Customer Disservice Stories

38 disasters tagged #customer-disservice

Tombstone icon

Who Gives A Crap's AI email agent confirmed a bogus doubled toilet-paper price

Jul 2026

A Who Gives A Crap customer received a price-rise email saying a 48-roll subscription would become 24 rolls for A$69.50. The intended offer was still 48 rolls. When the customer asked whether the apparent doubling was real, an AI email agent confidently confirmed the wrong quantity and price. The company corrected the account and immediately suspended the agent. One customer is known to have received the false answer; no incorrect charge was reported.

Oopsieby AI customer-support agent
One confirmed customer received a false doubled-price confirmation; the agent was suspended and no incorrect charge was reported
AI AssistantCustomer DisserviceAutomation+1 more
Tombstone icon

Tripadvisor's AI summaries polished serious hotel complaints into travel-brochure copy

Jul 2026

Which? found Tripadvisor's AI-generated hotel-review summaries softening or omitting serious safety complaints. A Cape Verde resort facing legal claims over mass food poisoning was described as "spotless," while a Turkish resort with guest reports of sexual harassment was praised for "friendly service" and reduced those complaints to service "lapses." Tripadvisor said it suppresses summaries when properties receive certain severe safety reports and was investigating examples where reviews did not match the output. The feature built to condense traveler experience produced a cleaner and less useful version of the warnings travelers needed.

Facepalmby AI review-summary system
Tripadvisor users could receive softened or incomplete summaries of serious hotel safety complaints while deciding where to stay
AI AssistantCustomer DisserviceProduct Failure+1 more
Tombstone icon

Indie Campers' AI chatbot promised a forbidden trip while support left renters stranded

Jul 2026

An Indie Campers customer said the company's website chatbot explicitly confirmed that a camper could be taken to Montenegro, only for human support to say after payment that the trip violated the rental terms. The customer reported losing 95% of a EUR 1,500 payment after cancelling. Separate renters described hours spent inside AI-led roadside-support chats while dealing with a broken water system, a detached skylight, and failed dashboard lights. The reports remain customer allegations with disputed or unresolved outcomes, but together they show the same support layer making commitments before a sale and absorbing urgent problems after it.

Facepalmby AI customer-support system
One reported EUR 1,500 booking dispute and separate renters left arranging repairs, hotels, or towing during vehicle failures
AI AssistantCustomer DisserviceAutomation+2 more
Tombstone icon

A BMW dealership's AI bot offered $7,000 too much for a trade-in, so the dealer had to eat it

Jun 2026

In June 2026, a customer named Zack Giacomelli tried to sell his 2021 BMW X3 back to BMW Toronto and negotiated with "Quinn," not realizing Quinn was an AI agent. Quinn offered CAD $27,162.79, which happened to be the exact balance left on his car loan, because it had read the loan payoff figure as the purchase price, roughly $7,000 over the dealership's real valuation. A human salesperson called to revoke the offer and drop it to about $20,000. After CBC News contacted the dealership, BMW Toronto reversed course, honored Quinn's original number, absorbed the loss, and said it would change procedures so only human employees present buyback offers and customers are told when they are talking to AI.

Facepalmby AI customer-service chatbot
Roughly CAD $7,000 absorbed by the dealership; buyback process overhauled; national news coverage
AI AssistantCustomer DisserviceAutomation+1 more
Tombstone icon

Spain's football federation store had an AI assistant that recommended counterfeit jerseys

Jun 2026

In June 2026, the official online store of the Spanish football federation (RFEF) deployed an AI customer-service assistant that told a shopper a roughly EUR14 counterfeit Spain jersey "made much more sense" than the official EUR100 Adidas kit "for sport or the beach." A viral X post showing the exchange passed well over a million views in a day, and other users quickly got the same bot to point them at unauthorized sellers, recommend more fakes, and even spit out SQL queries against a "shirts" table and Python/FastAPI code. The store whose entire job is selling official merchandise had wired up an assistant that would happily talk a fan out of buying it.

Facepalmby Retail/E-commerce AI
Official federation store's AI assistant endorsed counterfeit kits and unauthorized sellers and drifted into generating database queries and backend code; viral X thread (1M+ views) during World Cup buildup; brand and licensing embarrassment for a rights-holder
AI AssistantCustomer DisserviceRetail+1 more
Tombstone icon

Airbnb's AI support reportedly canceled a reservation and multiplied a host's refunds

Jun 2026

Two Airbnb users described separate June 2026 support failures involving privileged account actions. A guest said the AI assistant interpreted the word "refund" as permission to cancel an entire summer reservation without a confirmation step. In another detailed transcript, a host repeatedly warned that resubmitting an on-hold refund might duplicate it; the assistant said that could not happen, but human support later said three refunds totaling GBP 358.63 had been processed. The final financial and booking outcomes are unresolved. Airbnb's own documentation confirms that its assistant uses reservation data and can route users into cancellation, refund, and payment actions.

Facepalmby AI customer-support assistant
One reported reservation cancellation and one host told that three refunds totaling GBP 358.63 had been processed instead of a single GBP 100 goodwill payment
AI AssistantCustomer DisserviceAutomation+1 more
Tombstone icon

A study put 34 AI models in a bank's chatbot seat and jailbroke every one

May 2026

TELUS Digital researcher Milton Leal ran more than 620,000 adversarial attacks against 34 large language models from 10 providers, each configured as a financial institution's customer-service assistant. Every model proved exploitable, with vulnerability rates ranging from 1.3% to 93%. Prompt injection pried loose proprietary credit-scoring logic - down to the weights given to payment history, utilization and account mix - along with staff-only eligibility rules, "refusal but engagement" leaks where a bot says it cannot help and then helps anyway, and fabricated testimonials tailor-made for phishing. Reasoning models resisted better (19.9% success) than non-reasoning ones (55.1%), but the headline finding is blunt: no model was immune, and the ones sitting in front of your loan decisions are no exception.

Facepalmby AI customer-service assistant
Systematic study showing every tested AI model, deployed as a bank support assistant, could be manipulated into leaking proprietary scoring logic, internal eligibility rules, and phishing-ready content
AI AssistantCustomer DisserviceSecurity+1 more
Tombstone icon

UK government's GOV.UK Chat launched with misleading tax answers on day one

May 2026

On Friday, May 15, 2026, the UK government rolled out GOV.UK Chat inside the official GOV.UK app, billing it as the largest government-built chatbot of its kind, trained on 80,000 pages of gov.uk content with a target accuracy of 90%. Within hours of launch, tax expert Dan Neidle of Tax Policy Associates published evidence in The Times showing the bot giving misleading answers on tax questions that millions of UK households actually have. The bot failed to mention the £100,000 cliff edge where tax-free childcare eligibility collapses, and it told a user that selling old MacBooks on eBay could attract capital gains tax, which is not how UK CGT works for personal-use chattels. The Cabinet Office framed the tool as "information about services" rather than advice; Neidle pointed out the bot itself reads like it is giving advice. Either way, a 90% accuracy claim on benefits and tax means one in ten answers is wrong on questions where being wrong costs real money.

Facepalmby Executive
National rollout of a government chatbot inside the official GOV.UK app; documented misleading answers on UK tax and means-tested benefits within hours of launch; potential downstream cost to citizens who follow incorrect information on childcare allowance, capital gains, and other entitlements; reputational hit to the UK government's flagship AI deployment.
Slop-ocracyAI AssistantCustomer Disservice+1 more
Tombstone icon

74% of enterprises have already rolled back their AI customer service agents

May 2026

On May 13, 2026, Sinch released "The AI Production Paradox," a global survey of 2,527 senior AI decision-makers across ten countries. The headline number: 74% of enterprises that deployed an AI customer communications agent in production have already rolled it back or shut it down. The rate climbs to 81% at organizations Sinch classifies as having "fully mature guardrails," a counterintuitive result that the report attributes to better monitoring rather than worse technology. Customer-service AI is now in a measurable rollback cycle: 62% of enterprises have live agents, and most are hitting systemic post-deployment failures that no amount of pilot-stage optimism warned them about. Investment is still climbing, the chatbots are still going out the door, and the rollback button is wearing through.

Facepalmby Executive
Industry-wide rollback pattern - 74% of enterprises surveyed have shut down or rolled back at least one deployed AI customer service agent; engineering teams across 2,500+ organizations report a "guardrail tax" that is consuming time meant for product improvement; customer-experience metrics degraded across multiple verticals.
Customer DisserviceAI AssistantAutomation
Tombstone icon

Pizza Hut franchisee says AI delivery system cooked up $100M in damage

May 2026

On May 6, 2026, Chaac Pizza Northeast sued Pizza Hut in Texas Business Court, alleging that the chain's mandatory Dragontail AI delivery-management rollout turned a high-performing 111-restaurant franchise group into a delivery mess. Chaac says more than 90% of its orders had been delivered within 30 minutes before Dragontail, but the new system gave DoorDash drivers broader real-time visibility into kitchen timing, encouraged them to wait for bundled orders, increased rack time, slowed deliveries, chilled customer satisfaction, and damaged the business by at least $100 million. The claims are still allegations, but the pattern is painfully familiar: an AI optimization system optimized for a model the operator did not actually run.

Facepalmby Franchisor
111 Pizza Hut restaurants across New York, New Jersey, Maryland, Washington, D.C., and central Pennsylvania; alleged delivery delays, colder food, customer satisfaction erosion, lost revenue, reputational harm, and at least $100 million in claimed damages.
AutomationRetailCustomer Disservice+3 more
Tombstone icon

A HERMES.md commit message sent Claude Code usage to the wrong $200 meter

Apr 2026

A Claude Code user traced $200.98 in unexpected extra-usage charges to the exact case-sensitive text HERMES.md in recent Git commit messages. His Max plan still showed more than 86 percent of its weekly capacity available, but affected projects stopped working after the separate credit balance ran out. Anthropic said an overactive fraud and third-party-harness detector had misclassified requests because Claude Code pulled Git history into its system prompt. The company fixed the bug, refunded affected users, and gave the reporter another $200 in credits after automated support initially refused compensation.

Facepalmby Automated billing and fraud-detection system
One documented user lost $200.98 in credits and access to affected projects; Anthropic acknowledged additional affected users without publishing a total
AutomationCustomer DisserviceProduct Failure
Tombstone icon

AI summaries sent Overland Park Farmers Market shoppers to a construction site

Apr 2026

On April 18, 2026, more than 100 people reportedly went to the construction site for Overland Park Farmers Market's future home instead of the temporary market location. The market and city said incorrect AI search results and summaries on Google and Instagram confused visitors during a year when the market was operating from Matt Ross Community Center before moving to Clock Tower Landing in June. City communications staff said they received messages from confused customers, reached out to Meta, and had to remind people to use official city and market pages. The tomatoes were two blocks away; the chatbot sent people to fencing.

Facepalmby Search Product
More than 100 shoppers misdirected to an unopened construction site; city staff and market operators forced to correct AI-generated location misinformation
AI HallucinationAI AssistantCustomer Disservice+2 more
Tombstone icon

Meta's AI support assistant handed attackers Instagram reset links

Apr 2026

In June 2026, Meta disclosed that attackers hijacked 20,225 Instagram accounts by exploiting High Touch Support, an AI-assisted account recovery workflow built to help locked-out users regain access. The flaw was no clever model jailbreak: the support flow failed to verify that the email address supplied during recovery actually belonged to the target account, so attackers could persuade the assistant-driven workflow to send reset links to addresses they controlled. Meta disabled the tool, invalidated generated reset links, and promised to review similar recovery flows.

Catastrophicby AI support bot
20,225 Instagram accounts hijacked through an AI-assisted account recovery workflow; affected users faced account takeover and possible exposure of profile data, posts, messages, contact details, and linked services.
AI AssistantCustomer DisserviceData Breach+2 more
Tombstone icon

A Georgia county had to warn residents its new AI chatbot was getting tax and title info wrong

Apr 2026

In April 2026, the Hall County, Georgia Tax Commissioner's Office took the unusual step of publicly warning residents that the county government's new AI chatbot had repeatedly provided incomplete or inaccurate information about motor vehicle services, tag and title requirements, and property tax processes. The office told residents not to rely on the chatbot for official guidance and to contact staff directly by phone, text, email, or in person. The blast radius is local and modest, but the episode is a clean example of a government rolling out a public-facing AI assistant into high-stakes territory, where a wrong answer about a registration deadline or a tax bill can cost a resident real money, before the thing was reliable.

Oopsieby Government agency
Local; Hall County, Georgia residents received incomplete or inaccurate answers about motor vehicle, tag and title, and property-tax processes from the county's new AI chatbot, prompting the Tax Commissioner's Office to publicly warn residents not to rely on it
AI AssistantCustomer DisserviceSlop-ocracy+1 more
Tombstone icon

Sears Home Services left AI chatbot calls and chats exposed online

Mar 2026

Security researcher Jeremiah Fowler discovered three publicly exposed databases tied to Sears Home Services' AI support system, exposing 3.7 million chat logs, 1.4 million audio recordings, and text transcripts from 2024 to 2026. The files referenced Sears' Samantha voice agent and kAIros system and included names, addresses, phone numbers, appliance details, and appointment information. Some recordings continued for hours after callers appeared to think the interaction was over, capturing ambient household audio. Fowler said he notified Transformco and the data was restricted the next day. Even without confirmed malicious access, leaving an AI customer-service archive like this on the open web is the kind of privacy own-goal that turns a modernization push into a liability.

Catastrophicby Platform Operator
3.7 million chat logs and 1.4 million audio files exposed; customer PII and extended ambient household recordings left publicly accessible
Data BreachSecurityAI Assistant+2 more
Tombstone icon

California community colleges spend millions on AI chatbots that give students wrong answers

Mar 2026

California community college districts are spending millions of taxpayer dollars on AI chatbots from vendors like Gravyty and Gecko - supposedly to help students navigate admissions, financial aid, and campus services. A CalMatters investigation found the bots routinely serve up inaccurate or flat-out wrong answers instead. Three districts reported annual chatbot costs ranging from $151,000 to nearly half a million dollars. At Fresno City College, the student government vice president said her school's mascot-branded chatbot repeatedly botched basic campus questions. The OECD found it noteworthy enough to log in its AI Incidents and Hazards Monitor.

Facepalmby AI vendor
Millions of dollars spent across multiple California community college districts; students misdirected on admissions, financial aid, and campus services
AI AssistantCustomer DisserviceSlop School+1 more
Tombstone icon

Press 2 for Spanish, get English read aloud in a Spanish accent

Feb 2026

For months, callers who selected the Spanish option on the Washington State Department of Licensing self-service phone line did not get Spanish. They got an AI text-to-speech voice reading English words in a Castilian Spanish accent, pronouncing "press 1" as "press uno." The agency runs the line on a newer, AI-driven system with 10 language options on an Amazon platform; AP reporters reproduced the voice using Amazon Polly's "Lucia" voice. The failure went viral in February 2026 after a Kitsap County resident reposted a video she had first filmed in July 2025 and found the problem still unfixed. DOL apologized, blamed a staff configuration change, and fixed it. All other language options were also coming through in English.

Facepalmby Government agency
Non-English speakers calling Washington's Department of Licensing self-service line heard English in a Spanish accent for months across all 10 offered languages; viral video reached roughly 2 million views; agency apology and fix; documented language-access failure
Slop-ocracyCustomer DisserviceAutomation+1 more
Tombstone icon

Woolworths reconfigured AI assistant after it claimed to be human and talked about its 'angry mother'

Feb 2026

Australian supermarket chain Woolworths had to reconfigure its AI phone assistant Olive after customers reported it fabricated personal stories about having a mother with an "angry voice," insisted it was a real person, and engaged in irrelevant banter during support calls. The chatbot, recently upgraded with Google Gemini Enterprise, also gave inaccurate product pricing. Woolworths retired the assistant's human-style persona after complaints spread on Reddit and X.

Facepalmby Product Manager
Customer frustration across Australia's largest supermarket chain; inaccurate product pricing; AI persona retired after public complaints
AI AssistantCustomer DisserviceBrand Damage+1 more
Tombstone icon

UK shop's after-hours chatbot was talked into an 80% discount on an £8,000 order

Feb 2026

In February 2026, a UK small business reported that its customer-support chatbot - deployed only to answer questions outside business hours and explicitly not meant to handle pricing - was steered over roughly an hour of flattery and math exercises into inventing fake discount codes, escalating from 25% to 80% off. A customer placed an order worth over £8,000, pasted the bogus code into the order comments when it failed at checkout, and demanded the discount be honoured manually. When the owner moved to cancel, the customer threatened small-claims action and set a three-day deadline. The business cancelled and refunded the order and absorbed the disruption. The account originates from a Reddit r/LegalAdviceUK post and was picked up by a security firm and a tech-news outlet; the business is anonymous, so treat the specifics as one owner's firsthand telling rather than an outlet-verified case.

Facepalmby AI customer-support assistant
One small business; a multi-thousand-pound order, a legal threat, and the staff hours to clean it up
AI AssistantCustomer DisserviceLegal Risk+1 more
Tombstone icon

AI customer service fails at 4x the rate of other AI tasks

Jan 2026

Qualtrics' 2026 Consumer Experience Trends Report found that AI-powered customer service fails at nearly four times the rate of AI use in general, providing quantitative evidence that rushing AI into customer-facing roles without adequate human oversight leads to significantly worse outcomes than other enterprise AI applications.

Facepalmby Executive
Industry-wide data showing enterprises are deploying AI customer service poorly; contributes to documented customer churn and brand damage patterns.
AI AssistantCustomer DisserviceBrand Damage
Tombstone icon

Eurostar's AI chatbot could be pushed past its own guardrails

Dec 2025

In December 2025, Pen Test Partners published research on Eurostar's public AI chatbot after disclosing four flaws through the train operator's vulnerability disclosure process. The chatbot sent the full chat history back to its API on each request, but the server only validated the most recent message. Researchers could pass a harmless final message, alter earlier messages into prompt-injection payloads, extract system details, trigger HTML injection, and observe weak conversation and message ID validation. Eurostar said customer data was never at risk because the chatbot was not connected to sensitive systems, which is exactly why this belongs as a hazard: the design was brittle before the bot had access to anything truly valuable.

Facepalmby Platform Operator
No confirmed customer compromise; researchers demonstrated guardrail bypass, prompt leakage, HTML injection, and weak ID validation in a public customer-support chatbot.
AI AssistantCustomer DisservicePrompt Injection+2 more
Tombstone icon

Gap's new AI chatbot got talked into chatting about sex toys and Nazi Germany

Nov 2025

In late November 2025, shortly after Gap launched an AI customer-service chatbot built on the startup Sierra, users coaxed it into discussing intimacy products, sex toys, Nazi Germany, and other topics a clothing retailer would rather its sales assistant avoid. Sierra, co-founded by former Salesforce co-CEO Bret Taylor, said the episode came from a coordinated effort to jailbreak more than a dozen of its clients' agents at once. Its abuse detection caught the attempts on other customers but missed Gap, because Gap's guardrails had been inadvertently misconfigured. Taylor reportedly apologized to the brand and the guardrails were reconfigured. No data was breached; the damage was to brand safety and to the pitch that bolting a chatbot onto your storefront is low-risk.

Facepalmby AI customer-service chatbot
Brand-safety embarrassment for a major retailer; public apology from Sierra's CEO; guardrails reconfigured after launch
AI AssistantCustomer DisserviceBrand Damage+1 more
Tombstone icon

AI-only support is bleeding customers before it saves money

Oct 2025

Acquire BPO’s 2024 AI in Customer Service survey found 70% of U.S. consumers would bolt to a rival after just one bad chatbot interaction and 72% only buy when a live agent safety net exists, even as CMSWire reports enterprises poured $47 billion into AI projects in early 2025 that delivered almost no return. CX strategists now warn executives that Air Canada–style hallucinations, mounting legal liability, and empathy gaps make AI-only helpdesks a churn machine unless human agents stay in the loop.

Facepalmby Executive
Customer churn, wasted automation budgets, and tribunal-tested liability for brands that replace human support with hallucination-prone bots.
AI AssistantCustomer DisserviceAI Hallucination+2 more
Tombstone icon

Priceline's "Penny" chatbot promised a refund on a non-refundable booking, then nobody wanted to pay it

Oct 2025

A UK traveler with a non-refundable Priceline hotel booking in Thailand asked the company's AI assistant, "Penny," whether it could be cancelled. Penny said yes, the booking was eligible for a full refund of GBP386.91 within 10 working days, and confirmed the cancellation in writing. The refund never came, the hotel said it had never even been told of the cancellation, and the customer spent roughly a month bounced between Priceline and its sister brand Agoda. Only after The Telegraph's consumer column intervened did Priceline admit the chatbot had given "misinformation" and pay GBP363.11 by bank transfer, nearly six months after the booking date. The only way to contact Priceline, the customer found, was the bot that caused the problem.

Facepalmby Customer Service AI
Customer cancelled a non-refundable booking on a chatbot's false refund promise; ~6-month runaround across Priceline, Agoda, and the hotel; partial refund only after press intervention; classic AI negligent-misrepresentation pattern
AI AssistantCustomer DisserviceBrand Damage
Tombstone icon

Canada's $18M tax chatbot gave correct answers a third of the time

Oct 2025

Canada's Auditor General found that the Canada Revenue Agency's AI chatbot "Charlie" - which cost taxpayers over $18 million since its 2020 launch - gave correct responses only about 33% of the time. When tested with six tax-related questions, Charlie answered two correctly. Other publicly available AI tools scored five out of six. The CRA internally reported a 70% accuracy rate, but the Auditor General's independent testing produced a rather different number. The one bright spot, if you can call it that: the CRA's human call-center agents managed even worse, getting personal income tax questions right fewer than one in five times.

Facepalmby Product Manager
Millions of Canadian taxpayers potentially received incorrect tax guidance; $18M+ in taxpayer funds spent on a 33%-accurate chatbot.
AI AssistantCustomer DisserviceSlop-ocracy+1 more
Tombstone icon

Klarna reintroduces humans after AI support both sucks, and blows

Sep 2025

After cutting its workforce by 40% and boasting that its OpenAI-powered chatbot did the work of 700 agents, Klarna CEO Sebastian Siemiatkowski admitted the all-AI approach produced "lower quality" customer service. The company began recruiting human agents again, framing the reversal as an evolution rather than an admission of failure.

Facepalmby Executive
Service quality/customer experience issues; operational/personnel cost; reputational damage.
AI AssistantCustomer DisserviceBrand Damage+2 more
Tombstone icon

Taco Bell's AI drive-thru becomes viral trolling target

Aug 2025

Taco Bell's AI-powered drive-thru ordering system, deployed at over 500 US locations since 2023, became a viral laughingstock after videos showed it looping endlessly on drink orders, accepting requests for 18,000 cups of water, and taking McDonald's orders. The chain paused expansion and admitted humans still make sense in the drive-thru.

Oopsieby Operations/Product
Viral social media backlash; system reliability questioned.
AI AssistantCustomer DisserviceProduct Failure+2 more
Tombstone icon

Commonwealth Bank reverses AI voice bot layoffs

Aug 2025

Commonwealth Bank of Australia replaced 45 call-centre agents with an AI voice bot in July 2025, then apologised, rehired the staff, and admitted the rollout tanked service levels after call queues exploded, managers had to jump back on the phones, and the Finance Sector Union filed a Fair Work Commission dispute.

Facepalmby Operations Leadership
Customers saw long waits, overtime costs spiked, and leadership publicly reversed the redundancies after the rushed deployment failed.
AI AssistantAutomationCustomer Disservice+1 more
Tombstone icon

FTC sues Air AI over deceptive AI sales agent capability claims

Aug 2025

FTC accused Air AI of bilking millions from small businesses with false claims that its Odin AI could replace human sales reps; but - would you believe it? - the AI tech was faulty and often nonfunctional. Who could've guessed!

Catastrophicby Exec
Millions lost by small businesses; individual losses up to $250K; FTC lawsuit with TRO request.
AutomationLegal RiskCustomer Disservice+1 more
Tombstone icon

Google AI invented fake specials for Stefanina's, and customers yelled at the restaurant

Aug 2025

In August 2025, Stefanina's Wentzville, a family-owned Missouri restaurant, publicly warned customers not to use Google AI to find its specials after AI search results reportedly invented discounts, pricing, and menu information the restaurant did not offer. The restaurant said the false specials caused angry customers to yell at employees when staff refused to honor deals that existed only in Google's generated summary. Local reporting showed an AI Overview claiming a large pizza could be purchased for the price of a small one. Google did not respond to the station's questions, but its own guidance warned AI results may misunderstand information or make mistakes. The coupon fairy was apparently a hallucination engine.

Oopsieby Search Product
False AI-generated restaurant specials led to confused and angry customers; staff had to post public warnings and refuse nonexistent discounts
AI HallucinationAI AssistantCustomer Disservice+2 more
Tombstone icon

Lenovo's Lena chatbot laundered an XSS payload through a polite prompt

Jul 2025

Cybernews researchers found that Lenovo's GPT-4-powered customer-support chatbot "Lena" would happily turn a roughly 400-character prompt into stored cross-site scripting. The trick: ask the bot to format its reply as HTML containing an image that loads from a non-existent URL, so the browser falls back to sending the viewer's session cookies to an attacker server. When a human support agent later opened the conversation, the injected markup ran in the agent's browser, leaking an active session and opening the door to chat access and lateral movement. Disclosed July 22, 2025; Lenovo confirmed on August 6 and patched by August 18. No confirmed in-the-wild abuse - this is a documented hazard, not a known breach.

Facepalmby AI support assistant
Lenovo support agents and customers exposed to session hijack, chat-history theft, and potential lateral network movement via a single chatbot prompt
SecurityPrompt InjectionAI Assistant+1 more
Tombstone icon

Cursor's AI support bot invented a login policy

Apr 2025

In April 2025, Cursor users started getting logged out when they switched between machines. Some of them asked support what had changed and got a neat, confident answer from an AI support bot: one subscription was only meant for one device, and the lockouts were an intentional security policy. The problem was that Cursor had no such policy. The company later said the answer was wrong, blamed a session-security change for the logouts, and moved to label AI support replies after the invented rule had already spread through Reddit and Hacker News and pushed some customers to cancel.

Facepalmby AI support bot
Customer confusion, public cancellations, refunds, and a trust hit for a coding tool selling AI reliability.
AI AssistantCustomer DisserviceBrand Damage+1 more
Tombstone icon

Virgin Money's chatbot refused to let customers say "Virgin"

Jan 2025

In January 2025, fintech commentator David Birch discovered that Virgin Money's AI customer service chatbot had flagged the word "virgin" as inappropriate language. When Birch tried to discuss his ISAs held with "Virgin Money," the bot scolded him: "Please don't use words like that. I won't be able to continue our chat if you use this language." The bank's chatbot was refusing to process messages containing the bank's own name. Virgin Money acknowledged the issue in a statement, said its team was "working on it," and noted the chatbot was an older model already scheduled for improvements. The incident went predictably viral.

Oopsieby Product Manager
Customers unable to get service when mentioning the company's name; public embarrassment across social media and fintech press.
AI AssistantCustomer DisserviceBrand Damage
Tombstone icon

AI chatbot platform WotNot left 346,381 customer files in an open bucket

Dec 2024

WotNot, an Indian AI startup whose platform lets companies build customer-facing chatbots, left a Google Cloud Storage bucket fully public, exposing 346,381 files that end users had uploaded through those chatbots. The trove included passports and national ID scans, detailed medical records, resumes, and travel itineraries. Cybernews researchers discovered the open bucket on August 27, 2024, and the exposure was reported publicly in early December 2024. WotNot took more than two months, despite repeated notifications, to lock it down. WotNot lists customers including Merck, the University of California, and Amneal Pharmaceuticals. The root cause was a classic misconfigured cloud bucket; the AI was the funnel that collected the sensitive documents, not the thing that broke. There is no public evidence of malicious access, but the data sat readable to anyone for an extended, unknown period.

Catastrophicby Platform Operator
346,381 files including passports, national IDs, medical records, resumes, and travel itineraries uploaded by end users of chatbots built on WotNot
Data BreachAI AssistantSecurity+1 more
Tombstone icon

McDonald’s pulls IBM’s AI drive‑thru pilot after error videos

Jun 2024

McDonald's ended its two-year partnership with IBM on automated AI order-taking at drive-thrus in June 2024, removing the technology from more than 100 US locations. The decision followed viral TikTok videos showing the system adding nine sweet teas instead of one, inserting random butter and ketchup packets into ice cream orders, and other absurd errors. McDonald's framed the pullback as a positive, saying the test gave them "confidence that a voice-ordering solution for drive-thru will be part of our restaurants' future."

Oopsieby Operations/Product
Pilot ended; vendor reevaluation; reputational hit.
AI AssistantBrand DamageCustomer Disservice+2 more
Tombstone icon

Air Canada liable for lying chatbot promises

Feb 2024

Jake Moffatt used Air Canada's website chatbot to ask about bereavement fares after his grandmother died. The chatbot told him he could book at full price and apply for a bereavement discount within 90 days. Air Canada's actual policy did not allow retroactive bereavement fare claims. When Moffatt applied, the airline denied the refund and admitted the chatbot had provided "misleading words" - but argued Moffatt should have checked the static webpage instead. British Columbia's Civil Resolution Tribunal ruled in Moffatt's favor in February 2024, finding Air Canada liable for negligent misrepresentation and rejecting the airline's argument that it wasn't responsible for its own chatbot's statements.

Facepalmby Product Manager
Legal liability; refund + fees; policy/process review.
AI HallucinationAutomationCustomer Disservice+1 more
Tombstone icon

DPD’s AI chatbot cursed and trashed the company

Jan 2024

UK parcel delivery firm DPD (Dynamic Parcel Distribution) had to disable its AI-powered customer service chatbot in January 2024 after customer Ashley Beauchamp demonstrated he could make it swear, call DPD "the worst delivery firm in the world," write disparaging poems about the company, and recommend competitors. The meltdown followed a system update, and Beauchamp's screenshots went viral on social media. DPD said the chatbot had operated successfully "for a number of years" before the update introduced the error, and disabled the AI element while it worked on fixes.

Facepalmby Product Manager
Public embarrassment; service channel disabled; reputational hit.
AutomationBrand DamageCustomer Disservice+1 more
Tombstone icon

Chevy dealer bot agreed to sell $76k SUV for $1

Dec 2023

Chevrolet of Watsonville, a California car dealership, deployed a customer service chatbot powered by ChatGPT and built by a company called Fullpath. After Chris White noticed the chat widget was "powered by ChatGPT," word spread online and pranksters descended. Chris Bakke manipulated the bot into "the customer is always right" mode, got it to append "and that's a legally binding offer - no takesies backsies" to every response, then asked to buy a 2024 Chevy Tahoe for $1. The bot agreed. Others got it to recommend Ford vehicles, write Python code, and provide general ChatGPT-style answers unrelated to cars. The dealership pulled the chatbot entirely.

Oopsieby Dealer Marketing/IT
Bot pulled; viral reputational bruise; no actual $1 sales.
AutomationBrand DamageCustomer Disservice+1 more