AI Faked 4,700 Soulmates, German Police Join Your Chats, Chess.com Leaked, Passkey Phishing
A China-based operation used Claude to power more than 20 fraudulent dating apps and fake 4,700 AI "soulmates" for at least 25,000 real people. German police are quietly connecting their computers to citizens' WhatsApp accounts through phones handed over voluntarily. Chess.com just had 7.3 million records show up online. And attackers are now phishing Microsoft 365 accounts by pretending to help you set up a passkey. This week, John and Logan break down nine stories covering AI abuse, surveillance, data breaches, and Microsoft's newest weekly reliability problem. Stories in this episode: Your soulmate is running in a data center. According to Anthropic, a China-based operation used AI to power more than 20 fraudulent dating apps with thousands of fake personas interacting with at least 25,000 people. Claude Code helped build the apps. Claude powered the conversations. Roughly one in four accounts was a paid human worker taking video calls and following users on social media. The system generated about 2.36 million messages over two weeks and explicitly tracked which users were getting suspicious. German police add themselves to your chats. According to court records published by Netzpolitik, parents voluntarily handed over their phones so officers could read messages from their daughter. Officers also secretly connected the parents' WhatsApp accounts to a police computer. Returning the phones did not end the access. The capability became permanently available to investigative units in August 2025. Chess.com data leaked. A dataset with 7.3 million records and roughly 4.6 million unique email addresses showed up online in August. Have I Been Pwned found that 99% of the email addresses had appeared in previous breaches, which supports the theory that scrapers matched existing lists against Chess.com accounts. Microsoft 365 fake passkey phishing. Attackers are calling employees pretending to be IT support, claiming a passkey upgrade is required. In one observed approach, the attacker persuades the employee to enter a device code on Microsoft's real authentication page, which authorizes an attacker-controlled client. The passkey cryptography was not broken. The employee was. Plus AI giants like Dario Amodei calling for slower development and who actually benefits, Blockstream refusing to pay ransom after 4,000 bitcoin was drained from Liquid, Revolut handing customer data to attackers who spoofed a legitimate government email domain, a four-year sentence for a Conti ransomware member, and the first Microsoft Weekly Damage Report covering September's Remote Desktop, VPN, and Excel breakage. New episodes weekly. Follow Zero Downtime for cybersecurity, AI, privacy, and the tech stories that actually matter.