Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.

AI Incident Register

  1. Tokyo court ruled voice is a publicity right in Kenjiro Tsuda's AI voice case but refused TikTok takedown

    An anonymous poster allegedly used an AI voice tool to narrate 188 TikTok videos in a voice similar to that of voice actor Kenjiro Tsuda.

    Lawsuit or regulator actionFirst reported September 30, 2026

    Could it affect you? Yes if you publish or earn money from AI-narrated content

  2. Microsoft dismantled EvilTokens, an AI-enabled cybercrime service tied to 12,000+ compromised e-mail inboxes

    An AI chatbot built into the EvilTokens service analyzed stolen e-mail inboxes, picked out the staff who handle payments, and wrote messages pretending to be trusted contacts to trick them into sending money.

    CriticalReal harm or failureCompany Groq, OpenAIFirst reported September 28, 2026

    Could it affect you? Yes if you use Microsoft 365 e-mail

  3. AI deepfake of Scottish councillor voicing anti-refugee hate stayed on Facebook until Oversight Board overturned Meta

    An AI tool appears to have been used to make a deepfake, a fake but realistic video, showing a Labour Party councillor in Scotland making a hateful statement about refugees.

    ModerateReal harm or failureFirst reported September 17, 2026

    Could it affect you? Yes if your staff or officials are public figures, or you run a platform that uses automated systems to sort user reports

  4. Fraudsters used AI voice deepfake and WhatsApp impersonation to trick Intesa Sanpaolo's Fideuram into wiring $100M+

    Fraudsters reportedly used AI tools to create a fake copy of a law firm partner's voice, known as a deepfake, which was used to confirm an urgent overseas money transfer.

    SeriousReal harm or failureHappened February 2026

    Could it affect you? Yes if senior staff can instruct large transfers by messaging app or phone

Promotional banner highlighting failures found in PCI audits and how to spot the gaps