This topic covers actors who use AI to process public or intercepted information at scale to infer sensitive attributes such as location, stance, and social relationships, or to build surveillance software. The core harm is non-consensual identification and long-term tracking.
The report involves commercial 'surveillance outsourcing,' state-affiliated agencies, and contractors. The classification focuses on specific behaviors and does not assess individual reader risk based on ethnicity, religion, or nationality.
Not to be confused with
Not the limited use of public information in journalism or academic research.
Not a place to find tools or field templates for 'looking up a person'.
Not 'banning accounts means the surveillance system is destroyed' — GTG-50027 makes clear: on-premises deployment was not stopped.
Original report figure: the funnel by which a commercial surveillance platform classifies social media content and generates briefings. Text in the figure is the original English.
AI roles
AI can replace analysis teams for translation, summarization, and templated profiles, and can also serve as engineering labor to design surveillance software.
Once 'public' information is aggregated, the nature of the risk changes: the subjects never consented to this use.
According to the report, an operation aligned with the Chinese government's collection direction used Claude to track, profile, and attempt to recruit members of Uyghur communities in Syria. The operator did not speak Arabic, and the model provided dialect drafting, real-time translation, and task quality checks. The report assesses with low confidence that the operator was a contractor rather than a direct national security organ. The ethnic label is the target background described by the report, not an indication that the group itself is at risk.
According to the report, a group of accounts aligned with the Chinese government's direction used Claude as an analysis team to generate Chinese-language profiles of religious leaders and diaspora figures across Asia, following internal templates. Targets included Catholic, Tibetan Buddhist, Falun Gong, and Taiwanese Christian communities. This page only discusses group-level privacy risks and does not include any individual names or location details.
According to the report, a group of accounts was used to carry out three operations: a local internet police public-opinion pipeline, a police academy student's 'stability maintenance' report, and a local state security department's daily briefing. Targets ranged from domestic petitioners to overseas democrats and human rights organizations. These are three operations within one article unit; 'one case' should not be understood as 'one incident.'
According to the report, an operation within China used Claude as an automated 'public opinion monitoring' and intelligence analysis system. The actor instructed Claude to generate government briefings listing dissidents, activists, ethnic minorities, Chinese diaspora communities, and foreign media as threats to political stability. The report assesses with medium confidence that the operation was carried out by a contractor working for government clients, rather than by a state organ acting directly.
According to the report, an Iran-linked threat actor used Claude to build an automated open-source intelligence identity profiling tool targeting Israeli government and non-government individuals and Jewish diaspora organizations. The actor also used Claude to modify the open-source LSASS credential dumper NanoDump and build a custom C++ obfuscation/build pipeline to obfuscate malware samples and hinder analysis.
According to the report, an Iran-linked threat actor used Claude to collect and analyze publicly available data to develop targeting recommendations against U.S. Navy forces in the region. The actor used Claude to write targeting handbooks, identifying and tracking naval positions based on open-source information. The same account also developed enterprise software for Iranian state systems, including designing a large-scale domestic surveillance platform combining automatic license plate recognition and mobile device identifier interception. This page does not publish any target coordinates or exploitation details.
According to the report, an Iranian threat actor used 16 free Claude.ai accounts across 16 single-operator organizations to develop malware, delivery pipelines, and phishing portals targeting domestic Iranian users. The delivery pages were designed to serve malicious content only to visitors with IP addresses from Iran, themed around censorship-circumvention tools and fabricated Persian-language news brands. The actor used Claude to develop the SECOMS64 modular Windows implant, including a keylogger, screenshot capture, Chrome credential extraction, and more. This page does not publish any malware code or phishing links.
According to the report, two units linked to Iranian paramilitary and domestic security agencies used 16 Claude accounts to build surveillance systems and a malicious Firefox browser extension. A seven-department organization claimed to maintain a database of Iranian national identity records and monitored and profiled 6,388 Iranians over one year. Another provincial unit based in Qom developed a malicious Firefox extension called "al-Najm al-thāqib" to mass-collect user identities from major social network platforms. This page does not publish any surveillance logic or extension code.
According to the report, an independent consultant possibly based in Bamako used Claude to build a national surveillance platform called "Lakana 360" for Mali's national intelligence agency, the "Agence Nationale de la Sécurité" (ANSE), monitoring about 25 million SIM cards across the country's three national mobile operators. The platform was designed to circumvent Malian law's requirement for a court order to disclose certain surveillance records. This page does not publish any surveillance logic or data fields.
According to the report, a suspected commercial intelligence firm used Claude to build a prototype surveillance platform that batch-analyzed public posts by social media users in Iran and the Gulf region, inferred their location, group affiliation, and political leanings, and generated intelligence briefings in the style of government documents. The report discovered the operation during its pilot phase and found no evidence it was used against real targets.
Limits of response
The relationship between contractors and agencies is often of medium or low confidence and cannot be upgraded to confirmed.
This topic page does not include personal names, accounts, floor plans of facilities, or real-time locations.
Is it legal for others to analyze what I post on social media?
Laws vary by jurisdiction. The report focuses on non-consensual inference of sensitive attributes and surveillance uses. This site does not provide legal advice; it only explains risks.
Why do some cases omit names?
To avoid secondary harm. The mechanism is sufficiently explained at the population level; there is no need to reproduce individual profiles.