Skip to content

Anthropic reveals commercial espionage architecture targeting the Gulf: language models turn into tools for political classification and account intrusion

Share
Anthropic reveals commercial espionage architecture targeting the Gulf: language models turn into tools for political classification and account intrusion

Listen to this article

Read by Anchor

Anthropic disclosed the shutdown of an account used to build a commercial espionage platform that monitored social media users in the Gulf region and Iran, with the platform categorizing accounts demographically and politically and producing intelligence reports in Modern Standard Arabic that mimicked official government correspondence. The company explained in an extensive report on misuse of its models that the activity was carried out by a commercial intelligence entity called “S2T Unlocking Cyberspace”, which open-source sources indicate is an Israeli Singaporean firm, and suggested that it was developing a suite of commercial systems for Arabic-speaking clients in the Gulf.

The platform operated by feeding the “Claude” model about 25 posts per request, issuing automated commands to identify the poster’s category, residence and political leanings, and attaching a numerical confidence score to each inference. The system divided users into six main segments encompassing urban, rural, religious, military, youth and migrant categories, classifying each individual as either government-supporting or opposition. The exploitation went beyond monitoring to content generation, tasking the model with drafting posts under fictitious personas in Persian, Arabic, English and German, assigning orientations that simultaneously endorsed and opposed the Iranian regime, representing a direct use of artificial intelligence to manage both sides of polarization.

The report tracked a parallel track that focused onCreating a digital stock of over 255 fake accountsThey were prepared for publication on social platforms and classified into fine-grained segments, including one described as having a Gulf sectarian character and another masquerading as migrant labor residing in the United Arab Emirates. The operation generated ready-made tags covering sensitive regional issues such as the U.S. military presence in the Gulf, intended to give the fabricated accounts a convincing veneer that facilitates penetration of target circles. These details matched findings of an investigative report by the Forbidden Stories network in February 2023, which relied on a marketing brochure leaked from the company by the Colombian army, documenting the use of fake accounts to infiltrate private groups on WhatsApp and Telegram, harvest members’ data, and then move to phishing and implant spyware on phones.

This shift forces a recalibration of the digital threat equation for organizations and technical teams in the Gulf, Egypt and the Levant. Rental espionage firms no longer limit themselves to selling silent software vulnerabilities; they now employ language models as a low-cost operational layer to automate social engineering and fabricate digital identities in a coherent and convincing manner. This development undermines the effectiveness of traditional monitoring tools that relied on detecting linguistic errors to distinguish inauthentic accounts, which requires cybersecurity officials and institutional monitoring teams in the region to shift toward network-behavior analysis and scrutiny of unusual interaction patterns within closed messaging groups, rather than confining monitoring to open public arenas.

This incident puts the effectiveness of security gateways of major model providers on the test, as the subsequent suspension of accounts after they reach an advanced trial stage demonstrates that APIs remain vulnerable to use in sensitive intelligence activities. For the regional technology sector, this reality reinforces the importance of accelerating work on locally managed sovereign computing infrastructure and models, enabling the subjection of data-flow operations to national inspection and audit rules, while establishing controls that limit the ability of cross-border commercial tools to turn the Arab digital space into material for surveillance and political filtering.

Don't miss the next story

Subscribe for updates