Surveillance operations · GTG-54009

A commercial surveillance platform using AI to profile social accounts: GTG-54009 case

Source notice

This page is an English translation of the relevant content from Anthropic's September 2026 report, pages 82–86. Actor identity and activity descriptions come from the report and media investigations cited by the report; this site has not independently verified all real-world outcomes.

According to the report, a suspected commercial intelligence firm used Claude to build a prototype surveillance platform that batch-analyzed public posts by social media users in Iran and the Gulf region, inferred their location, group affiliation, and political leanings, and generated intelligence briefings in the style of government documents. The report discovered the operation during its pilot phase and found no evidence it was used against real targets.

What happened

In June 2026, we banned an account that used Claude to build a commercial surveillance platform for analyzing, classifying, and profiling the social media activity of users in Iran and the Persian Gulf region. Our investigation found that the activity was carried out by, or on behalf of, an entity called 'S2T Unlocking Cyberspace'; open-source research suggests this is an Israeli–Singaporean commercial intelligence firm.

The platform's core purpose was surveillance: tagging the location of social media users, sorting people into coded demographic groups, and generating intelligence briefings in formal Arabic that read like government documents.

Our findings independently corroborate a February 2023 investigation by the Forbidden Stories journalism network; that investigation documented a surveillance product by S2T, which journalists discovered in a company brochure within leaked Colombian military files. The capabilities described in the brochure closely match the behavior we observed in this operation.

We identified the operation during its pilot phase and found no evidence that later stages of S2T's surveillance chain (as described in the Forbidden Stories report) were used against real targets before the ban.

What the AI did

The actor was building a multi-brand system portfolio, likely serving Arabic-speaking clients in the Gulf region.

The system captured and classified the location of diaspora social network users, categorizing them as pro-government or anti-government.

A demographic scheme with six population groups (urban, religious, military, youth, diaspora, rural) was used to classify people.

The final briefings were written in formal Arabic in the style of official government communications, including sentiment scores broken down by Gulf nationality and suggested counter-narratives.

The report shows that the actor handed roughly 25 social media posts to Claude at a time, asking it to analyze the poster's demographic group, location, and political leanings, and to give a confidence score for each judgment.

In addition, the actor had Claude generate posts in Persian, Arabic, English, and German for suspected fake online identities — designed to look like ordinary users on both sides of a political camp, which the report believes was to build credibility for a large number of fake accounts.

What the report observed

The report describes several product lines of the platform, likely aimed at Arabic-speaking clients in the Gulf region; the system categorized diaspora social network users by location and tagged their stance.

The report also lists a parallel workflow: over 255 synthetic social accounts, divided into different groups such as diaspora, youth students, and military. The report emphasizes that it identified the operation during its pilot phase and found no evidence that it entered later stages targeting real targets before being banned.

Notably, the report's own honesty boundary: Anthropic says it cannot independently confirm the downstream steps reported in the media, such as infiltrating private groups and phishing.

Schematic: social media posts flow through AI classification and profiling into an intelligence briefing output process.
Original report figure: the information collection funnel described in the report — AI-driven classification and fake-identity content generation. The text in the image is the original English.

Confirmed & unknown

Confirmed

  • The report confirms the platform's purpose, population classification method, and the existence of stockpiled fake accounts
  • The report confirms the operation was discovered and banned during its pilot phase
  • The report confirms its observations closely match the capabilities described in Forbidden Stories' 2023 investigation

Unknown

  • Whether the platform was used against real targets in later stages before the ban — the report shows no such evidence
  • The downstream steps reported in the media (infiltrating groups, phishing, etc.) were not independently confirmed by Anthropic
  • The actual client identity of the platform was not confirmed in the report

Platform response

Anthropic banned the relevant accounts, stating this violated its usage policy prohibitions on surveillance, profiling, and coordinated inauthentic behavior, and shared indicators with partners tracking 'surveillance-for-hire' actors.

Limits of response:Banning accounts only interrupts their use of Claude; the report does not claim the platform as a whole stopped operating.

Takeaways

  • Public posts can also be collected in bulk and used to infer sensitive attributes such as location and stance — 'public' does not mean 'consent to be profiled'.
  • Seemingly ordinary local accounts online may be mass-produced fake identities; when judging a source, the account's history and consistency are more reliable than a single piece of content.
  • 'Commercial intelligence services' may be a wrapper for surveillance; check whether their data sources obtained the subjects' consent.

Sources