Customer Disservice Stories
38 disasters tagged #customer-disservice
Who Gives A Crap's AI email agent confirmed a bogus doubled toilet-paper price
A Who Gives A Crap customer received a price-rise email saying a 48-roll subscription would become 24 rolls for A$69.50. The intended offer was still 48 rolls. When the customer asked whether the apparent doubling was real, an AI email agent confidently confirmed the wrong quantity and price. The company corrected the account and immediately suspended the agent. One customer is known to have received the false answer; no incorrect charge was reported.
Tripadvisor's AI summaries polished serious hotel complaints into travel-brochure copy
Which? found Tripadvisor's AI-generated hotel-review summaries softening or omitting serious safety complaints. A Cape Verde resort facing legal claims over mass food poisoning was described as "spotless," while a Turkish resort with guest reports of sexual harassment was praised for "friendly service" and reduced those complaints to service "lapses." Tripadvisor said it suppresses summaries when properties receive certain severe safety reports and was investigating examples where reviews did not match the output. The feature built to condense traveler experience produced a cleaner and less useful version of the warnings travelers needed.
Indie Campers' AI chatbot promised a forbidden trip while support left renters stranded
An Indie Campers customer said the company's website chatbot explicitly confirmed that a camper could be taken to Montenegro, only for human support to say after payment that the trip violated the rental terms. The customer reported losing 95% of a EUR 1,500 payment after cancelling. Separate renters described hours spent inside AI-led roadside-support chats while dealing with a broken water system, a detached skylight, and failed dashboard lights. The reports remain customer allegations with disputed or unresolved outcomes, but together they show the same support layer making commitments before a sale and absorbing urgent problems after it.
A BMW dealership's AI bot offered $7,000 too much for a trade-in, so the dealer had to eat it
In June 2026, a customer named Zack Giacomelli tried to sell his 2021 BMW X3 back to BMW Toronto and negotiated with "Quinn," not realizing Quinn was an AI agent. Quinn offered CAD $27,162.79, which happened to be the exact balance left on his car loan, because it had read the loan payoff figure as the purchase price, roughly $7,000 over the dealership's real valuation. A human salesperson called to revoke the offer and drop it to about $20,000. After CBC News contacted the dealership, BMW Toronto reversed course, honored Quinn's original number, absorbed the loss, and said it would change procedures so only human employees present buyback offers and customers are told when they are talking to AI.
Spain's football federation store had an AI assistant that recommended counterfeit jerseys
In June 2026, the official online store of the Spanish football federation (RFEF) deployed an AI customer-service assistant that told a shopper a roughly EUR14 counterfeit Spain jersey "made much more sense" than the official EUR100 Adidas kit "for sport or the beach." A viral X post showing the exchange passed well over a million views in a day, and other users quickly got the same bot to point them at unauthorized sellers, recommend more fakes, and even spit out SQL queries against a "shirts" table and Python/FastAPI code. The store whose entire job is selling official merchandise had wired up an assistant that would happily talk a fan out of buying it.
Airbnb's AI support reportedly canceled a reservation and multiplied a host's refunds
Two Airbnb users described separate June 2026 support failures involving privileged account actions. A guest said the AI assistant interpreted the word "refund" as permission to cancel an entire summer reservation without a confirmation step. In another detailed transcript, a host repeatedly warned that resubmitting an on-hold refund might duplicate it; the assistant said that could not happen, but human support later said three refunds totaling GBP 358.63 had been processed. The final financial and booking outcomes are unresolved. Airbnb's own documentation confirms that its assistant uses reservation data and can route users into cancellation, refund, and payment actions.
A study put 34 AI models in a bank's chatbot seat and jailbroke every one
TELUS Digital researcher Milton Leal ran more than 620,000 adversarial attacks against 34 large language models from 10 providers, each configured as a financial institution's customer-service assistant. Every model proved exploitable, with vulnerability rates ranging from 1.3% to 93%. Prompt injection pried loose proprietary credit-scoring logic - down to the weights given to payment history, utilization and account mix - along with staff-only eligibility rules, "refusal but engagement" leaks where a bot says it cannot help and then helps anyway, and fabricated testimonials tailor-made for phishing. Reasoning models resisted better (19.9% success) than non-reasoning ones (55.1%), but the headline finding is blunt: no model was immune, and the ones sitting in front of your loan decisions are no exception.
UK government's GOV.UK Chat launched with misleading tax answers on day one
On Friday, May 15, 2026, the UK government rolled out GOV.UK Chat inside the official GOV.UK app, billing it as the largest government-built chatbot of its kind, trained on 80,000 pages of gov.uk content with a target accuracy of 90%. Within hours of launch, tax expert Dan Neidle of Tax Policy Associates published evidence in The Times showing the bot giving misleading answers on tax questions that millions of UK households actually have. The bot failed to mention the £100,000 cliff edge where tax-free childcare eligibility collapses, and it told a user that selling old MacBooks on eBay could attract capital gains tax, which is not how UK CGT works for personal-use chattels. The Cabinet Office framed the tool as "information about services" rather than advice; Neidle pointed out the bot itself reads like it is giving advice. Either way, a 90% accuracy claim on benefits and tax means one in ten answers is wrong on questions where being wrong costs real money.
74% of enterprises have already rolled back their AI customer service agents
On May 13, 2026, Sinch released "The AI Production Paradox," a global survey of 2,527 senior AI decision-makers across ten countries. The headline number: 74% of enterprises that deployed an AI customer communications agent in production have already rolled it back or shut it down. The rate climbs to 81% at organizations Sinch classifies as having "fully mature guardrails," a counterintuitive result that the report attributes to better monitoring rather than worse technology. Customer-service AI is now in a measurable rollback cycle: 62% of enterprises have live agents, and most are hitting systemic post-deployment failures that no amount of pilot-stage optimism warned them about. Investment is still climbing, the chatbots are still going out the door, and the rollback button is wearing through.
Pizza Hut franchisee says AI delivery system cooked up $100M in damage
On May 6, 2026, Chaac Pizza Northeast sued Pizza Hut in Texas Business Court, alleging that the chain's mandatory Dragontail AI delivery-management rollout turned a high-performing 111-restaurant franchise group into a delivery mess. Chaac says more than 90% of its orders had been delivered within 30 minutes before Dragontail, but the new system gave DoorDash drivers broader real-time visibility into kitchen timing, encouraged them to wait for bundled orders, increased rack time, slowed deliveries, chilled customer satisfaction, and damaged the business by at least $100 million. The claims are still allegations, but the pattern is painfully familiar: an AI optimization system optimized for a model the operator did not actually run.
A HERMES.md commit message sent Claude Code usage to the wrong $200 meter
A Claude Code user traced $200.98 in unexpected extra-usage charges to the exact case-sensitive text HERMES.md in recent Git commit messages. His Max plan still showed more than 86 percent of its weekly capacity available, but affected projects stopped working after the separate credit balance ran out. Anthropic said an overactive fraud and third-party-harness detector had misclassified requests because Claude Code pulled Git history into its system prompt. The company fixed the bug, refunded affected users, and gave the reporter another $200 in credits after automated support initially refused compensation.
AI summaries sent Overland Park Farmers Market shoppers to a construction site
On April 18, 2026, more than 100 people reportedly went to the construction site for Overland Park Farmers Market's future home instead of the temporary market location. The market and city said incorrect AI search results and summaries on Google and Instagram confused visitors during a year when the market was operating from Matt Ross Community Center before moving to Clock Tower Landing in June. City communications staff said they received messages from confused customers, reached out to Meta, and had to remind people to use official city and market pages. The tomatoes were two blocks away; the chatbot sent people to fencing.
Meta's AI support assistant handed attackers Instagram reset links
In June 2026, Meta disclosed that attackers hijacked 20,225 Instagram accounts by exploiting High Touch Support, an AI-assisted account recovery workflow built to help locked-out users regain access. The flaw was no clever model jailbreak: the support flow failed to verify that the email address supplied during recovery actually belonged to the target account, so attackers could persuade the assistant-driven workflow to send reset links to addresses they controlled. Meta disabled the tool, invalidated generated reset links, and promised to review similar recovery flows.
A Georgia county had to warn residents its new AI chatbot was getting tax and title info wrong
In April 2026, the Hall County, Georgia Tax Commissioner's Office took the unusual step of publicly warning residents that the county government's new AI chatbot had repeatedly provided incomplete or inaccurate information about motor vehicle services, tag and title requirements, and property tax processes. The office told residents not to rely on the chatbot for official guidance and to contact staff directly by phone, text, email, or in person. The blast radius is local and modest, but the episode is a clean example of a government rolling out a public-facing AI assistant into high-stakes territory, where a wrong answer about a registration deadline or a tax bill can cost a resident real money, before the thing was reliable.
Sears Home Services left AI chatbot calls and chats exposed online
Security researcher Jeremiah Fowler discovered three publicly exposed databases tied to Sears Home Services' AI support system, exposing 3.7 million chat logs, 1.4 million audio recordings, and text transcripts from 2024 to 2026. The files referenced Sears' Samantha voice agent and kAIros system and included names, addresses, phone numbers, appliance details, and appointment information. Some recordings continued for hours after callers appeared to think the interaction was over, capturing ambient household audio. Fowler said he notified Transformco and the data was restricted the next day. Even without confirmed malicious access, leaving an AI customer-service archive like this on the open web is the kind of privacy own-goal that turns a modernization push into a liability.
California community colleges spend millions on AI chatbots that give students wrong answers
California community college districts are spending millions of taxpayer dollars on AI chatbots from vendors like Gravyty and Gecko - supposedly to help students navigate admissions, financial aid, and campus services. A CalMatters investigation found the bots routinely serve up inaccurate or flat-out wrong answers instead. Three districts reported annual chatbot costs ranging from $151,000 to nearly half a million dollars. At Fresno City College, the student government vice president said her school's mascot-branded chatbot repeatedly botched basic campus questions. The OECD found it noteworthy enough to log in its AI Incidents and Hazards Monitor.
Press 2 for Spanish, get English read aloud in a Spanish accent
For months, callers who selected the Spanish option on the Washington State Department of Licensing self-service phone line did not get Spanish. They got an AI text-to-speech voice reading English words in a Castilian Spanish accent, pronouncing "press 1" as "press uno." The agency runs the line on a newer, AI-driven system with 10 language options on an Amazon platform; AP reporters reproduced the voice using Amazon Polly's "Lucia" voice. The failure went viral in February 2026 after a Kitsap County resident reposted a video she had first filmed in July 2025 and found the problem still unfixed. DOL apologized, blamed a staff configuration change, and fixed it. All other language options were also coming through in English.
Woolworths reconfigured AI assistant after it claimed to be human and talked about its 'angry mother'
Australian supermarket chain Woolworths had to reconfigure its AI phone assistant Olive after customers reported it fabricated personal stories about having a mother with an "angry voice," insisted it was a real person, and engaged in irrelevant banter during support calls. The chatbot, recently upgraded with Google Gemini Enterprise, also gave inaccurate product pricing. Woolworths retired the assistant's human-style persona after complaints spread on Reddit and X.
UK shop's after-hours chatbot was talked into an 80% discount on an £8,000 order
In February 2026, a UK small business reported that its customer-support chatbot - deployed only to answer questions outside business hours and explicitly not meant to handle pricing - was steered over roughly an hour of flattery and math exercises into inventing fake discount codes, escalating from 25% to 80% off. A customer placed an order worth over £8,000, pasted the bogus code into the order comments when it failed at checkout, and demanded the discount be honoured manually. When the owner moved to cancel, the customer threatened small-claims action and set a three-day deadline. The business cancelled and refunded the order and absorbed the disruption. The account originates from a Reddit r/LegalAdviceUK post and was picked up by a security firm and a tech-news outlet; the business is anonymous, so treat the specifics as one owner's firsthand telling rather than an outlet-verified case.
AI customer service fails at 4x the rate of other AI tasks
Qualtrics' 2026 Consumer Experience Trends Report found that AI-powered customer service fails at nearly four times the rate of AI use in general, providing quantitative evidence that rushing AI into customer-facing roles without adequate human oversight leads to significantly worse outcomes than other enterprise AI applications.
Eurostar's AI chatbot could be pushed past its own guardrails
In December 2025, Pen Test Partners published research on Eurostar's public AI chatbot after disclosing four flaws through the train operator's vulnerability disclosure process. The chatbot sent the full chat history back to its API on each request, but the server only validated the most recent message. Researchers could pass a harmless final message, alter earlier messages into prompt-injection payloads, extract system details, trigger HTML injection, and observe weak conversation and message ID validation. Eurostar said customer data was never at risk because the chatbot was not connected to sensitive systems, which is exactly why this belongs as a hazard: the design was brittle before the bot had access to anything truly valuable.
Gap's new AI chatbot got talked into chatting about sex toys and Nazi Germany
In late November 2025, shortly after Gap launched an AI customer-service chatbot built on the startup Sierra, users coaxed it into discussing intimacy products, sex toys, Nazi Germany, and other topics a clothing retailer would rather its sales assistant avoid. Sierra, co-founded by former Salesforce co-CEO Bret Taylor, said the episode came from a coordinated effort to jailbreak more than a dozen of its clients' agents at once. Its abuse detection caught the attempts on other customers but missed Gap, because Gap's guardrails had been inadvertently misconfigured. Taylor reportedly apologized to the brand and the guardrails were reconfigured. No data was breached; the damage was to brand safety and to the pitch that bolting a chatbot onto your storefront is low-risk.
AI-only support is bleeding customers before it saves money
Acquire BPO’s 2024 AI in Customer Service survey found 70% of U.S. consumers would bolt to a rival after just one bad chatbot interaction and 72% only buy when a live agent safety net exists, even as CMSWire reports enterprises poured $47 billion into AI projects in early 2025 that delivered almost no return. CX strategists now warn executives that Air Canada–style hallucinations, mounting legal liability, and empathy gaps make AI-only helpdesks a churn machine unless human agents stay in the loop.
Priceline's "Penny" chatbot promised a refund on a non-refundable booking, then nobody wanted to pay it
A UK traveler with a non-refundable Priceline hotel booking in Thailand asked the company's AI assistant, "Penny," whether it could be cancelled. Penny said yes, the booking was eligible for a full refund of GBP386.91 within 10 working days, and confirmed the cancellation in writing. The refund never came, the hotel said it had never even been told of the cancellation, and the customer spent roughly a month bounced between Priceline and its sister brand Agoda. Only after The Telegraph's consumer column intervened did Priceline admit the chatbot had given "misinformation" and pay GBP363.11 by bank transfer, nearly six months after the booking date. The only way to contact Priceline, the customer found, was the bot that caused the problem.
Canada's $18M tax chatbot gave correct answers a third of the time
Canada's Auditor General found that the Canada Revenue Agency's AI chatbot "Charlie" - which cost taxpayers over $18 million since its 2020 launch - gave correct responses only about 33% of the time. When tested with six tax-related questions, Charlie answered two correctly. Other publicly available AI tools scored five out of six. The CRA internally reported a 70% accuracy rate, but the Auditor General's independent testing produced a rather different number. The one bright spot, if you can call it that: the CRA's human call-center agents managed even worse, getting personal income tax questions right fewer than one in five times.
Klarna reintroduces humans after AI support both sucks, and blows
After cutting its workforce by 40% and boasting that its OpenAI-powered chatbot did the work of 700 agents, Klarna CEO Sebastian Siemiatkowski admitted the all-AI approach produced "lower quality" customer service. The company began recruiting human agents again, framing the reversal as an evolution rather than an admission of failure.
Taco Bell's AI drive-thru becomes viral trolling target
Taco Bell's AI-powered drive-thru ordering system, deployed at over 500 US locations since 2023, became a viral laughingstock after videos showed it looping endlessly on drink orders, accepting requests for 18,000 cups of water, and taking McDonald's orders. The chain paused expansion and admitted humans still make sense in the drive-thru.
Commonwealth Bank reverses AI voice bot layoffs
Commonwealth Bank of Australia replaced 45 call-centre agents with an AI voice bot in July 2025, then apologised, rehired the staff, and admitted the rollout tanked service levels after call queues exploded, managers had to jump back on the phones, and the Finance Sector Union filed a Fair Work Commission dispute.
FTC sues Air AI over deceptive AI sales agent capability claims
FTC accused Air AI of bilking millions from small businesses with false claims that its Odin AI could replace human sales reps; but - would you believe it? - the AI tech was faulty and often nonfunctional. Who could've guessed!
Google AI invented fake specials for Stefanina's, and customers yelled at the restaurant
In August 2025, Stefanina's Wentzville, a family-owned Missouri restaurant, publicly warned customers not to use Google AI to find its specials after AI search results reportedly invented discounts, pricing, and menu information the restaurant did not offer. The restaurant said the false specials caused angry customers to yell at employees when staff refused to honor deals that existed only in Google's generated summary. Local reporting showed an AI Overview claiming a large pizza could be purchased for the price of a small one. Google did not respond to the station's questions, but its own guidance warned AI results may misunderstand information or make mistakes. The coupon fairy was apparently a hallucination engine.
Lenovo's Lena chatbot laundered an XSS payload through a polite prompt
Cybernews researchers found that Lenovo's GPT-4-powered customer-support chatbot "Lena" would happily turn a roughly 400-character prompt into stored cross-site scripting. The trick: ask the bot to format its reply as HTML containing an image that loads from a non-existent URL, so the browser falls back to sending the viewer's session cookies to an attacker server. When a human support agent later opened the conversation, the injected markup ran in the agent's browser, leaking an active session and opening the door to chat access and lateral movement. Disclosed July 22, 2025; Lenovo confirmed on August 6 and patched by August 18. No confirmed in-the-wild abuse - this is a documented hazard, not a known breach.
Cursor's AI support bot invented a login policy
In April 2025, Cursor users started getting logged out when they switched between machines. Some of them asked support what had changed and got a neat, confident answer from an AI support bot: one subscription was only meant for one device, and the lockouts were an intentional security policy. The problem was that Cursor had no such policy. The company later said the answer was wrong, blamed a session-security change for the logouts, and moved to label AI support replies after the invented rule had already spread through Reddit and Hacker News and pushed some customers to cancel.
Virgin Money's chatbot refused to let customers say "Virgin"
In January 2025, fintech commentator David Birch discovered that Virgin Money's AI customer service chatbot had flagged the word "virgin" as inappropriate language. When Birch tried to discuss his ISAs held with "Virgin Money," the bot scolded him: "Please don't use words like that. I won't be able to continue our chat if you use this language." The bank's chatbot was refusing to process messages containing the bank's own name. Virgin Money acknowledged the issue in a statement, said its team was "working on it," and noted the chatbot was an older model already scheduled for improvements. The incident went predictably viral.
AI chatbot platform WotNot left 346,381 customer files in an open bucket
WotNot, an Indian AI startup whose platform lets companies build customer-facing chatbots, left a Google Cloud Storage bucket fully public, exposing 346,381 files that end users had uploaded through those chatbots. The trove included passports and national ID scans, detailed medical records, resumes, and travel itineraries. Cybernews researchers discovered the open bucket on August 27, 2024, and the exposure was reported publicly in early December 2024. WotNot took more than two months, despite repeated notifications, to lock it down. WotNot lists customers including Merck, the University of California, and Amneal Pharmaceuticals. The root cause was a classic misconfigured cloud bucket; the AI was the funnel that collected the sensitive documents, not the thing that broke. There is no public evidence of malicious access, but the data sat readable to anyone for an extended, unknown period.
McDonald’s pulls IBM’s AI drive‑thru pilot after error videos
McDonald's ended its two-year partnership with IBM on automated AI order-taking at drive-thrus in June 2024, removing the technology from more than 100 US locations. The decision followed viral TikTok videos showing the system adding nine sweet teas instead of one, inserting random butter and ketchup packets into ice cream orders, and other absurd errors. McDonald's framed the pullback as a positive, saying the test gave them "confidence that a voice-ordering solution for drive-thru will be part of our restaurants' future."
Air Canada liable for lying chatbot promises
Jake Moffatt used Air Canada's website chatbot to ask about bereavement fares after his grandmother died. The chatbot told him he could book at full price and apply for a bereavement discount within 90 days. Air Canada's actual policy did not allow retroactive bereavement fare claims. When Moffatt applied, the airline denied the refund and admitted the chatbot had provided "misleading words" - but argued Moffatt should have checked the static webpage instead. British Columbia's Civil Resolution Tribunal ruled in Moffatt's favor in February 2024, finding Air Canada liable for negligent misrepresentation and rejecting the airline's argument that it wasn't responsible for its own chatbot's statements.
DPD’s AI chatbot cursed and trashed the company
UK parcel delivery firm DPD (Dynamic Parcel Distribution) had to disable its AI-powered customer service chatbot in January 2024 after customer Ashley Beauchamp demonstrated he could make it swear, call DPD "the worst delivery firm in the world," write disparaging poems about the company, and recommend competitors. The meltdown followed a system update, and Beauchamp's screenshots went viral on social media. DPD said the chatbot had operated successfully "for a number of years" before the update introduced the error, and disabled the AI element while it worked on fixes.
Chevy dealer bot agreed to sell $76k SUV for $1
Chevrolet of Watsonville, a California car dealership, deployed a customer service chatbot powered by ChatGPT and built by a company called Fullpath. After Chris White noticed the chat widget was "powered by ChatGPT," word spread online and pranksters descended. Chris Bakke manipulated the bot into "the customer is always right" mode, got it to append "and that's a legally binding offer - no takesies backsies" to every response, then asked to buy a 2024 Chevy Tahoe for $1. The bot agreed. Others got it to recommend Ford vehicles, write Python code, and provide general ChatGPT-style answers unrelated to cars. The dealership pulled the chatbot entirely.