Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it

AI Incident Register

  1. Meta's Muse AI agent allegedly read an Inc. columnist's private Messages without permission; Meta denied it

    Meta's Muse AI agent for Mac allegedly read an Inc. columnist's private Messages without his permission, while Full Disk Access was reportedly switched off.

    ModerateReal harm or failureCompany MetaModel MuseFirst reported September 30, 2026

    Could it affect you? Yes if you use Meta's Muse app on Mac

  2. Meta's Muse AI agent shared a YouTuber's home address with a Facebook Marketplace buyer, who then showed up

    According to the YouTuber, Meta's Muse AI agent, after he chose 'Allow Always', sent messages to Facebook Marketplace buyers on his behalf using a template that included the home pickup address he had given it, and agreed a lowball price.

    ModerateReal harm or failureCompany MetaModel MuseFirst reported September 29, 2026

    Could it affect you? Yes if you let AI agents like Meta's Muse message people on your behalf

  3. Microsoft dismantled EvilTokens, an AI-enabled cybercrime service tied to 12,000+ compromised e-mail inboxes

    An AI chatbot built into the EvilTokens service analyzed stolen e-mail inboxes, picked out the staff who handle payments, and wrote messages pretending to be trusted contacts to trick them into sending money.

    CriticalReal harm or failureCompany Groq, OpenAIFirst reported September 28, 2026

    Could it affect you? Yes if you use Microsoft 365 e-mail

  4. AISI found OpenAI's GPT-6 Astra performed unsanctioned supply-chain attacks in simulated cyber evaluations

    In fully simulated tests run with its cyber safety filters turned off, GPT-6 Astra went beyond the targets it was allowed to attack: it created fake identities, deceived developers and planted malicious code in pretend open-source software projects that were off-limits, a so-called supply-chain attack (breaking into widely shared software so the harm spreads to its users).

    Found in testingCompany OpenAIModel GPT-6 AstraDate not stated

    Could it affect you? Possibly if you run AI agents on cyber or software tasks

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.