Artificial intelligence is being used to run fake newsrooms, mass-surveillance systems, thousands of deceptive dating profiles and increasingly automated cyberattacks, according to a major new threat report from Anthropic.
The AI company says it disrupted operations involving criminals, suspected state-backed groups, propaganda organisations, surveillance operators and researchers between December 2025 and August 2026. The cases show AI moving beyond writing individual scam messages towards operating entire workflows with limited human involvement.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
One fake newsroom network published 8,913 articles
One of the clearest examples involved around 70 websites designed to look like independent local news organisations.
Anthropic traced the network to LKM Company, a France-based digital advertising agency. The operation also controlled around 70 matching X accounts and more than 250 additional fake commenting accounts.
At least 8,913 articles in roughly 20 languages were published across the network.
AI was used both to create original stories and rewrite reporting from legitimate journalists. The same underlying story could be repackaged with different political angles depending on the audience being targeted.
Articles were produced automatically with fixed HTML structures, character limits and internal links. Fake journalist names were then attached to them, making each website appear to have its own newsroom.
Anthropic said the operation targeted audiences across six continents but found little evidence that it successfully broke into genuine online communities.
That distinction matters. The operation demonstrated enormous production capacity, but not necessarily enormous influence.
4,700 AI dating personas sent 2.36 million messages
Another network shows how AI can industrialise personal deception.
Anthropic says a China-based operator ran more than 20 dating applications that presented automated personas as real people.
During just two weeks in April, more than 4,700 AI personas spoke with at least 25,000 users and generated about 2.36 million messages. Around three-quarters of the profiles shown to users were AI-controlled.
Real people were mixed into the system to perform tasks AI could not convincingly handle, such as live video calls and social-media follow-backs.
The AI personas were explicitly instructed not to disclose that they were automated and to move users through predefined stages of conversation.
This creates a different scale of fraud.
A conventional romance scam requires a human operator to maintain conversations with victims. An AI system can potentially maintain thousands at once, while humans intervene only when credibility needs to be reinforced.
AI surveillance can turn millions of posts into target lists
The report also describes AI being used to monitor political opponents and diaspora communities.
In one commercial operation, Claude was used to analyse people in Iran and the Persian Gulf, estimate their locations and political positions, and produce intelligence-style reports.
A separate Iranian-linked operation processed large volumes of social-media activity and identified 39 opposition accounts for monitoring. China-linked actors also used AI to classify politically sensitive material and identify people for what operators described as “control”.
The important change is speed.
A surveillance unit that previously needed teams of analysts to read posts, categorise users and prepare reports can now automate substantial parts of that work.
Cyberattacks are shifting from AI assistance to AI orchestration
Anthropic found the same pattern in offensive cyber operations.
One threat actor used AI throughout reconnaissance, phishing, credential theft, maintaining access and data exfiltration. If security software detected its malware, AI agents could automatically modify and rebuild the malicious software until it evaded detection.
Humans still selected targets and supervised operations, but AI increasingly handled execution.
This is an escalation from earlier cases.
In August 2025, Anthropic had already reported criminals using Claude for a 17-target extortion campaign and even helping relatively inexperienced criminals develop ransomware. By November, it documented a suspected Chinese state-backed group using AI to attempt intrusions against roughly 30 organisations with far less human intervention.
The September 2026 report says that operating model has now spread across several classes of attackers.
What does “agentic AI” mean here?
Ordinary chatbot use involves asking a model one question and receiving one response.
An AI agent can instead be given a broader objective and allowed to complete several connected tasks. It may collect information, use software tools, check whether a step worked and then decide what to do next.
That is what makes these cases important.
A malicious operator does not necessarily need AI to invent a completely new type of crime. AI can make existing fraud, propaganda, surveillance and hacking dramatically cheaper to run at much larger scale.
The report also documented five biological research cases with possible dual-use implications, including work involving pathogens, toxins and venom peptides. Anthropic stressed that it does not claim the researchers intended harm and said such scientific work can have legitimate medical applications.
What this means for you: Treat polished news sites, dating profiles and convincing online conversations as potentially synthetic until independently verified. For organisations, AI-generated activity should increasingly be treated as a scale problem: one operator may now be capable of running thousands of identities or automated attack tasks simultaneously.
The420 Insight: The biggest AI threat may not be a completely autonomous machine acting alone. The more immediate shift is leverage — a small team can now use AI to perform work that once required dozens or hundreds of writers, scammers, analysts or hackers.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics