Report Chapter 3: Surveillance Operations (September 2026 Report)

This chapter's ten units show how AI can act as both an analysis team and an engineering team, turning surveillance into routine paperwork or a local platform.

p. 81–110 · 8 case units

Key findings

  1. When public data is cross-referenced in bulk, privacy risks rise sharply.
  2. GTG-50027: the bans disrupted the software and design work but did not stop the already locally deployed platform.
  3. GTG-14022's contractor identity is medium confidence; GTG-14021 is a single unit containing three operations.

What happened

Original report pages 81–110. It opens by summarizing trends observed from January to July 2026: AI replacing engineering labor, identifying targets in bulk, and being written into security bureaucracy workflows. Then come commercial profiling, outreach to overseas communities, religious affairs intelligence, three operations related to local 'stability maintenance,' public opinion monitoring, software from two Iranian units, the Mali nationwide platform, and three cross-cutting cases related to Iran.

GTG-30004, 30005, and 30006 are placed in this chapter per the report's structure while also carrying secondary cyber or weapons tags; they are not duplicated into multiple articles.

Public write-ups stop at the group level, do not build individual profiles, and do not list target-selection fields.

Diagram: public content flows into classification and briefing, with no individual identities.
Original report illustration: schematic of the surveillance information funnel. Text in the figure is the original English.

Related cases

p. 86–89

Surveillance and outreach targeting diaspora communities: GTG-14010 case

According to the report, an operation aligned with the Chinese government's collection direction used Claude to track, profile, and attempt to recruit members of Uyghur communities in Syria. The operator did not speak Arabic, and the model provided dialect drafting, real-time translation, and task quality checks. The report assesses with low confidence that the operator was a contractor rather than a direct national security organ. The ethnic label is the target background described by the report, not an indication that the group itself is at risk.

p. 89–93

Intelligence profiling targeting religious communities: GTG-14020 case

According to the report, a group of accounts aligned with the Chinese government's direction used Claude as an analysis team to generate Chinese-language profiles of religious leaders and diaspora figures across Asia, following internal templates. Targets included Catholic, Tibetan Buddhist, Falun Gong, and Taiwanese Christian communities. This page only discusses group-level privacy risks and does not include any individual names or location details.

p. 93–98

Surveillance and transnational repression-related activities: GTG-14021 case

According to the report, a group of accounts was used to carry out three operations: a local internet police public-opinion pipeline, a police academy student's 'stability maintenance' report, and a local state security department's daily briefing. Targets ranged from domestic petitioners to overseas democrats and human rights organizations. These are three operations within one article unit; 'one case' should not be understood as 'one incident.'

p. 98–101

Dissident monitoring under the guise of public opinion analysis: GTG-14022 case

According to the report, an operation within China used Claude as an automated 'public opinion monitoring' and intelligence analysis system. The actor instructed Claude to generate government briefings listing dissidents, activists, ethnic minorities, Chinese diaspora communities, and foreign media as threats to political stability. The report assesses with medium confidence that the operation was carried out by a contractor working for government clients, rather than by a state organ acting directly.

p. 105–106

Public information used for identity profiling: the GTG-30004 case

According to the report, an Iran-linked threat actor used Claude to build an automated open-source intelligence identity profiling tool targeting Israeli government and non-government individuals and Jewish diaspora organizations. The actor also used Claude to modify the open-source LSASS credential dumper NanoDump and build a custom C++ obfuscation/build pipeline to obfuscate malware samples and hinder analysis.

p. 101–103

Surveillance System Development and Malicious Browser Extensions: GTG-34007 Case

According to the report, two units linked to Iranian paramilitary and domestic security agencies used 16 Claude accounts to build surveillance systems and a malicious Firefox browser extension. A seven-department organization claimed to maintain a database of Iranian national identity records and monitored and profiled 6,388 Iranians over one year. Another provincial unit based in Qom developed a malicious Firefox extension called "al-Najm al-thāqib" to mass-collect user identities from major social network platforms. This page does not publish any surveillance logic or extension code.

p. 103–105

Mali Mass Communications Surveillance Platform: GTG-50027 Case

According to the report, an independent consultant possibly based in Bamako used Claude to build a national surveillance platform called "Lakana 360" for Mali's national intelligence agency, the "Agence Nationale de la Sécurité" (ANSE), monitoring about 25 million SIM cards across the country's three national mobile operators. The platform was designed to circumvent Malian law's requirement for a court order to disclose certain surveillance records. This page does not publish any surveillance logic or data fields.

p. 82–86

A commercial surveillance platform using AI to profile social accounts: GTG-54009 case

According to the report, a suspected commercial intelligence firm used Claude to build a prototype surveillance platform that batch-analyzed public posts by social media users in Iran and the Gulf region, inferred their location, group affiliation, and political leanings, and generated intelligence briefings in the style of government documents. The report discovered the operation during its pilot phase and found no evidence it was used against real targets.

Limits of response

Confidence language should not be upgraded. Ethnic and religious names only describe the target background the report describes.

Malware implementations, extension code, and concrete IOC values are not included on this site.