BETA nonprofit public democratic european moderated

Search

#SyntheticPersonas

Disinformation for hire – the network of 70 fake newsrooms sold as a service The websites looked local. Naija Pulse appeared to cover Nigeria, Echo Berlin Germany, The British Daily Britain, Fifty States the United States and Commonwealth Post Australia. Each had its own branding, articles, supposed journalists and matching social-media presence. Taken individually, they resembled small independent news outlets. According to Anthropic, however, they were parts of a single commercial influence network spanning six continents. Anthropic’s September 2026 threat report identifies the operation as GTG-54002, a commercial “influence-as-a-service” network that used Claude to generate and rewrite political content at industrial scale. Investigators linked roughly 70 fabricated news websites to around 70 matching X accounts and more than 250 additional inauthentic commenting accounts designed to create the appearance of genuine public engagement. The network produced at least 8,913 articles in about 20 languages before Anthropic disrupted the activity. The significance of the case is not simply the number of fake sites. It is the business model. The network did not consistently promote one government, party or ideology. Anthropic found that its political position changed according to the apparent interests of different customers. The company therefore described it as a commercial influence operation: political manipulation offered in much the same way as other outsourced digital services. A fake media ecosystem built at scale Anthropic says the infrastructure was created rapidly. Domains were registered from France during a roughly ten-week period in mid-2025 and deployed through shared technical infrastructure, allowing investigators to connect publications that outwardly appeared unrelated. Most of the supporting social-media accounts were also created within a narrow timeframe in June and July 2025. The sites were designed to look like functioning local newsrooms rather than anonymous propaganda pages. Articles carried fabricated bylines belonging to journalists who, according to Anthropic, did not exist. Each outlet had a corresponding account on X, while a second layer of fake profiles commented on and amplified the articles. Many of those accounts used AI-generated profile photographs. The result was a three-tier structure: the newsroom published the story, the branded social account distributed it, and apparently ordinary users supplied the appearance of public reaction. Some of those sites remained publicly visible after the operation was exposed. The British Daily, for example, described itself as providing “conservative insights” on British sovereignty and migration, while Commonwealth Post presented itself as an Australian liberal publication focused on democracy, migration and regional security. Those contrasting editorial identities illustrate the central feature identified by Anthropic: the network was capable of taking different political positions in different markets. Claude as a publishing engine Claude was not simply asked to draft occasional articles. The operators built a structured production pipeline around it. Prompts required fixed JSON outputs, formatted HTML, precise character limits and internal links, allowing articles to move directly into an automated publishing workflow. The system could generate entirely new material or take reporting produced by legitimate journalists and rewrite it to fit a desired political perspective. Anthropic identified three recurring techniques. The same source article could be rewritten in opposite ideological directions for different audiences; a political interpretation could be added to a story that originally contained none; and material could be moved from one country to another after its original context had been removed. The articles were also structured to improve the apparent authority of the sites in search engines, helping the network imitate ordinary digital publishing practices rather than simply broadcasting propaganda. This is where generative AI changes the economics of an influence operation. A conventional network of dozens of supposedly local publications would normally require writers, translators, editors and social-media staff. Here, much of that production could be standardised and automated while human operators concentrated on political direction, customer requirements and distribution. The DRC–Rwanda conflict as a test case The clearest concentration of activity involved the Democratic Republic of Congo. Anthropic identified 318 articles concerning the DRC across the fake-news network. The material generally supported positions aligned with the Congolese government, particularly on regional mineral agreements and tensions with Rwanda. Early in the network’s growth, many of the fake social-media personas following and amplifying its accounts also presented themselves as Congolese. Investigators observed one especially revealing episode on 11 September 2025, when multiple sites published almost identical articles about the DRC–Rwanda conflict within approximately three minutes of one another. The wording and political tone were adjusted for different regional audiences, while associated X accounts distributed the links in a coordinated pattern. Anthropic said the activity contained signals suggesting that one or more customers had interests connected to the DRC–Rwanda conflict. It did not, however, identify those customers and explicitly stated that it found no evidence that any government had directed the operation. That distinction is essential. The content may have benefited a political actor without demonstrating that the actor commissioned or controlled it. Influence without ideology Commercialisation is what distinguishes GTG-54002 from many state-linked information operations. A government propaganda network usually has an identifiable strategic direction. A commercial influence provider does not need one. Its infrastructure can support one position in one country and the opposite position somewhere else, provided different customers are willing to pay. That makes attribution more difficult. Analysts cannot necessarily infer the operator from the ideology of the content because ideology may simply be part of the service package. The enduring asset is the infrastructure: domains, publishing systems, fake journalists, social-media accounts and automated amplification. Anthropic says the operation was disrupted before it achieved significant genuine reach. It classified GTG-54002 as Category Two on the Brookings Breakout Scale: material circulated across the network’s own sites and associated social accounts but showed no evidence of substantial penetration into authentic communities. Most of the 8,913 articles generated little observable engagement from real users. That limited impact is important. The case should not be presented as a successful global manipulation campaign. It is better understood as evidence that the infrastructure required to run such campaigns has become cheaper, faster and increasingly commoditised. The deeper shift is that a fake media ecosystem no longer has to be built around a single political cause. It can be built once, automated and then repurposed for the next customer. Disinformation, in this model, is no longer only a political instrument as it turend into the service. Sources: Anthropic — Countering misuse of AI: September 2026 https://www.anthropic.com/threat-intelligence-report-september-2026 Business Standard — AI scaling fake newsrooms, surveillance and online scams https://www.business-standard.com/technology/tech-news/anthropic-report-ai-fake-newsrooms-dating-surveillance-scams-126091100730_1.html Mimikama — KI baut 70 erfundene Nachrichtenportale https://www.mimikama.org/ki-netzwerk-erfundene-nachrichtenportale-echo-berlin/ Poliscoop Media — Anthropic exposes DRC propaganda network https://www.poliscoopmedia.com/articles/anthropic-exposes-drc-propaganda-network-20260911 The British Daily — example of a fabricated outlet identified in the network https://www.british-daily.com/contact Commonwealth Post — example of a fabricated outlet identified in the network https://commonwealth-post.com/category/science MalPulse — infrastructure references for network domains https://www.malpulse.com/infra-pivots/usom-pivots/list/?page=1105 Keywords: #DISINFORMED #Episode13 #DisinformationAsAService #InfluenceAsAService #FakeNewsrooms #FakeMedia #SyntheticMedia #ArtificialIntelligence #AI #GenerativeAI #ClaudeAI #Anthropic #Disinformation #InfluenceOperations #InformationWarfare #FIMI #CommercialInfluence #PoliticalManipulation #NarrativeManipulation #NarrativeLaundering #SourceLaundering #MediaImpersonation #FakeJournalists #SyntheticPersonas #Astroturfing #SocialMediaManipulation #CoordinatedInauthenticBehaviour #CIB #DigitalInfluence #AutomatedPropaganda #ContentAutomation #AIPropaganda #LKMCompany #NaijaPulse #AxumVoices #JamboJournal #EchoBerlin #TheBritishDaily #FiftyStates #CommonwealthPost #DRC #Rwanda #OSINT #WRLD

Countering misuse of AI: September 2026 / Anthropic

IRAN: MEK/NCRI – when AI impersonated a real activist in live conversations For years, synthetic media has largely meant fabricated images, cloned voices and manipulated video. A case uncovered by Anthropic in September 2026 suggests a more consequential development: artificial intelligence being used not merely to imitate how a person looks or sounds, but to behave as that person in an ongoing conversation. Anthropic says it dismantled a distributed influence operation targeting Iranians inside the country and abroad that it linked to the People’s Mojahedin Organization of Iran, or PMOI/MEK, and its political front, the National Council of Resistance of Iran. The operators used a shared AI-agent platform to support impersonation, audience profiling, coordinated social-media activity, synthetic personas and the laundering of organisational content through apparently independent accounts. At least four people involved in the operation worked for official NCRI media outlets, according to Anthropic. The company also found references to committee approval processes and MEK leadership, but said it could not independently determine the precise level of central control. Cloning a person from 8,400 Telegram posts The most striking part of the operation involved a real activist whose Telegram identity was copied. According to Anthropic, the operators instructed Claude in Persian that it was now that person, then provided approximately 8,400 of the activist’s Telegram posts so the system could learn and reproduce his writing style. The AI-assisted account was subsequently used to conduct live political conversations with the activist’s existing contacts. Anthropic says that, to its knowledge, the people receiving those messages did not know they were interacting with an account being operated with AI assistance. This is materially different from a conventional chatbot or a static deepfake. The system was not simply producing a forged statement attributed to someone else. It was using a large archive of that person’s authentic language as behavioural training material, then applying the resulting imitation interactively. In practical terms, the deception moved from synthetic content to synthetic identity. Anthropic did not publish the identity of the impersonated activist, nor details of his contacts, and the public report does not establish what specific information the conversations produced. What it does establish is that the impersonation was operational rather than experimental: the cloned account was used in real exchanges with real people. From social-media monitoring to psychographic dossiers The impersonation sat inside a much broader targeting system. Anthropic says the network scraped more than 500 social-media channels and categorised individuals by location, age, profession, political orientation and arrest history. It then analysed approximately 51,944 archived messages from conversations to construct detailed psychographic dossiers on dozens of people inside Iran. The system was therefore not limited to broadcasting propaganda. It was also designed to understand specific audiences and individuals. Profiles could be used to decide what kind of message was most likely to resonate with a particular person, which political identity they appeared closest to and how they should be approached. Anthropic describes this as a structured targeting funnel rather than ad hoc social-media activity. That distinction is important in the Iranian context. Political activists, dissidents and opposition contacts inside Iran can face arrest and severe punishment. The report does not show that the dossiers directly led to arrests or other harm, but collecting and organising information such as arrest history and political affiliation adds a surveillance dimension to what would otherwise be described as an influence operation. A shared AI system for an influence network Anthropic found that the actors used a shared Claude-based platform named “Viktor”, with separate workspaces and persistent memory. Those memory files contained approved sources, prohibited words, account-management instructions and methods intended to reduce the risk of detection. One operator loaded MEK founding doctrine into the system as what the report called “strategic base data”, allowing others to reuse it across their work. This persistent-memory structure meant the AI did not have to be briefed from scratch for every task. Once doctrine, stylistic rules and operational constraints had been stored, the system could repeatedly produce material consistent with the network’s objectives. Anthropic says the same general playbook appeared across different workspaces despite the operators not sharing obvious account infrastructure. The network also used automated pipelines to coordinate Instagram posting schedules and tailor messages to different audiences. Some accounts initially avoided mentioning the Mojahedin at all, allowing material aligned with MEK/NCRI narratives to appear as neutral or independent political commentary. Content was distributed through the organisation’s own media ecosystem as well as accounts presented as ordinary news or activist profiles. Anthropic assessed the campaign as Category Two on its Breakout Scale: active on multiple platforms with distribution through NCRI-linked media properties and amplifier accounts, but without evidence of broad authentic penetration. Synthetic citizens and disguised organisational media The same infrastructure generated AI avatars presented as ordinary Iranians, complete with Persian audio, to promote Maryam Rajavi’s political programme. Anthropic says the synthetic nature of these personas was intentionally concealed. Operators also rewrote and redistributed content originating from MEK-affiliated media while stripping identifying features or presenting it through apparently independent accounts. The network’s political messaging targeted the Iranian government but also rival opposition currents, including monarchists and supporters of the Pahlavi camp. Anthropic documented fabricated video material attacking a member of the Pahlavi family and the use of the slogan “Neither Shah Nor Sheikh”, consistent with the NCRI’s broader competition with other opposition movements. That rivalry provides relevant context. Reuters describes the MEK as one of Iran’s principal organised opposition movements in exile and the dominant force behind the NCRI, led by Maryam Rajavi. Its relationship with other opposition currents is often contentious, while the extent of its support inside Iran remains uncertain. What can be attributed – and what cannot Anthropic’s attribution is unusually specific but still needs to be stated carefully. The company says its investigation linked the operation to MEK/NCRI and established that at least four participants worked for official NCRI media organisations. It also found a common operational playbook, committee review structures and repeated references to MEK leadership. On that basis, Anthropic said central tasking was likely. It nevertheless stopped short of saying it had proven that NCRI’s senior leadership directly ordered or managed every component of the operation. That caveat matters. The strongest public evidence supports describing GTG-84006 as a MEK/NCRI-aligned influence operation involving personnel from official NCRI media, rather than asserting that every action was directly commanded by the organisation’s top leadership. The broader significance of the case lies elsewhere. Earlier generations of synthetic media attempted to fabricate evidence: a photograph, a voice recording or a video. Here, AI was used to maintain an identity over time, remember doctrine, analyse targets and speak directly to real people while appearing to be someone they already trusted. The deepfake was no longer merely an artefact. It had become a participant in the conversation. Sources Anthropic — Countering misuse of AI: September 2026 https://www.anthropic.com/threat-intelligence-report-september-2026 AI Misuse Case Library — GTG-84006 activist impersonation case https://www.misuseofai.com/en/cases/gtg-84006-activist-impersonation/ Reuters — Who makes up Iran’s fragmented opposition? https://www.reuters.com/business/media-telecom/who-makes-up-irans-fragmented-opposition-2025-06-18/ Reuters — Iran’s divided opposition senses its moment https://www.reuters.com/world/middle-east/irans-divided-opposition-senses-its-moment-activists-remain-wary-protests-2025-06-19/ Reuters — NCRI and Maryam Rajavi https://www.reuters.com/world/middle-east/dissident-leader-abroad-urges-iranians-bring-down-khamenei-2025-06-24/ Keywords #DISINFORMED #Episode12 #Iran #MEK #PMOI #NCRI #IranianOpposition #Disinformation #InfluenceOperations #InformationWarfare #ArtificialIntelligence #AI #GenerativeAI #ClaudeAI #Anthropic #AIDeception #AIImpersonation #IdentityImpersonation #SyntheticIdentity #InteractiveDeepfake #DigitalImpersonation #PersonaCloning #BehaviouralCloning #Telegram #PsychographicProfiling #TargetProfiling #AudienceTargeting #SocialMediaManipulation #Astroturfing #SyntheticPersonas #NarrativeLaundering #CoordinatedInfluence #PoliticalInfluence #DigitalInfluence #OppositionPolitics #IranPolitics #OSINT #WRLD

Countering misuse of AI: September 2026 / Anthropic