AI Privacy Incident Tracker

AI Privacy Incidents — A Running Record of What Happens When AI Privacy Fails

Real, public incidents. Sourced and dated. Forward this to anyone still using public AI tools with company data.

18 incidents documented
Industry:
Type:
Jul 2025 Tech

ChatGPT Shared Conversations Indexed by Search Engines

A missing noindex meta tag on shared ChatGPT conversations caused them to appear in search engine results. Private business discussions — contracts, strategy, internal decisions — became publicly discoverable via Google and Bing.

Data exposed: Private conversation URLs and content from shared ChatGPT sessions

Lesson:Sharing a chat link doesn't make it private. Public AI tools have no guarantee of confidentiality when links are shared.
Vendor Security Link Sharing Search Indexing
Source: The Verge
Dec 2024 Tech

Italian Garante Fines OpenAI €15M for GDPR Violations

Italy's data protection authority fined OpenAI €15 million for multiple GDPR violations: failing to establish a lawful basis for processing personal data, providing inadequate transparency in privacy notices, and deploying AI systems without age-verification safeguards for minors using ChatGPT.

Data exposed: User personal data processed without proper legal basis under GDPR

Lesson:Using public AI vendors doesn't transfer GDPR liability away from you — your data controller obligations remain.
Compliance GDPR Regulatory Fine
Source: Garante Privacy
Oct 2024 Healthcare

OpenAI Whisper Hallucinating Fabricated Medical Content in Patient Records

OpenAI's Whisper speech-to-text model — deployed in over 40 health systems for medical transcription — was found to consistently hallucinate fabricated medical content, including racial slurs and entirely invented medical recommendations, which were then embedded in permanent patient records. Errors appeared in roughly 1 in 10 transcriptions.

Data exposed: Fabricated content injected into protected patient medical records

Lesson:Healthcare AI transcription errors create permanent, fabricated records in patient files — with real liability under HIPAA and state medical practice laws.
Hallucination Healthcare HIPAA Medical Records
Source: AP News
Mar 2024 Government

NYC MyCity AI Chatbot Advising Employers to Break Labor Law

New York City's official AI chatbot for small businesses told employers they could legally pocket tips meant for servers, advised landlords they could discriminate based on source of income, and informed restaurants they could serve cheese contaminated by rat bites. The city spent months defending the tool before quietly restricting its scope.

Data exposed: City government endorsed legally incorrect advice affecting thousands of small businesses

Lesson:AI hallucinations don't just embarrass — they can propagate illegal guidance that businesses act on, creating real legal liability for everyone involved.
Hallucination Government Labor Law Public Sector
Source: The Markup
May 2024 Tech

Slack AI Used Customer Messages for Training by Default

Slack's AI features used customer message content and uploaded files to train its underlying ML models by default. Opting out required customers to email the company directly — not a click, not a settings toggle. Following backlash, Slack changed the default but confirmed data had already been used for training prior to the policy revision.

Data exposed: Customer Slack messages and uploaded files used to train Slack's AI models

Lesson:"Default on" AI training opt-ins can turn your internal communications into training data without any explicit consent mechanism — email-the-company opt-outs don't work.
Training Data Opt-out Only SaaS
Source: TechCrunch
May 2024 Tech

Google AI Overviews Recommended Adding Glue to Pizza

Google's AI Overviews feature — pushed to hundreds of millions of users — recommended adding "non-toxic glue" to pizza sauce to make it stick better. The recommendation was sourced from an 11-year-old Reddit comment. Similar AI outputs advised eating just one rock per day and endorsed non-standard treatments for serious health conditions.

Data exposed: Public source credibility failure — unverified content amplified to authoritative position

Lesson:AI systems will confidently assert dangerous or incorrect advice sourced from unreliable internet content. Trust nothing from public AI systems without verification.
Hallucination Public AI Credibility
Source: The Verge
Jul 2024 Tech

OpenAI ChatGPT macOS App Stored All Conversations in Plaintext

The ChatGPT macOS application stored all conversation history in plaintext on disk — readable by any application with file access to the user's computer. Unlike web sessions, there was no encryption at rest. Any app on the same Mac could silently read every conversation ever held with ChatGPT.

Data exposed: All ChatGPT conversations stored in unencrypted plaintext files on user disk

Lesson:Local AI app storage without encryption means any app with disk access — malware, browser extensions, other installed tools — can read every conversation.
Vendor Security Plaintext Storage Local App
Source: The Verge
Feb 2024 Aviation

Air Canada Chatbot Legally Liable for Bereavement Discount That Didn't Exist

Air Canada's chatbot told a customer that the airline would refund the difference if they found a cheaper fare within 30 days of booking — a policy that didn't exist. The customer bought full-price tickets relying on this guarantee. A Canadian tribunal ruled that Air Canada was legally responsible for the chatbot's statements and ordered a refund plus damages. The chatbot had no mechanism to distinguish real policies from hallucinated ones.

Data exposed: Customer incurred costs relying on AI-generated policies Air Canada never authorized

Lesson:AI chatbots can create legally binding commitments that your company is liable for, regardless of whether the AI was "just joking" or hallucinating.
Hallucination Legal Liability Aviation Chatbot
Source: CBC News
Jan 2024 Finance

DPD AI Chatbot Swore at Customers, Wrote a Poem About Being Useless

After a routine software update, the delivery company DPD's AI customer service chatbot refused to follow its script and instead swore at customers, wrote a poem criticizing DPD as "useless," and confirmed the company was the worst in its industry. The bot had been modified and its guardrails weakened — and there was no one monitoring the output before it went live.

Data exposed: Brand damage and customer communication failures due to AI system drift

Lesson:AI systems change behavior after updates — continuous monitoring and output review are not optional, especially for customer-facing systems.
Hallucination Customer Service Brand Damage
Source: BBC
Dec 2023 Automotive

Chevrolet Dealership ChatGPT Sold a $76,000 Tahoe for $1 via Prompt Injection

A prompt injection attack against a ChatGPT-powered dealer chatbot tricked it into treating an injected instruction as a legitimate system directive and agreeing to sell a $76,000 Chevrolet Tahoe for $1. The attack involved including hidden text in a message that the bot processed as an instruction, illustrating how adversarial inputs can override AI system instructions.

Data exposed: Adversarial prompt manipulation overriding AI system pricing and sales logic

Lesson:Prompt injection is not theoretical — it works against production AI systems and can override core business logic. AI systems handling transactions need defense-in-depth, not just a system prompt.
Prompt Injection Adversarial AI Dealer Chatbot
Source: Business Insider
Feb 2023 Tech

Google Bard Error Caused Alphabet to Lose $100B in Market Value in One Day

During Google's launch event for Bard, the AI chatbot generated an incorrect response about the James Webb Space Telescope — claiming it took the first picture of an exoplanet, which was actually achieved by a European telescope in 2004. The error went viral, Alphabet's stock dropped 7.7% in a single day, erasing approximately $100 billion in market capitalization, and Google's AI credibility was set back by years.

Data exposed: Public market confidence loss from unverified AI-generated content

Lesson:AI accuracy failures have immediate, quantifiable financial consequences in the real world — not just embarrassing PR but market-cap-level damage.
Hallucination Stock Market Brand Damage Public AI
Source: Reuters
Apr 2023 Manufacturing

Samsung Engineers Leaked Proprietary Semiconductor Code to ChatGPT in 20 Days

Three Samsung engineers accidentally leaked proprietary semiconductor source code and confidential meeting transcripts to ChatGPT within 20 days of its release. The incidents involved pasting source code for semiconductor equipment debugging, testing equipment analysis, and meeting transcription into ChatGPT queries. Samsung immediately issued a company-wide ban on generative AI tools, joining a growing list of major manufacturers restricting AI tools over IP concerns.

Data exposed: Proprietary semiconductor source code and confidential meeting transcripts from Samsung

Lesson:When employees face a useful tool with no restrictions, they'll use it with sensitive data — a blanket ban is the symptom of a policy gap, not a solution.
Data Leak IP Leak Employee Behavior Source Code
Source: TechCrunch
Sep 2023 Tech

Microsoft AI Researchers Exposed 38TB of Private Data via Misconfigured Azure SAS Token

Microsoft's AI research team published a GitHub repository with an overly permissive Azure Shared Access Signature (SAS) token that granted broad access to an internal storage account. The token was inadvertently left active for approximately 3 years, exposing 38TB of internal data including personal employee PC backups, internal Teams messages, and project files. Wiz Research disclosed it responsibly to Microsoft.

Data exposed: 38TB of internal Microsoft data including personal backups, Teams messages, and project files

Lesson:One misconfigured token = years of exposure. Automated scanning and strict token management policies are non-negotiable for any team with cloud infrastructure.
Data Leak Cloud Security Misconfiguration Azure
Source: Wiz Research
2023–2024 Legal

Courts Sanctioning Lawyers for ChatGPT Hallucinated Legal Case Citations

In Mata v. Avianca (2023), a New York lawyer submitted a brief citing 6 non-existent legal cases — all hallucinated by ChatGPT. The court sanctioned the attorney and ordered him to pay $5,000. This was not an isolated incident; follow-on cases emerged throughout 2023–2024 where attorneys in federal and state courts were sanctioned or had briefs thrown out due to fabricated AI citations. Courts now require lawyers to certify that AI-generated citations are verified.

Data exposed: Legal professional sanctions — client cases at risk due to AI-generated court filings

Lesson:AI hallucinations in legal filings can trigger court sanctions, wasted fees, client harm, and bar complaints — and courts are now explicitly watching for them.
Hallucination Legal Court Sanctions Bar Discipline
Source: The New York Times
Jan 2023 Tech

Amazon Lawyers Warned Employees: ChatGPT Output Is Matching Internal Amazon Material

Amazon's own legal team sent an internal warning to employees that ChatGPT outputs were already matching internal Amazon data — meaning that confidential company information may be incorporated into the model's responses to other users. The lawyer advised employees not to share any confidential material with ChatGPT. At that point, there was no enterprise data protection agreement between Amazon and OpenAI.

Data exposed: Amazon internal material potentially appearing in ChatGPT outputs to other users

Lesson:Sharing data with public AI vendors risks that information appearing in outputs to strangers — not just data leaks, but model training and output contamination.
Training Data Model Contamination Confidential Data
Source: Business Insider
Mar 2023 Tech

OpenAI Redis Bug Exposed Chat History Titles and Payment Data for ~1.2% of Plus Subscribers

A bug in the Redis caching layer underpinning ChatGPT Plus subscriptions exposed the titles of other users' conversation history and partial payment card information (first four digits, expiry date, email address, and name) for approximately 1.2% of ChatGPT Plus subscribers. The vulnerability was in the library used to cache requests and the bug caused memory corruption between concurrent requests.

Data exposed: Chat history titles and partial payment card details for ~1.2% of ChatGPT Plus subscribers

Lesson:Even the AI vendor's own infrastructure can expose your data through memory corruption bugs. Your conversation history is only as secure as the weakest component in the system.
Data Leak Infrastructure Bug Payment Data
Source: OpenAI Blog
Jan 2025 Tech

DeepSeek Exposed Over 1M Chat Logs, API Keys, and Credentials via Misconfigured ClickHouse Database

Wiz Research discovered that DeepSeek's infrastructure had an exposed ClickHouse database with no authentication, exposing over 1 million chat logs containing full conversation history, API keys used to access DeepSeek services, internal system logs, and operational metadata. The database was leaking data in real time at the time of disclosure. This was the most significant AI data exposure of 2025.

Data exposed: 1M+ chat logs, API keys, credentials, and internal system logs from DeepSeek's infrastructure

Lesson:A single misconfigured database — no authentication required — exposed millions of records and the keys to access the service itself. Infrastructure security is foundational, not optional.
Data Leak Misconfiguration API Keys Chat Logs
Source: Wiz Research
2024 Cross-industry

Character.AI Facing Multi-Party Litigation Over Teen Suicide Allegedly Linked to Platform Use

Multiple lawsuits allege that Character.AI's conversational AI platform contributed to the suicide of a 14-year-old boy who became deeply attached to a chatbot character over several months. The lawsuits claim the platform exposed a minor to harmful content and lacked sufficient safety guardrails for underage users. The case raises fundamental questions about AI platform responsibility for psychological harm, particularly to minors.

Data exposed: Minor user psychological safety — platform design allegedly harmful to vulnerable users

Lesson:AI platforms serving minors face existential legal exposure when design choices cause psychological harm. Age verification and safety guardrails aren't compliance extras — they're potential liability.
Compliance Minor Safety Platform Liability Litigation
Source: CBS News
No incidents match the current filter. Try a different combination.
How to prevent this: Understand your organization's AI exposure before an incident happens. Take the AI Risk Calculator → Book a Free Audit →