What is the story about?
A China-based studio built more than 20 “dating” apps that were, by the operator’s own design, mostly not dating apps at all. Instead, they were AI-run confidence schemes engineered to slip past App Store and Play Store review and keep victims paying for as long as possible.
Anthropic disclosed the operation, internally designated GTG-15001, in its September 2026 threat intelligence report.
Over a single two-week window in April 2026, the company found more than 4,700 distinct AI-driven personas, built using Claude, holding conversations with at least 25,000 people. In that fortnight alone, the Claude-run personas generated roughly 2.36 million messages.
What makes the case notable isn’t the fraud itself — romance scams are old news — but the industrial design behind it: a studio that treated AI chatbots, image generators and gig workers as interchangeable parts on an assembly line, with each handling the task it was best suited to.
A feed that was three-quarters fake
Users swiping through the network’s apps saw a match feed that was roughly 75% AI personas and 25% real people, according to Anthropic’s findings, with no way to tell which was which.
That mix was deliberate. Real people, recruited as gig workers, were paid per message, per video call and per social-media follow-back. They were brought in specifically to pass the “authenticity checks” that AI alone couldn’t fake: a live video call and a real social-media follow-back.
Even those human workers weren’t fully human in practice. A separate, smaller AI model fed them three suggested replies for each conversation, and the worker simply tapped one to send. The same model also scored uploaded photos for attractiveness and moderated images and voice notes.
A third, image-editing model produced the avatar imagery used across the network. Anthropic said it has shared its findings with the other AI providers whose models were used for these roles.
Claude handled the part that was hardest to fake by hand: sustaining thousands of concurrent, in-character conversations continuously. According to Anthropic, the personas were instructed never to admit they were automated, to deflect any request for a video call or photo, and to move users through a fixed sequence of conversational stages.
Built to fool the app stores, too
The operation’s deception extended beyond its users to the platforms hosting the apps. Anthropic’s investigators found developer documentation describing a hidden interface mode that activated only while an app was under App Store or Play Store review, then went dormant once it was live.
Class names were differentiated across the more than 20 app variants specifically to defeat the similarity checks platforms use to catch cloned or linked apps.
An in-app browser that redirected payments to third-party processors was configurable from the operator’s servers, allowing it to be switched off and hidden whenever a reviewer was looking.
Anthropic said it has passed the platform-specific evidence, including the storefront publishers’ identities, directly to Apple and Google.
Named app brands identified in the network include DORA, DONI, ROMI, LUMA, JOVIA, KIRA, GRACECHAT, HAVEN, NALO and LOVIA, alongside further variants Anthropic could identify only by internal numeric IDs.
A troubling gap in the safety net
Perhaps the most uncomfortable detail in Anthropic’s disclosure came from a small number of sampled exchanges.
Claude’s own internal reasoning appeared to register that something was wrong, including cases where users disclosed serious illness or acute distress, yet the model did not break character or refuse to continue.
Anthropic said the deception was invisible from inside any single conversation because the system prompt read like an ordinary companion or roleplay app, giving no outward sign of the monetisation and deceit built around it.
How it was funded and how it fell
The operator accessed AI models through PRC-based proxy and reseller infrastructure, rotating traffic to work around Anthropic’s regional access restrictions and usage policies. The report says this pattern recurs across many of the cases in its September 2026 findings, not just this one.
Anthropic said it has since banned the accounts and “throwaway” organisations tied to the network, including accounts held directly by the operator’s own employees.
Because most of those accounts were affiliated with PRC-origin proxy networks, Anthropic said they were caught up in its broader account-abuse detection and enforcement work rather than through a bespoke takedown of this network alone.
The company also flagged the case to the other AI providers whose tools powered the non-conversational parts of the operation — the reply-suggestion engine and the avatar generator.
Anthropic claims that its report is a threat-intelligence disclosure, not a criminal indictment, and it stops short of naming the studio, its executives or its home jurisdiction beyond “China-based.”
Anthropic disclosed the operation, internally designated GTG-15001, in its September 2026 threat intelligence report.
Over a single two-week window in April 2026, the company found more than 4,700 distinct AI-driven personas, built using Claude, holding conversations with at least 25,000 people. In that fortnight alone, the Claude-run personas generated roughly 2.36 million messages.
What makes the case notable isn’t the fraud itself — romance scams are old news — but the industrial design behind it: a studio that treated AI chatbots, image generators and gig workers as interchangeable parts on an assembly line, with each handling the task it was best suited to.
A feed that was three-quarters fake
Users swiping through the network’s apps saw a match feed that was roughly 75% AI personas and 25% real people, according to Anthropic’s findings, with no way to tell which was which.
That mix was deliberate. Real people, recruited as gig workers, were paid per message, per video call and per social-media follow-back. They were brought in specifically to pass the “authenticity checks” that AI alone couldn’t fake: a live video call and a real social-media follow-back.
Even those human workers weren’t fully human in practice. A separate, smaller AI model fed them three suggested replies for each conversation, and the worker simply tapped one to send. The same model also scored uploaded photos for attractiveness and moderated images and voice notes.
A third, image-editing model produced the avatar imagery used across the network. Anthropic said it has shared its findings with the other AI providers whose models were used for these roles.
Claude handled the part that was hardest to fake by hand: sustaining thousands of concurrent, in-character conversations continuously. According to Anthropic, the personas were instructed never to admit they were automated, to deflect any request for a video call or photo, and to move users through a fixed sequence of conversational stages.
Built to fool the app stores, too
The operation’s deception extended beyond its users to the platforms hosting the apps. Anthropic’s investigators found developer documentation describing a hidden interface mode that activated only while an app was under App Store or Play Store review, then went dormant once it was live.
Class names were differentiated across the more than 20 app variants specifically to defeat the similarity checks platforms use to catch cloned or linked apps.
An in-app browser that redirected payments to third-party processors was configurable from the operator’s servers, allowing it to be switched off and hidden whenever a reviewer was looking.
Anthropic said it has passed the platform-specific evidence, including the storefront publishers’ identities, directly to Apple and Google.
Named app brands identified in the network include DORA, DONI, ROMI, LUMA, JOVIA, KIRA, GRACECHAT, HAVEN, NALO and LOVIA, alongside further variants Anthropic could identify only by internal numeric IDs.
A troubling gap in the safety net
Perhaps the most uncomfortable detail in Anthropic’s disclosure came from a small number of sampled exchanges.
Claude’s own internal reasoning appeared to register that something was wrong, including cases where users disclosed serious illness or acute distress, yet the model did not break character or refuse to continue.
Anthropic said the deception was invisible from inside any single conversation because the system prompt read like an ordinary companion or roleplay app, giving no outward sign of the monetisation and deceit built around it.
How it was funded and how it fell
The operator accessed AI models through PRC-based proxy and reseller infrastructure, rotating traffic to work around Anthropic’s regional access restrictions and usage policies. The report says this pattern recurs across many of the cases in its September 2026 findings, not just this one.
Anthropic said it has since banned the accounts and “throwaway” organisations tied to the network, including accounts held directly by the operator’s own employees.
Because most of those accounts were affiliated with PRC-origin proxy networks, Anthropic said they were caught up in its broader account-abuse detection and enforcement work rather than through a bespoke takedown of this network alone.
The company also flagged the case to the other AI providers whose tools powered the non-conversational parts of the operation — the reply-suggestion engine and the avatar generator.
Anthropic claims that its report is a threat-intelligence disclosure, not a criminal indictment, and it stops short of naming the studio, its executives or its home jurisdiction beyond “China-based.”
/images/ppid_59c68470-image-178911003610995635.webp)

/images/ppid_59c68470-image-178911503651855227.webp)
/images/ppid_59c68470-image-178919005578396536.webp)
/images/ppid_59c68470-image-178910755618253473.webp)



/images/ppid_59c68470-image-178909512057616452.webp)
/images/ppid_59c68470-image-178910758822286021.webp)

/images/ppid_59c68470-image-178910752498742699.webp)
/images/ppid_59c68470-image-178909266069320087.webp)
/images/ppid_59c68470-image-178909263097923578.webp)