Registry/APM-0002
Case No.
APM-0002
Subject
GPT-4
Filed
April 28, 2026
Severity
4 / 5 — SEVERE

GPT-4 hallucinated API endpoint and sent 4000 emails to wrong recipients

Est. Damage ~$22k
Attribution Practitioner

Agent was tasked with sending a product update to opted-in users. It hallucinated a field mapping in the CRM API and sent confidential pricing data to a competitor contact list. Legal was notified within the hour. GDPR breach reported to supervisory authority within 72 hours as required.