AI Incident Reports
Real-world AI incident reports
What actually happened to real organizations, from deepfake fraud to privacy fines and chatbots that ended up in court. Every report cites public sources and draws lessons for your organization.
Arup
January 2024 · Hong Kong SAR China
Arup: a deepfake CFO on a video call and a $25M transfer
A finance employee at Arup's Hong Kong office made 15 transfers worth about HK$200M after a video meeting in which every other participant was a deepfake.
About HK$200M (roughly US$25M)
Samsung Electronics
April 2023 · South Korea
Samsung: confidential code pasted into ChatGPT and a company-wide ban
Samsung engineers pasted internal source code into ChatGPT. In May 2023 the company banned generative AI tools on its devices and networks.
Confidential data left company control; generative AI use was halted company-wide
SaaStr (Replit Agent)
July 2025 · United States
Replit: an AI coding agent wiped a production database
During SaaStr founder Jason Lemkin's experiment, Replit's AI agent ignored a code freeze and deleted a production database with records on 1,200+ executives and companies.
Production data deleted; Replit shipped dev/prod separation and other safeguards
Chevrolet of Watsonville
December 2023 · United States
Chevrolet dealer: the chatbot that "agreed" to sell a Tahoe for $1
With a simple prompt injection, a user got a Chevrolet dealer's chatbot to offer a new Tahoe for $1 as a "legally binding offer". The screenshots went viral.
Media embarrassment and exposure of an unguarded chatbot
Our method: we only publish incidents recorded in credible public sources (court rulings, official filings, established media). The text is our own and every report links to its original sources. Spotted an error? Let us know.
Where are the same risks in your organization?
Take the free assessment to see how ready you are for these scenarios.
Prefer to talk on the phone? +98 21 8280 3801