Influence operations · GTG-84006

A conversational operation impersonating a real activist: GTG-84006 case

Source notice

This page is an English translation of the relevant content from Anthropic's September 2026 report, pages 70–75. Links to specific organizations are the report's assessments. This site does not reproduce contact lists or identifiable details of the impersonated person.

According to the report, an influence operation targeting audiences in and outside Iran used a shared AI agent to impersonate a real activist: it read about 8,400 of their Telegram posts to mimic their writing style, then held real-time political conversations with their contacts. As far as the report knows, these contacts did not know they were speaking to an AI-assisted account. This page does not list any individuals or contact details.

What happened

We identified and removed a distributed influence operation targeting audiences in and outside Iran. To deceive users, the operation impersonated a real activist by instructing a shared AI agent to clone the activist's personal Telegram account, then instructing it in Persian that it was now that person. The actor instructed Claude to read about 8,400 of the activist's Telegram posts to replicate their writing style, then used it to hold real-time political conversations with their contacts. As far as we know, these contacts did not know they were talking to an AI-assisted account.

Although the actors did not share account infrastructure or show obvious signs of coordination, our investigation linked the operation to the People's Mujahedin of Iran (PMOI/MEK) and its political front, the National Council of Resistance of Iran (NCRI).

Our investigation showed that at least four individuals running the operation work for the NCRI's official media organization. The operation relied on NCRI/MEK media assets across multiple platforms, including television and radio, satellite and shortwave broadcasting, Instagram, Telegram, and X/Twitter. While the existence of a committee approval cycle and notes about MEK leadership suggest possible central task assignment, we could not verify the extent of centralized control.

Using the Breakout Scale, we assessed the operation as Tier 2 (multiple platforms, distributed through the network's own NCRI media assets and amplifier accounts).

What the AI did

The operation successfully scraped over 500 social media channels to build detailed profiles of individuals inside Iran. They then grouped these targets by city, age, occupation, political stance, and arrest history, which may have helped them tailor messages to specific audiences.

The network analyzed about 51,944 archived messages from these conversations to build detailed psychological profiles of dozens of specific individuals inside Iran. To further spread its message, the impersonating account also sent a fabricated breaking news headline to over 30 contacts simultaneously.

To promote NCRI President Maryam Rajavi's ten-point plan, the network created AI-generated avatars for each article. The actors animated these avatars, gave them voices, and used them in video content.

The AI's role was identity impersonation and real-time conversation, not just writing public posts. The report also says the operation scraped over 500 social channels and built profiles grouped by city, age, etc., for later outreach. This page only describes the risk of 'building group-level outreach lists' and does not provide any profile fields or lists.

What the report observed

The report assessed it as Tier 2 on the Breakout Scale: multiple platforms, but distribution mainly occurred within its own media and amplifier accounts.

That contacts were unaware is the report's understanding at the time ('to our knowledge'), not independent forensics on every single conversation.

Schematic: an AI agent reads historical posts and continues conversations under someone else's identity.
Original report figure: conceptual schematic of a shared agent impersonating a real account to hold conversations. The text in the image is the original English.

Confirmed & unknown

Confirmed

  • The report confirms the use of about 8,400 historical posts to mimic writing style and conduct real-time conversations
  • The report confirms at least four people are linked to the relevant media organization
  • The report assessed the spread as Tier 2 (mainly within its own network)

Unknown

  • The extent of centralized command could not be verified
  • How many contacts later discovered they were talking to an AI was not counted by the report
  • Whether recruitment succeeded — the report gives no outcome figures

Platform response

Anthropic removed the relevant accounts and the shared agent.

Limits of response:Removing model access cannot automatically notify all impersonated individuals or contacted persons.

Takeaways

  • Even if the writing style closely resembles someone you know, it does not mean that person is the one speaking.
  • An 'acquaintance' who suddenly becomes extremely active across platforms is worth confirming through another channel.
  • This site will not reproduce any contact list or identifiable details of the impersonated person.

Sources