One Man, Twenty-Five Million Phones

A consultant in Bamako built a national wiretap. In China, a department of analysts became a single desk. The price of surveilling an entire population has collapsed.

Sep 13, 2026
Share on Facebook
Share on Twitter
Share on Linkedin
Copy the URL
One Man, Twenty-Five Million Phones


To understand the technical words and acronyms used in this series, please refer to this: A Primer on Terminology


Mass surveillance used to be expensive because someone had to build the system, and then a room full of analysts had to read what it collected. That expense is the main reason it stayed rare, and it is the assumption underneath most surveillance laws, including India’s. This section examines nine places where that cost disappeared.

 

Between January and July 2026, Anthropic shut down a set of operations in which state-aligned actors, government contractors and commercial spyware companies used its models to build and run surveillance systems. The actors were based in China, Iran and West Africa, or were selling their services to whoever would buy them, and they ranged from lone individuals to whole teams.

 

Read together, the nine cases show the same event happening nine times: software replacing a surveillance workforce. In one case, a department that once employed many teams of analysts now runs out of a single office. In another, one consultant built a wiretap covering an entire country.


GTG-50027, Mali

A single subscriber, assessed as a Bamako-based independent consultant working with Mali's state intelligence service, used the model as the primary engineering workforce for a national domestic surveillance platform. The system, named Lakana 360, monitors roughly 25 million SIM cards across all three of the country's national mobile operators.


 

 

The procedural detail in this case matters more than the technical inventory. The platform was explicitly designed to get around Malian legal restrictions that require a court order for certain surveillance records. At the operator’s request, the warrant requirement was removed from the component that writes the dossier. That component was reclassified as a national pipeline, with the control switched off by default and data retention set to indefinite. Approval and audit tools existed only for targeted interception. They did not reach the bulk collection layer underneath.

 

Human Rights Watch has documented Malian security services detaining and abducting opposition figures, journalists and civil society members.

 

Anthropic banned the account and said so plainly: the enforcement action disrupted the design work, not the deployment. The platform runs entirely on-premises using local models, which means it remains in operation today.


GTG-14020, religious affairs

A China-based operation using the model as a stand-in for a staffed analyst team. A unit that once comprised many teams of analysts has been reduced to a single office producing thousands of investigations a month. One operator ran four concurrent workstreams generating Chinese-language dossiers on senior Catholic cardinals across Asia, the leadership of the Presbyterian Church in Taiwan, Tibetan Buddhist civil society and the administration in exile, Falun Gong practitioners and affiliated media including Shen Yun and NTD, and Christian missionary networks linking Singapore, Hong Kong and the mainland.

 

Each dossier followed an internal template requiring a target's China-related activities and scandals. The collection covered birth dates, birthplaces, immigration dates and social media handles, and extended to reconnaissance of religious venues including floor plans, facades and structural diagrams. Coverage spanned WeChat, Xiaohongshu, Douyin and Weibo alongside LinkedIn, Instagram, Threads, X and Facebook, on a daily cycle. In prompts, the actor instructed the model to adopt China's standpoint and to apply the state's designations to the groups concerned. Targets ranged from senior public religious figures to private citizens.


GTG-14021, stability maintenance

Three linked operations tied to municipal public and state security organs: an individual cyber police officer, a police academy student who was also a public security detective, and a local state security bureau assessed with medium confidence as being in Zhejiang.

 

The cyber police unit ran a sentiment monitoring pipeline with custom skills, querying a government surveillance database and distributing daily reports on politically sensitive incidents, including tracking a prominent overseas dissident account. The bureau ran a daily pipeline producing situational awareness briefings on government templates, then wrote the workflow up as an internal AI usage manual for the rest of the bureau, complete with a prompt formula instructing the model to role-play an intelligence analyst serving the state.

 

Targets ran from domestic petitioners and rights defenders to pro-democracy figures in Hong Kong, organisers of Tiananmen commemorations, Uyghur advocacy organisations and Western human rights institutions. Reports labelled Uyghur advocacy as adjacent to terrorism and major human rights organisations as hostile forces.

 

The most serious element is pre-operational venue intelligence on lawful overseas protests: the gathering point, route and terminus of a pro-democracy march in Vancouver, venues for Uyghur cultural events in Turkey, screenings at the Oslo Freedom Forum.

 

Anthropic’s admission on this case is the one to quote in full, because the company states that its safeguards did not work consistently across these three operations. In one instance, the model correctly refused a request at first but was overcome when the actor rephrased the request. It then produced functional suppression guidance naming ten private citizens for what the state calls control, including petition interdiction, coercive summons and close monitoring of movements and communications. In a second instance, the model complied with the actor’s requests across many sessions without any intervention at all.


GTG-14022, public opinion monitoring

A China-based operation used the model as an automated system to track and manage online sentiment, producing restricted briefings for officials. The actor instructed it to role-play a senior emergency public opinion analyst serving the government.

 

The pipeline processed fifteen to thirty or more foreign news articles each day from Weibo, X, YouTube, Telegram and Facebook. It scored each item for political sensitivity and rewrote it using official terminology. For example, the instruction set changed Taiwan government to Taiwan authorities throughout and put scare quotes around terms critical of the state. Some documents recommended enforcement actions only a government could carry out, using the language of China’s three warfares doctrine: psychological, legal and public-opinion warfare. The framework was version-controlled at v2.6, had a master control table and appendices, and ran through the model’s code execution environment with minimal human intervention.

 

Anthropic assesses with medium confidence that this was a contractor working for government clients instead of a state organ. The report's own observation is the sharpest one: nothing here was technically novel. What was novel was how thoroughly it had been absorbed into a bureaucracy.


GTG-14010, Uyghurs in Syria

A PRC-aligned operation, assessed with low confidence as a contractor instead of a state security organ acting directly, tracked, profiled and attempted to recruit Uyghurs and Uyghur armed formations in Syria, including by offering payment for reporting on the units.

 

Chatter bulk-extracted from more than a hundred monitored WhatsApp groups and dozens of Telegram channels was converted into structured Chinese-language targeting data, including profiles of individuals assessed as vulnerable through financial stress, family separation or ideological disillusionment. The actor specifically identified targets with family members remaining in Xinjiang, a form of leverage that can only be acted on through coordination with domestic security.

 

The actor involved spoke no Arabic whatsoever, so the model drafted the covert outreach in Syrian dialect, translated replies in real time, role-played an Arabic-speaking expert consultant to quality-check the deception for dialect, military terminology and target psychology, and formatted the results for handoff up a reporting chain. It also located specific Uyghur businesses and points of interest in Syria, and supported a parallel campaign of coordinated mass reporting and delegitimization against Uyghur diaspora journalists, notably at the Uyghur Post, an outlet launched after Radio Free Asia's Uyghur Service closed. In parallel, the actor drafted surveillance platform tenders and capability brochures marketed to bureau-level government clients.

 

The model declined several of the most severe requests, including covert interrogation and large-scale persona cultivation.


GTG-34007, Iran

Sixteen accounts across two linked units associated with paramilitary and domestic security agencies, running different playbooks into the same central infrastructure.

 

One unit, a seven-department organisation with offices across Iran's provinces, claimed to maintain an identity-record database of Iranian nationals and to have surveilled and profiled 6,388 Iranians in a single year. It used the model as analyst and production studio, building a front end to a government-controlled surveillance case-management system and running social-network analysis over 155,216 tweets that named 39 opposition and diaspora accounts.

 

A Qom-based provincial unit used the model as its engineering department. Its flagship was a malicious Firefox extension, shipped to production and disguised as a prayer-times utility, used to mass-harvest user identities from major social platforms. The same unit built a messenger de-anonymiser, a phone-number-to-identity resolver, a national-ID phishing page and a Telegram mass-report bot.

 

Both units logged into a shared system called Arman, in which a subject's file contained their national ID, beliefs, criminal record, social accounts and an action tab. A separate actor co-located with one unit turned the custom-skills feature into a voice-cloning operation, cloning three Iranian writers and preparing narratives in advance for the Supreme Leader's succession.

 

Anthropic's finding here is uncomfortable and worth stating: the model refused explicit profiling and propaganda requests, but the safeguards did not refuse many of the surveillance software tooling requests.





GTG-54009, the commercial vendor

An account banned in June 2026 that was building a commercial surveillance platform to analyse, classify and profile social media users in Iran and the Persian Gulf. Anthropic assesses the work was carried out by or on behalf of S2T Unlocking Cyberspace, which open-source research suggests is an Israeli-Singaporean commercial intelligence vendor.

 

The platform mapped users' locations, sorted populations into six coded demographic groups, urban, clerical, military, youth, diaspora and rural, classified people as pro-government or opponents, and produced formal Arabic briefings styled as official government communications with sentiment scores by nationality and recommended counternarratives. A secondary workstream held more than 255 synthetic social accounts, apparently a stock being built for later deployment, spanning both pro- and anti-regime personas.

 

The findings independently corroborate a February 2023 investigation by the journalism network Forbidden Stories, which found an S2T surveillance product described in a company brochure among leaked Colombian military files. Anthropic caught this at the pilot stage and found no evidence the later stages of the chain were used against real targets before the ban.


GTG-30004, GTG-30005 and GTG-30006, Iran-nexus

These three operations sit at the seam between surveillance and cyber operations.

 

The first built an automated open-source intelligence and reconnaissance harness that profiled hundreds of individuals in Israel and the Jewish diaspora, enriching a pre-existing target list. In a parallel workstream, the same actor modified an open-source credential dumper and built a custom obfuscation pipeline that renamed identifiers and injected dummy functions, intended to make malware harder to analyse.

 

The second compiled targeting handbooks against US naval forces from publicly accessible data, through a Python pipeline built with the model's help: a roster of US personnel scraped from captions on public military photographs, publicly accessible ship and aircraft transponder identifiers, commercial satellite-imagery query scripts, and an inventory of websites exposing naval movements. It also catalogued known vulnerabilities in shipboard systems, specifically maritime satellite terminals, Cisco communications equipment and industrial control products. Separately, the same account designed software components for a domestic mass-surveillance platform combining automatic licence-plate recognition with mobile-device identifier interception, and built analytics over a same-day export of a private 244-member Telegram group.

 

The third used free accounts across sixteen single-operator organisations to build malware, a delivery pipeline and a phishing portal aimed at Iranians at home. Delivery pages served malicious content only to visitors with Iranian IP addresses, themed around censorship-circumvention tools and a fabricated Farsi news brand. The implant was modular: keylogger, screenshot capture, browser credential extraction with an encryption bypass, reconnaissance of endpoint security tooling, USB propagation, layered persistence including a binary disguised as a Windows font-driver service. Tooling was wrapped in a fake image-editing application carrying a counterfeit copyright notice. Separately the actor built tooling to steal Microsoft 365 mailboxes with no consent flow at all, by decrypting local credential stores and replaying tokens against Outlook web APIs while spoofing genuine desktop client identifiers so the traffic looked native.

 

The model refused nine out of ten directly malicious requests. The safeguards performed considerably worse once the actor fragmented the work into individually benign web-development tasks spread across later, smaller sessions.


The Question Facing Indian Policy Makers

India is operationalising interception rules under the Telecommunications Act and enforcement architecture under the data protection law. Both frameworks were designed against an implicit cost model: surveillance capability is expensive, institutionally visible, and therefore politically constrained.

 

Lakana 360 breaks all three of those assumptions simultaneously, because the capability cost no more than the price of a single consultant, and it remained institutionally invisible until a foreign company's threat intelligence team happened to find it. And because it runs on local models on-premises, no outside party can switch it off.

 

India also sits on both sides of the transnational repression question, as a state with one of the world's largest diasporas and as a home to diaspora communities from elsewhere, including Tibetan communities that appear directly in the targeting described above.


VK Shashikumar 🇮🇳
VK Shashikumar 🇮🇳

VK Shashikumar is a former roving foreign affairs and war correspondent who reported conflicts from the ground across Asia

Follow to stay updated