Scams & fraud · GTG-15001

Undisclosed AI identities in dating apps: GTG-15001 case

Source notice

This page is an English translation of the relevant content on pages 139–142 of Anthropic's September 2026 report. Actor attribution and scale figures come from that report; this site has not independently verified all real-world outcomes.

According to an Anthropic report, a Chinese app studio used Claude to build a network of more than 20 dating apps and power AI virtual identities that conversed with users — even though its services were advertised as entirely human-run. In a two-week window in April 2026, the report found more than 4,700 distinct AI virtual identities interacting with at least 25,000 unique individuals. The studio also recruited real people to mix into the same matching feed as the bots, mainly for authenticity checks. The ratio of AI to humans was roughly 3:1.

What happened

GTG-15001 reflects both the reach and the limitations of current AI models in fraud and scam activity. A Chinese app studio used Claude to build a network of more than 20 dating apps and to power AI virtual identities that conversed with users — even though its services were advertised as entirely human-run. In a two-week window in April 2026, we found more than 4,700 distinct AI virtual identities interacting with at least 25,000 unique individuals.

The studio also recruited real people, mixing them into the same matching feed as the bots. These people were mainly included for authenticity checks (live video calls and social media follows) to reduce fraud victims' suspicion. These workers were also AI-enhanced, with another model generating some of their messages.

This is a cousin of a 2025 case in which another actor set up a Telegram bot as a service for other scammers to generate dating app messages. Although it did not exploit any novel model-abuse techniques, GTG-15001 operated on a much larger scale and deliberately abused multiple AI providers to take on different, non-overlapping roles.

As with many cases in this report, the actor relied on China-based API reseller/proxy infrastructure to obtain and rotate AI model access at scale and to circumvent Anthropic's supported-region and usage policies. We banned the threat actor's accounts and worked with industry partners, including other AI labs, to disrupt the actor's use of multiple AI models.

What the AI did

The AI-to-human ratio was 3:1. The operator recruited real people as gig workers, mixing their profiles into the same swiping feed as the Claude-powered identities, with an AI-to-human ratio of roughly 3:1. The humans handled interactions that Claude could not perform, such as live video calls and social media follows, to convince users the app was real.

Multiple AI providers were used for different roles. Claude ran the autonomous conversational identities, producing about 2.36 million messages within the two-week window. A small non-Anthropic model generated short reply suggestions for the gig workers, as well as facial attractiveness scores and photo/voice moderation. An image-editing model generated avatar images. We have shared the relevant details directly with the providers involved.

The system prompt elicited in-identity replies in almost all sampled exchanges. The system prompt read like an ordinary role-play or companion deployment, and monetization and deception were not visible from within any single exchange. In a few sampled cases, the model's own reasoning revealed the harm, including exchanges where users disclosed serious illness or acute distress, but the model did not refuse to complete the exchange and instead continued outputting in-character.

The apps were designed to evade App Store and Play Store review. Developer documentation showed a UI controller that activated only during store review and was otherwise dormant. Class names were differentiated across the more than 20 app variants to defeat the similarity checks platforms use to associate apps. A redirect routing payments to a third-party processor's in-app browser was server-side configurable, so it could be hidden during review.

What the report observed

The operation ran as a three-sided market:

Target users (United States): users swiped a feed that was 75% Claude identities and 25% humans, unable to distinguish between them. Messages and matches consumed credits, which required purchasing in-app currency when used up.

AI identities (Claude): the system prompt set the identity as an ordinary user seeking romance or companionship. Claude handled most of the text conversations.

Human gig workers: workers handled interactions requiring a real person (video calls, social media follows) and used another model's suggested replies.

The report confirms more than 20 dating apps, more than 4,700 AI virtual identities, and at least 25,000 interacting individuals. The report confirms the AI-to-human ratio was roughly 3:1.

Diagram: the report uses it to illustrate the three-sided market structure of AI identities, human gig workers, and users.
Original report illustration: diagram of the deceptive dating app network. The text in the figure is the original English.

Confirmed & unknown

Confirmed

  • The report confirms a Chinese app studio used Claude to build more than 20 dating apps
  • The report confirms more than 4,700 AI virtual identities interacted with at least 25,000 people
  • The report confirms the AI-to-human ratio was roughly 3:1
  • The report confirms the apps were designed to evade app store review

Unknown

  • Whether users knew they were conversing with AI is not stated in the report
  • The total financial loss to users is not given in the report
  • The studio's true identity is not fully disclosed in the report

Platform response

Anthropic banned the threat actor's accounts and worked with industry partners, including other AI labs, to disrupt the actor's use of multiple AI models.

Limits of response:Banning accounts cannot recover fees users have already paid, nor can it remove apps already published in app stores.

Takeaways

  • Undisclosed AI identities in dating apps are a form of deception; users may be unable to distinguish AI from humans.
  • Mixing AI with humans can increase the credibility of the deception, because humans handle authenticity checks such as video calls.
  • Apps can be designed to evade app store review; users should be cautious about apps from unknown sources.

Sources