Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Editorial · CASRAI · Generative AI use and disclosure

ICLR 2026 Breach: Bribery, AI-Written Reviews

A Nov. 2025 OpenReview bug exposed ICLR 2026 reviewer identities, enabling bribery and harassment amid separate reports that 21% of reviews were AI-generated.

Published 29 Jul 2026· 7 minute read

Two distinct integrity failures converged around the ICLR 2026 review cycle: a security breach in the OpenReview platform that exposed anonymous reviewer identities and, by ICLR’s own account, was exploited by third parties to harass and attempt to bribe reviewers — and separate, independently reported analysis suggesting a substantial share of ICLR 2026 reviews were themselves fully AI-generated. The two problems are not the same story, but together they illustrate how fragile the infrastructure and norms of large-scale conference peer review have become under simultaneous pressure from automation and platform security gaps.

What happened: the OpenReview security incident

On 27 November 2025, ICLR’s organizers were notified of a vulnerability in the OpenReview API that allowed unauthorized access to data that is supposed to stay anonymous during review — the names of authors, reviewers, and area chairs linked to specific submissions. According to ICLR’s own public incident response, published on the ICLR blog, the exposure covered author, reviewer, and other identifying details for “over ten thousand” ICLR 2026 papers, roughly 45% of the conference’s submissions. OpenReview patched the underlying bug within about an hour of notification, but the scraped dataset had already begun circulating outside the platform; ICLR reports that publicly hosted copies of the data it was aware of were taken down by 1 December 2025.

The exposure struck directly at double-anonymized peer review and other forms of identity-protected review, where reviewer anonymity is a structural safeguard against retaliation and undue influence, not an incidental feature.

Harassment, bribery attempts, and collusion reports

ICLR’s incident write-up describes the exposure as having enabled misconduct beyond the data leak itself: the organizers report “third parties (neither authors nor reviewers) harassing, intimidating and offering bribes to multiple reviewers,” as well as receiving reports of possible collusion attempts between authors and reviewers who could now identify each other. Separately, on 28 November 2025, a commenter posted messages publicly identifying reviewers on roughly 600 papers.

A note on sourcing: the harassment, bribery, and collusion-attempt characterizations above are ICLR’s own account, published in its official incident response, and have been corroborated in outline by independent science-press coverage (e.g. Science magazine’s news desk). Neither ICLR’s post nor the press coverage identifies specific individuals, dollar amounts, or verified quotes from a bribery attempt, and this page does not assert any beyond what ICLR itself has stated publicly. Readers should treat the scale and severity of the harassment as reported by the conference organizers rather than independently audited.

ICLR’s response

Per the organizers’ own timeline, ICLR froze review-editing forms and public commenting on 27–28 November 2025, reverted all reviews to their pre-breach state by 28 November, reassigned every affected paper to a new area chair, extended the metareview deadline to 6 January 2026, banned the individual identified as having circulated the reviewer-identifying data, and moved to desk-reject papers where authors or reviewers were found to have acted on the leaked identities to collude.

A separate, concurrent problem: how much of ICLR 2026 review was AI-generated?

Independently of the breach, multiple outlets reported in this window on analysis attributed to the AI-text-detection firm Pangram Labs suggesting that roughly 21% of ICLR 2026 peer reviews were fully AI-generated, with a larger share showing at least some detectable trace of AI-generated text. CASRAI has not independently reproduced this analysis or reviewed Pangram Labs’ underlying methodology for this specific figure, and the number should be treated as a reported third-party finding rather than a confirmed, audited statistic — the same caution CASRAI applied to Pangram’s separately reported NeurIPS 2026 desk-rejection figures, where the underlying methodology involved sensitivity to detector window-size settings that materially changed the headline number.

The AI-generated-review question and the OpenReview breach are causally unrelated — one is a platform security failure, the other a claim about reviewer behavior — but their coincidence in the same review cycle compounded scrutiny of ICLR 2026’s review process as a whole, and both bear on the same underlying concern: whether large AI conferences’ review pipelines, which now handle submission volumes in the tens of thousands, are able to guarantee either the confidentiality or the human origin of a review.

How this differs from other 2026 AI-peer-review stories

This is the third distinct AI-and-peer-review integrity story CASRAI has tracked in the 2026 conference cycle, and each involves a different failure mode:

  • ICLR 2026 (this page): a platform security breach exposing reviewer identities, reportedly exploited for harassment and bribery attempts — a confidentiality and platform-security failure, not a scoring-manipulation technique.
  • ICML 2026 “paper laundering”: a peer-reviewed study demonstrating that cosmetic, content-preserving LLM rewrites of a manuscript could inflate the score an AI reviewer assigned it — a scoring-gaming vulnerability in AI-assisted review, not a breach or a claim about reviewers themselves using AI.
  • NeurIPS 2026 Pangram desk rejections: a conference’s own use of an AI-text detector to desk-reject submitted papers without appeal — a dispute about detecting AI-generated submissions, not reviews, and not a security incident.

Read together, the three stories span the review pipeline end to end: AI use in the papers being reviewed, AI use in the reviews themselves, and the security of the platform that is supposed to keep both processes confidential.

Why this matters for research-integrity offices and CRIS operators

  • Anonymity is infrastructure, not policy. A double-anonymized review policy is only as strong as the platform enforcing it; a single API-level flaw converted a policy commitment into a fully identified, exploitable dataset within hours.
  • Reviewer protection needs an incident-response plan, not just a code of conduct. ICLR’s response — freezing forms, reverting scores, reassigning area chairs, extending deadlines — is a template other large, platform-mediated review processes (including institutional and funder review panels using similar tooling) should have ready before an incident, not improvised during one.
  • AI-generated-review detection remains contested and unaudited. As with the NeurIPS detector controversy, a headline percentage attributed to a commercial detection vendor is not the same as a peer-reviewed, replicated finding; research-integrity offices citing this figure should cite it as reported, with the same caveat CASRAI applies here.
  • Institutional research-integrity officers (see Research Integrity Officer) evaluating whether to recognize AI-conference peer-review service, or investigating a specific complaint arising from either incident type, should request the underlying incident report or detection methodology rather than relying on secondary press coverage alone.

Frequently asked questions

Is the ICLR 2026 OpenReview breach the same story as the AI-generated peer review claims?

No. They are separate issues that happened to surface in the same review cycle. The breach was a platform vulnerability that exposed reviewer identities and, per ICLR’s own account, was exploited for harassment and bribery attempts. The AI-generated-review figure is a separate, third-party-reported analysis of how many reviews appear to have been written by AI, unrelated to the breach’s cause.

Who confirmed the harassment and bribery attempts against ICLR reviewers?

ICLR’s organizers disclosed this in their own public incident response on the ICLR blog. It has been corroborated in outline by independent science-press coverage. Specific individual cases, amounts, or verified transcripts of bribery attempts have not been published.

Is the 21% AI-generated-review figure confirmed by ICLR or independently audited?

It is attributed in press reporting to analysis by the AI-text-detection firm Pangram Labs. CASRAI has not seen a published, independently audited methodology for this specific ICLR 2026 figure and treats it as a reported, not confirmed, statistic.

What did ICLR do to remediate the breach?

Per its own timeline, ICLR froze review editing and commenting, reverted all reviews to their pre-breach state, reassigned every paper to a new area chair, extended the metareview deadline, banned the individual who circulated the leaked identities, and moved to desk-reject papers implicated in collusion.

Sources

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →