SCAM

AI-Powered Dating App Network Used More Than 4,700 Fake Personas to Target 25,000 People

ADVERTISEMENT

Anthropic has disclosed a large-scale dating scam operation in which a China-based app studio used artificial intelligence to build and operate more than 20 dating apps, creating thousands of AI-generated personas that were presented to users as real people.

ADVERTISEMENT

The operation, tracked by Anthropic as GTG-15001, was identified as part of the company’s September 2026 threat intelligence report examining malicious uses of its Claude AI models.

According to Anthropic, the operators used Claude to build the dating app network and to power AI personas that communicated with users. The apps advertised their service as fully human, even though most of the profiles were operated by AI. During a two-week period in April 2026, Anthropic identified more than 4,700 distinct AI personas that collectively engaged in conversations with at least 25,000 unique individuals.

The scale of the operation was made possible by combining AI-generated conversations with a smaller number of real people.

Three AI personas for every human worker

The dating apps did not rely exclusively on bots. The operators recruited real people as gig workers and placed their profiles in the same matching feeds as the AI-controlled personas. Anthropic estimates that the operation maintained approximately a 3-to-1 ratio of AI personas to real people.

The human workers were used for interactions that the AI system could not perform, particularly live video calls and social media follows. Those interactions were designed to make the dating profiles appear authentic and reduce users’ suspicions that they were communicating with artificial personas.

The human workers themselves were also assisted by AI. Another model generated some of the messages they could send to users, allowing the operation to automate additional parts of the conversations.

Anthropic described the approach as a deliberate division of labor: Claude handled large-scale conversations, while real people provided capabilities that required direct human interaction.

Millions of AI-generated messages

Claude was used to operate the autonomous conversational personas at considerable scale. Anthropic estimates that the Claude-powered personas generated approximately 2.36 million messages during the two-week period examined by investigators.

Other AI systems were assigned different tasks rather than being used for the same purpose.

A small non-Anthropic model generated short reply suggestions for the gig workers. It was also used for face-attractiveness scoring and photo and voice moderation. An image-editing model was used to generate avatar imagery.

Anthropic said it shared the relevant information about those systems with the providers involved.

The investigation also found that the system prompt used for Claude was effective at eliciting in-persona responses in essentially all of the sampled conversations. From inside those exchanges, the monetization and deceptive nature of the operation were not apparent.

In a small number of sampled conversations, Claude’s own reasoning surfaced indications that users were experiencing serious harm or distress. Anthropic said that some users disclosed serious illness or acute distress, yet the model continued responding in character rather than refusing to continue the interaction.

Dating apps designed to evade app-store review

The operators also designed the applications to make the network more difficult for Apple and Google to identify. Developer documentation examined by Anthropic showed a UI controller that activated only during app-store review and remained dormant otherwise.

The operators also differentiated class names across more than 20 versions of the apps. According to Anthropic, this was intended to defeat similarity checks used by platforms to identify related applications.

The backend infrastructure could also fabricate activity.

It generated artificial likes and visitors, and could provide pre-recorded “video” when no real person was available. The system also tracked which users had begun to suspect that they were communicating with a bot.

How Claude personas, real gig workers, and a metered paywall combine in one feed
How Claude personas, real gig workers, and a metered paywall combine in one feed

These features allowed the operation to maintain the appearance of an active dating service while controlling how users encountered evidence that a profile might not represent a real person.

Multiple dating brands

Anthropic identified a number of dating app brands associated with the operation, including:

  • DORA
  • DONI
  • ROMI
  • LUMA
  • JOVIA
  • KIRA
  • GRACECHAT
  • HAVEN
  • NALO
  • LOVIA

Anthropic also identified additional variants using internal numeric IDs. The investigation found that the operation consisted of more than 20 app variants rather than a single application.

AI providers were assigned different jobs

One of the notable characteristics of GTG-15001 was that the operators did not depend on a single AI model for every part of the operation.

Instead, they used several AI providers for separate functions.

Claude was responsible for autonomous conversations with users. Another model assisted human workers by generating short responses and was also used for facial-attractiveness scoring and photo and voice moderation. A separate image-editing model generated avatar images.

Real people provided the remaining human capabilities, including live video calls and social-media follow-backs.

Anthropic said this allowed the operators to combine different AI systems and human workers into a single deceptive dating ecosystem.

The result was an operation in which AI handled the high-volume, repetitive communication while humans were brought in when direct interaction was necessary.

A larger version of an earlier scam model

Anthropic described GTG-15001 as a development of an earlier case it investigated in 2025.

In that earlier case, another actor created a Telegram bot that was offered as a service to other scammers. The bot generated dating-app messages that could be used in fraudulent conversations.

GTG-15001 used a similar underlying concept but operated on a substantially larger scale.

The operators deliberately assigned different tasks to multiple AI providers and combined those systems with real workers. Anthropic said the case did not involve novel techniques for misusing AI models, but its scale and the deliberate combination of multiple providers made it notable.

Proxy infrastructure used to obtain AI access

Anthropic also found that the operators relied on PRC-based API reseller and proxy infrastructure to obtain and rotate access to AI models at scale.

The infrastructure was used to circumvent Anthropic’s supported-region restrictions and usage policies.

This was part of a broader pattern identified in Anthropic’s September 2026 report, in which threat actors used proxy services to obtain access to AI models while attempting to evade geographic and account-level controls.

Anthropic ultimately banned the accounts and organizations it attributed to GTG-15001.

The company also worked with other AI laboratories to disrupt the operators’ use of multiple AI models.

Infrastructure

Anthropic published indicators associated with the operation that it assessed to be operator-controlled and useful for the security community.

The identified domains include:

  • heyhru[.]com
  • archat[.]us – app marketing site
  • file[.]archat[.]us – content delivery and API infrastructure
  • sitin[.]ai – gig-worker web application

The investigation also identified the IP address:

  • 38[.]129[.]138[.]244 – AS26042, a U.S.-based egress proxy through which the operation’s API traffic was routed. Anthropic observed this infrastructure in April 2026.

The identified backend infrastructure included:

  • managedkafka[.]heyhru-server[.]cloud[.]goog – the operator’s backend hosted on Google Cloud.

Anthropic also identified two mobile application package names:

  • com.qiga.vio
  • com.cavalier.nalo

Anthropic said it banned the accounts and organizations attributed to the operation, including disposable organizations and accounts belonging directly to the operators’ employees.

Because most of the accounts were associated with PRC-origin proxy networks, Anthropic said those accounts are frequently disrupted through broader account-abuse detection and enforcement measures.

The company also shared its findings with other AI laboratories whose models were used for non-conversational functions in the operation.

The GTG-15001 investigation illustrates how AI can change the economics and scale of online dating deception. Rather than requiring a large human workforce to maintain thousands of simultaneous conversations, the operators used AI to conduct millions of messages while reserving human involvement for interactions that were more difficult to automate.

Anthropic’s findings show that the operation was not simply a collection of fake dating profiles. It was a coordinated system combining AI-generated identities, automated conversations, human gig workers, multiple AI providers, image generation, fabricated engagement, review-evasion mechanisms and proxy infrastructure.

The company identified and disrupted the operation as part of its broader effort to detect and counter malicious uses of Claude.

How useful was this post?

Click on a star to rate it!

Average rating / 5. Vote count:

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

ADVERTISEMENT
ADVERTISEMENT

Admin

We help people recognize and avoid online scams by sharing reliable information about scam tactics, stolen photos, and fake profiles.

Related Articles

Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
ADVERTISEMENT