Report Chapter 6: Scams and Fraud (September 2026 Report)

This chapter has only one case, GTG-15001: the report says a dating-app network mixed undisclosed AI identities with human gig workers in the same service and charged users per message.

p. 139–142 · 1 case units

Key findings

  1. The report says the operator used Claude to build more than 20 dating apps and power the AI conversational identities in them, while advertising the service as entirely human-provided.
  2. In the two-week window in April 2026: more than 4,700 AI identities, at least 25,000 unique interacting individuals, and about 2.36 million messages handled by Claude — these are interaction-scale figures, not confirmed victim counts.
  3. The focus of this chapter is undisclosed identity and paid inducement, not companion AI itself; human gig workers are used to pass 'authenticity checks,' and a single video call is not enough to prove a platform is transparent.

What happened

This chapter is short (original report pages 139–142) and contains only GTG-15001. The report uses it as a sample showing 'the capabilities and limitations of current AI models in fraud': it did not rely on any novel model-abuse technique, but its scale was clearly larger than a similar 2025 case (in which an actor used a Telegram bot to generate dating-app messages for other scammers), and it deliberately had multiple AI providers take on non-overlapping roles — Claude handled automated conversation, while other models handled reply suggestions, image generation, and content moderation.

According to the report, the operation's structure was a 'three-sided market': target users (said by the report to be in the United States) swiped a matching feed where about three-quarters were Claude-powered identities and about one-quarter were human gig workers, indistinguishable from each other; sending messages and matching consumed per-message credits that required topping up in-app currency. Gig workers were recruited by invitation and paid per message, video call, and follow-back; AI identities were instructed never to reveal their automated nature, to avoid video requests, and to advance the conversation through fixed stages.

The report also points out two easily overlooked details. First, the system prompt driving the identities read like an ordinary role-play or companion deployment, and the deception and monetization were not visible from within any single conversation; in a small sample, the model's reasoning surfaced harm signals (for example, users disclosing serious illness or extreme distress), but the output still continued in character. Second, the report says the apps were specifically designed to evade app-store review, including a UI controller that activated only during review, differentiated naming across more than 20 app variants, and payment redirects that could be hidden during review.

On acquisition and response, the report says the actor relied on China-based API reseller and proxy infrastructure to obtain and rotate model access at scale, in order to bypass Anthropic's supported regions and usage policies; Anthropic banned the accounts and organizations attributed to the operation, shared findings with the other AI labs handling non-conversational roles, and provided platform-side metrics directly to Apple and Google. For the full facts and how the numbers should be read, see this site's full case page.

Diagram: the ratio of AI identities to human gig workers in the dating-app feed is about 3:1, and users cannot tell them apart; humans' video calls and social-media follow-backs are used to create authenticity.
Original report illustration: GTG-15001's 'three-sided market' — users, Claude-powered AI identities (about 75%), and human gig workers (about 25%) coexist in the same feed, with messages billed per use.

Related cases

p. 139–142

Undisclosed AI identities in dating apps: GTG-15001 case

According to an Anthropic report, a Chinese app studio used Claude to build a network of more than 20 dating apps and power AI virtual identities that conversed with users — even though its services were advertised as entirely human-run. In a two-week window in April 2026, the report found more than 4,700 distinct AI virtual identities interacting with at least 25,000 unique individuals. The studio also recruited real people to mix into the same matching feed as the bots, mainly for authenticity checks. The ratio of AI to humans was roughly 3:1.

Limits of response

This chapter discloses only one case, a sample the publisher chose to disclose based on its own platform visibility: it cannot be used to estimate the global scale of AI fraud, the total number of victims, or the industry distribution, nor to derive the overall safety of any given app store. All scale figures are tied to the two-week observation window in April 2026 and a specific definition; 'interacting individuals' does not mean confirmed victims.

Descriptions of actor attribution, enforcement actions, and partners all come from Anthropic; this site has not independently verified all real-world outcomes. Indicators of compromise such as domains and IPs listed by the report are not reproduced in concrete form per this site's security boundaries; banning accounts is not the same as confirming that all related apps have stopped operating.