Influence operations · GTG-54002
Commercial influence operations across regions: GTG-54002 case
This page is an English translation of the relevant content from Anthropic's September 2026 report, pages 47–53. Actor attribution, confidence language, and scale figures all come from that report; this site has not independently verified all real-world outcomes.
According to Anthropic's report, a network disguised as 'independent local newsrooms' used Claude to mass-produce and rewrite political content: about 70 fake news websites, at least 8,913 articles, about 20 languages, plus 70 associated X accounts and over 250 fake comment accounts for amplification. But the report also emphasizes: most content had almost no real audience engagement, and no evidence of spread beyond its own network was found — output volume is not the same as influence. The report traced the network to a French digital advertising company, could not confirm the paying clients, and found no evidence of any government direction.
What happened
We identified and removed an account that used Claude to mass-produce and rewrite political content. The operation used the model to rewrite and distribute fabricated news stories across about 70 fake news websites. The content was further amplified by 70 associated and matching X/Twitter accounts, and a network of over 250 fake comment X/Twitter accounts.
Our investigation showed that the campaign targeted global audiences across six continents. Although the actors built the network to look like independent local newsrooms, we traced the operation to LKM Company, a France-based digital advertising firm.
The network did not adhere to a single political ideology; instead, they shifted political stances to support different sides of the political spectrum depending on who was paying at the time. This behavior fits a commercial 'influence for hire' model.
In these operations, private companies are hired to manipulate information, shift public opinion, advance specific political agendas, or carry out targeted smear campaigns against individuals.
We disrupted the operation before it could build a real audience. The network published at least 8,913 articles in about 20 languages, but most of the content we identified had almost no observable engagement from real audiences. Using the Brookings Institution's Breakout Scale (a framework for measuring the effectiveness of influence operations), we assessed the campaign as Tier 2: content was distributed through the network's own websites and matching social media accounts, with no evidence that it broke out of its own campaign scope.
What the AI did
The actors used Claude for two main purposes: writing fully original articles for their fake news outlets, and rewriting real articles by legitimate journalists. An automated system rewrote real news reports into politically slanted versions tailored to appeal to each specific national audience and the political angle they wanted.
The operation targeted audiences in highly competitive democratic spaces, with particular focus on the United States, Brazil, France, and the Democratic Republic of the Congo (DRC). Because the political environments in these countries differ greatly, the network's targeting showed no single political agenda.
Our investigation found signs that the campaign may reflect the intentions of one or more clients with interests in the ongoing DRC–Rwanda conflict. We could not independently confirm which clients commissioned the content, and we found no evidence of any government direction.
The operation registered domains from France over a ten-week window in mid-2025, standing up its network infrastructure in a short period. They hosted all these assets on shared infrastructure behind a single deployment. This allowed our investigators to link the seemingly independent about 70 news websites to a single operator account.
The network used Claude to create a standardized content pipeline. All prompts given required a fixed JSON output structure, formatted HTML, precise character limits, and 3 to 4 internal links per article. This allowed the actors to automatically generate and publish content at scale. The articles were specifically designed to boost their websites' authority rankings on search engines.
We found the operation repeatedly relied on three manipulation techniques: rewriting the same source story in opposite ideological directions for different audiences; adding a political angle to stories that originally had none; and 'laundering' stories across borders into unrelated regions, stripping them of their original context.
To make articles look legitimate, the actors attributed them to fake journalist names. Our investigation found these journalists do not exist. These fabricated bylines made each website look like an independent local newsroom with its own staff. The network paired each fake outlet with an X (formerly Twitter) account. The websites were then amplified by a layer of comment accounts created in the exact same time frame as the websites, many using AI-generated avatars. Most of these fake accounts were created in June and July 2025.
On September 11, 2025, we detected signs of coordinated inauthentic behavior when the network's websites published nearly identical articles about the DRC–Rwanda conflict within three minutes. The actors modified the tone of each article to suit different regional audiences while coordinating the distribution of these links across numerous X accounts.
What the report observed
A close look at the network's output revealed a heavy focus on the Democratic Republic of the Congo, with 318 related articles across all fake news websites. These reports generally supported the DRC government's position, with particular attention to regional mineral transactions and ongoing tensions with Rwanda. This strategy matched the network's audience growth; in the first few weeks, the fake identities following its X accounts were overwhelmingly DRC-related, and its DRC-specific news pages became the most shared and popular accounts across the entire operation at that time.
An X account claiming to be a 'digital army' of Congolese civilians was also observed following multiple accounts in the network. We found no evidence of any government direction.
We identified the account through our ongoing investigation of influence operations in the region. We banned them and the organizations associated with the campaign, and implemented new detection methods targeting the operation's behavioral signatures. The report shares indicators to support action by other industry partners, particularly the shared deployment identifier linking the network to one account, and a representative sample of the 70 fake outlets selected across regions (the full list of domains and accounts is provided separately). Per this site's safety boundaries, specific domains and accounts are not reproduced.

Confirmed & unknown
Confirmed
- About 70 fake news websites can be traced to the same operator account (shared infrastructure and deployment identifier)
- Bylined journalists do not exist; many amplification accounts use AI-generated avatars
- At least 8,913 articles in about 20 languages — but no evidence of spread beyond the network's own accounts was found
- The report traces the operation to LKM Company and banned the account and associated organizations
Unknown
- The identity of the paying clients could not be independently confirmed
- The actual reach to real audiences is unknown (the report assesses very little engagement)
- The subsequent handling of these accounts and websites by social and search platforms is not detailed item-by-item by the report
Platform response
Anthropic says it discovered the account during its ongoing investigation of influence operations in the region, banned the account and associated organizations, and implemented new detection methods targeting their behavioral signatures. The report also shares the shared deployment identifier linking about 70 websites to the same account and a sample of fake outlets for industry partners to act on; the full list of domains and accounts is provided separately and not reproduced on this site.
Limits of response:What was banned was the operator account and associated organizations; the report does not state the outcome for all websites and accounts across platforms.
Takeaways
- When you see 'multiple outlets reporting the same thing at the same time,' pay attention: they may belong to the same operator, just with different names and stances.
- High content output and many languages do not equal a large audience; judging influence requires evidence of real engagement and cross-platform spread.