09/2026
15 Sept 2026 to 16 Sept 2026IndonesiaUnidentified image tool
On 23 September 2026 the spokesperson of the East Jakarta metropolitan police (Polres Metro Jakarta Timur) confirmed to reporters that a grade-9 student at a state junior high school in Pulogadung, East Jakarta, had edited photographs of several female schoolmates using artificial intelligence so that they appeared indecent, and that the edited images had been made into WhatsApp stickers; the police women-and-children protection unit is investigating. The case surfaced through a post on Threads which said about 200 edited photographs had been produced and sold to others; Kompas.com noted on 24 September that the sale allegation still rested only on that post, VIVA reported that police were still checking the claim that the images had been sold, and ANTARA reported on 23 September that police were still establishing the editing method, the recipients and the number of depicted students. As of 24 September the depicted students had not filed a report (detik and VIVA date the spokesperson's telephone remarks 'Kamis (22/9/2026)', a date that is internally inconsistent) and police appealed to them to do so. According to the parents' account relayed by police, on 15 and 16 September several people took the student who made the images to an empty house and then to a reservoir in Kayu Putih, punched him on the nose, ears and head, kicked his chest and stomach and threatened him with a bladed weapon; police attribute the beating to friends of the depicted students (ANTARA, detik, VIVA), while Kompas.com's 23 September report quotes the same spokesperson as saying the depicted students themselves beat him; he filed an assault report, which police are handling alongside the image case, and the school has held mediation with the students' parents. No student or school is named in the reports.
Core concern High reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution supported · 8 sources, 1 underlying account · Added 25/09/2026
19 Jun 2026 to 13 Aug 2026BrazilChatGPT and OpenAI moderation
Over about two months in 2026 a 36-year-old farmer in rural São Gabriel da Palha, Espírito Santo, exchanged messages with ChatGPT that the Espírito Santo civil police describe as plans to kill his eight-year-old son, attack other people and kill himself; one message said he had offered 50,000 to someone to kill him and his son. OpenAI reported the messages to the FBI, which passed them through Brazil's Ministry of Justice cyber-operations laboratory to the state police on 16 June; the man was arrested on 19 June as he left home, a day before the date on which police believed the plan would be carried out. Police say what the platform provided was corroborated at the scene (four bottles of unidentified substances and a knotted rope were found) but that he denied intending to kill the child; his lawyer says he was talking nonsense to a chatbot and took no concrete step. After 54 days in custody a court granted habeas corpus on 13 August 2026 because the inquiry had not been concluded and no charges had been brought, imposing electronic monitoring and a ban on approaching or contacting his son and the child's mother. Police were still examining his phone and awaiting forensic results. OpenAI provided user details and his messages but not ChatGPT's replies and did not answer the BBC's question why; it told the BBC it may notify law enforcement when it detects a credible and imminent risk of harm to others. The case is recorded as an institutional response to AI use: the reported adverse consequence is the detention without charge, and the police account that the report prevented a planned killing is preserved as context.
Core + contextual relations High reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 4 sources, 2 underlying accounts · Added 23/09/2026
19 Jun 2026GermanyUnidentified image tool
On 'the previous Friday' (19 June 2026, read relative to the 24 June 2026 report) the leadership of the Heinz-Brandt-Schule in Berlin-Weißensee (Pankow district) learned that two of its pupils were suspected of having created and distributed AI-generated sexualised nude images of female classmates; the school wrote to parents that it was 'shocked and appalled' that classmates' photographs had been abused in this way and described the alleged acts as a massive attack on the personality rights of the affected girls and a form of sexualised violence. The two pupils alleged to be mainly responsible were suspended from lessons with immediate effect, and the school imposed measures on pupils who are said to have known about the images without reporting them. The Senate Department for Education confirmed the incidents and the ongoing investigation in the Tagesspiegel's report of 24 June 2026. The school's letter says the investigation is conducted on behalf of the public prosecutor. A Berlin police spokesman said complaints had been filed over the creation of so-called deepfakes, that the investigation had been taken over by the State Criminal Police Office unit responsible for sexual offences against minors, and that criminal liability for possessing, obtaining, creating or distributing youth pornography under section 184c of the Criminal Code was under consideration; the police gave no further details, citing victim protection. At least three cases are alleged. The school said it would revise its prevention and sex-education concepts and asked parents to talk to their children about handling other people's photographs and AI applications. Nobody is named; the number of girls depicted is not reported.
Core concern Medium reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution supported · 1 source · Added 22/09/2026
16 Sept 2026IndiaUnidentified video tool
A Rajasthan social-media influencer visited Haridwar with her family in June 2026 and on 6 June uploaded to Instagram a short video, recorded by relatives, of herself taking a dip in the Ganga at Har Ki Pauri wearing a salwar suit. About two months later she found that the video had been manipulated with AI into an objectionable version showing the same movements with her face and body portrayed 'in a shameful manner'; the fake reel went viral in the week before 20 September and drew objectionable comments and re-sharing. In a public appeal she asked whoever uploaded it to remove it, saying it was a matter of her dignity, that she was mentally very disturbed and had reached a point where she could not step out of her house. She filed a complaint with the cyber-crime police on 16 September 2026; the investigating Rajasthan Police Service officer said they were trying to identify who created and circulated the video and to have it removed, and that identifying the accused would take time. Dainik Bhaskar's English edition reported the case on 20 September in a 'Sunday Big Story' that does not name her.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 1 source · Added 21/09/2026
11 Aug 2026BrazilUnidentified voice-cloning tool
On Monday 10 August 2026 a digital influencer from Picos, in the centre-south of Piauí, began negotiating a car advertised online for sale in Fortaleza (Ceará), where an uncle of his lives, and asked the sellers to take the car to the uncle so he could inspect it. On Tuesday 11 August a contact using a different number but the uncle's photo sent him audio messages in a voice identical to his uncle's, generated with artificial intelligence, saying the car was in good condition and telling him to make the bank transfer. Believing he was speaking to his uncle, he transferred the money; when he then called the uncle's real number he learned he had been defrauded. The loss exceeded R$56,000, money he says he had saved for years. He registered a police report on 11 August; the Piauí property-crimes unit (Depatri) is investigating and he is seeking a refund from the banks. The account is the victim's own, reported by G1 Piauí on 13 August 2026 from his social-media posts and an interview; the police unit did not respond to G1 before publication.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 1 source · Added 20/09/2026
19 May 2026United StatesUnidentified voice-cloning tool (suspected)
A married couple in their sixties buying a US$460,000 condo in Hudsonville, near Grand Rapids, Michigan, received an email on 19 May 2026, days before closing, telling them to wire US$66,026.92 for the down payment and closing costs within 24 hours. The email listed a phone number differing from their loan officer's by two digits, and the husband then received a call confirming the instructions in a voice that sounded just like the loan officer. The couple borrowed from family and other sources and wired the money. The day before closing their real loan officer sent the actual statement; the closing was cancelled hours before signing and the money was gone. The husband now believes the call came from a spoofed number using AI-assisted voice cloning; Tyler Adams of CertifID, which is working with the couple and federal officials, said someone's email in the transaction was probably compromised and that the scammers likely cloned the loan officer's voice from social-media clips. The sender's address had two extra letters ('UnitedsMortgages' instead of 'UnitedMortgage'). Neither the lender nor the loan officer is accused of complicity. The couple later completed the purchase in early June from their mutual fund, reported the loss to the FBI's Internet Crime Complaint Center, and describe lasting apprehension and have discussed delaying retirement. CNN reported the case on 15 September 2026; the account the money went to has since closed.
Core concern Medium reported severity Investigation Opened
AI involvement suspected · Causal attribution alleged · 2 sources, 1 underlying account · Added 20/09/2026
1 Aug 2026 to 16 Sept 2026KazakhstanUnidentified video tool
On 16 September 2026 the Prosecutor General's Office of Kazakhstan warned of an investment-fraud scheme in which criminals advertise non-existent projects on TikTok, Instagram, YouTube and other platforms using deepfake videos of well-known people and fake 'AI' investment platforms promising very high passive income: 'Kaspi AI' with Mikhail Lomtadze, 'Quantum AI' with Elon Musk, 'TON' with Pavel Durov, and 'people's investments' in KazMunayGas or Gazprom fronted by news presenters from Khabar 24, KTK and Channel One. The office said 119 such cases had been registered across the country in the previous one and a half months. Its example: in September 2026 a woman from Taldykorgan saw an Instagram advertisement offering high returns from share trading, left her details through the link, was contacted by the fraudsters and, following their instructions, transferred more than 7 million tenge to third-party accounts; the money and supposed dividends appeared in a fake wallet that she could not withdraw from. A pre-trial investigation is under way. The office urged people not to trust guaranteed-return offers or transfer money to strangers.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution supported · 5 sources, 1 underlying account · Added 20/09/2026
1 Jan 2026IndonesiaUnidentified image and video tool
A female student at a state university in Solo (Surakarta), Central Java, learned on 1 January 2026 from friends that her face had been composited onto pornographic images and a video, which her lawyer said were found on Instagram and Telegram. Her family reported the case to the Central Java regional police cyber directorate on 28 January 2026. Police issued a formal police report on 31 July, arrested her ex-boyfriend, a university student in Semarang, at his boarding house in Gunungpati on 4 August 2026, and detained him. The police spokesman said the suspect used AI to place the complainant's face on another woman's naked body so that she appeared in pornographic content, uploaded it to his X account, did not sell it, and acted out of resentment after an on-and-off relationship ended. He faces charges under Articles 51 and 35 of the Electronic Information and Transactions Law and an article printed by two outlets as 'Law No. 1 of 2026', with a maximum of 12 years' imprisonment. Her lawyer said she could not sleep, withdrew, felt shame and at one point lost hope, that his team had found seven women in total allegedly targeted of whom six had not reported, and that the suspect's parents asked for an out-of-court settlement; police said only one complainant was confirmed.
Core concern High reported severity Investigation Opened
AI involvement reported · Causal attribution supported · 6 sources, 2 underlying accounts · Added 20/09/2026
May 2026SingaporeUnidentified video tool
In May 2026 the Singapore Police Force (SPF) reported that a man had lost at least S$4.9 million (about US$3.8 million) to a government-official impersonation scam. He received a WhatsApp message carrying the profile photo of Secretary to the Cabinet Wong Hong Kuan and an email from a proton.me address in that name, requesting urgent funding assistance for 'the situation in the Strait of Hormuz', with a fake 'letter of guarantee' bearing the Prime Minister's signature promising reimbursement within 15 business days; he signed a non-disclosure agreement and supplied a copy of his identity card. He was then invited to a Zoom video conference in which Prime Minister Lawrence Wong, President Tharman Shanmugaratnam, Minister Indranee Rajah, Monetary Authority of Singapore representatives and foreign officials appeared; all were fabricated with deepfake AI, and the closing 'remarks' by the fake Prime Minister acknowledged the victim's attendance. Contacted afterwards on WhatsApp by a scammer posing as a lawyer, he transferred the money in a series of transactions to a corporate bank account, and realised the fraud only when he contacted the real cabinet secretary. On 16 May the police released footage of the fake conference, noting lips out of sync with speech, audio broadcast from a single account and a distorted background.
Core concern High reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 3 sources, 1 underlying account · Added 18/09/2026
14 Sept 2026United StatesUnidentified image and video tool
On 14 September 2026 Manhattan District Attorney Alvin Bragg announced the seizure of 12 domain names used to disseminate, publish and sell non-consensual AI-generated sexual 'deepfake' videos. His office said individuals under investigation had used AI image- and video-creation tools to turn photos and videos of approximately 1,200 real people, overwhelmingly women, into hyper-realistic sexual imagery without consent. The victims included actors, politicians, athletes, musicians, activists and social-media influencers. WIRED and outside researchers reported that many videos reposted content from the defunct MrDeepFakes platform and that dozens of politicians appeared on the sites; investigations into who ran them are ongoing.
Core concern High reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 2 sources · Added 17/09/2026
12 Jun 2026RussiaChatGPT
On 12 June 2026 a Russian-speaking crypto investor, known by the alias Alex (@vesnuhin), asked ChatGPT in Russian where to swap sFLR for WFLR tokens. ChatGPT's reply included a link to sceptre.network, a phishing clone of the legitimate sceptre.fi. He connected his wallet and signed an unlimited-approval transaction; within seconds about 1.9 million FXRP, worth roughly $2.1 million (about 180 million rubles), were drained. A blockchain analyst traced the theft, and reported that the phishing link appeared only in Russian-language answers. Russia's Interior Ministry (MVD) later confirmed the loss.
Core concern High reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 4 sources, 2 underlying accounts · Added 17/09/2026