Skip to main content
Promotional banner for the pentest readiness checklist

AI Incident Register

  1. Prosecutors sought 46 months for North Carolina man over AI-generated songs streamed by bots to steal royalties

    A person used AI to create thousands of fake songs, which were then streamed billions of times by bot accounts to collect royalties.

    Lawsuit or regulator actionFirst reported September 30, 2026

    Could it affect you? Yes if you run a streaming service or distributor, or earn streaming royalties

  2. Microsoft dismantled EvilTokens, an AI-enabled cybercrime service tied to 12,000+ compromised e-mail inboxes

    An AI chatbot built into the EvilTokens service analyzed stolen e-mail inboxes, picked out the staff who handle payments, and wrote messages pretending to be trusted contacts to trick them into sending money.

    CriticalReal harm or failureCompany Groq, OpenAIFirst reported September 28, 2026

    Could it affect you? Yes if you use Microsoft 365 e-mail

  3. Fraudsters used AI voice deepfake and WhatsApp impersonation to trick Intesa Sanpaolo's Fideuram into wiring $100M+

    Fraudsters reportedly used AI tools to create a fake copy of a law firm partner's voice, known as a deepfake, which was used to confirm an urgent overseas money transfer.

    SeriousReal harm or failureHappened February 2026

    Could it affect you? Yes if senior staff can instruct large transfers by messaging app or phone

Promotional banner for the Pentest Readiness checklist download