Case · DiggingBeagle record

A dating-app network mixed thousands of AI personas with real workers

Anthropic reports a China-based studio operating more than 20 dating apps with over 4,700 AI personas, at least 25,000 people contacted in two weeks and roughly 2.36 million AI-generated messages.

Activity described in Anthropic's September 2026 threat report. The observed campaign window occurred in April 2026 but became public in September.

First seen
Sep 10, 2026
Case kind
incident
AI role
WITH AI
Claims
4

Reconstruction

The deception was operational rather than just conversational. Anthropic says the studio built more than 20 dating apps and mixed Claude-powered personas with recruited human workers. The feed was presented as human, while the reported ratio was roughly three AI personas for every real person.

The human workers handled the interactions that the bots could not convincingly complete, such as live video calls and social-media follows. Claude handled the autonomous conversations at much larger scale, with roughly 2.36 million messages over the two-week observation window. Other AI systems were assigned separate jobs such as image editing and short reply generation.

The apps were also engineered around platform review. Anthropic reports review-specific UI behavior and differentiated variants intended to reduce similarity detection. That makes the case relevant to security and trust: AI was one component in a broader system that concealed who or what users were actually interacting with.

Mechanism & boundary

  1. 01

    Build and operate multiple dating apps

    The studio deploys a family of applications presented as human dating services.

    Boundary: operator / app stores

  2. 02

    Mix AI personas with real gig workers

    Automation handles most text interaction while humans cover authenticity checks.

    Boundary: automation / human identity

  3. 03

    Run millions of conversations

    AI personas converse autonomously with users at scale.

    Boundary: persona / user

  4. 04

    Hide normal behavior during store review

    Review-specific logic and variant differentiation reduce platform visibility.

    Boundary: application / platform review

Timeline

  1. Sep 10, 2026

    Anthropic publishes GTG-15001 case study

    report

    The September threat report discloses the dating-app network.

Claims & evidence

reported findingsupported

Anthropic reports roughly three AI personas for every real person mixed into the dating-app feed.

Measured value
75 percent AI share implied by 3-to-1 ratio
Method
Derived from Anthropic's reported approximate 3-to-1 AI-to-human ratio
Period
two-week observation window
reported findingsupported

Anthropic reports more than 4,700 AI personas engaging at least 25,000 unique people across a two-week window in a network of more than 20 dating apps.

reported findingsupported

Anthropic reports that the apps included review-specific behavior intended to hide their normal functionality during App Store and Play Store review.

  • supports
    Countering misuse of AI: September 2026

    Locator: GTG-15001 store-review evasion

    Anthropic describes review-only UI logic and differentiated variants intended to reduce detection during store review.
reported findingsupported

Anthropic reports Claude-powered personas sending roughly 2.36 million messages over the two-week observation window.

Measured value
2360000 messages
Method
Anthropic threat-intelligence observation
Period
two-week observation window

Evidence visuals

chart

Deceptive dating-app network scale

Anthropic September 2026 threat report. Counts represent different objects and should not be combined.

Measurecount
AI personas4700
Unique people contacted25000
Messages2360000
Different count types; the chart is a scale view, not a conversion funnel. · Source: A dating-app network mixed thousands of AI personas with real workers

chart

GTG-15001 AI-to-human profile mix

Derived directly from Anthropic's approximate 3-to-1 AI-to-human ratio.

Measurepercent
AI personas75
Real workers25
Approximate ratio, not an audited census of every account. · Source: A dating-app network mixed thousands of AI personas with real workers

Implications

Identity assurance for conversational platforms has to examine the service architecture, not only individual model outputs. Hidden automation can be combined with human workers and platform-review evasion to create a convincing synthetic population.

Controls & mitigations

  • Require clear disclosure when conversational profiles are automated.
  • Use app-store and service-side controls that compare review behavior with production behavior.
  • Audit identity and monetization systems around AI personas, not only model responses.

What remains unknown

  • The public report does not name the apps or quantify direct financial loss.
  • The exact share of users who believed every profile was human is not established.

Cite this record

DiggingBeagle. “A dating-app network mixed thousands of AI personas with real workers.” First seen Sep 10, 2026. https://diggingbeagle.com/cases/a-dating-app-network-mixed-thousands-of-ai-personas-with-real-workers/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.