Technology

Industrial-Scale Catfishing: How 28 Dating Apps Ran 100,000 AI Chats a Day

Martin HollowayPublished 3d ago4 min readBased on 2 sources
Reading level
Industrial-Scale Catfishing: How 28 Dating Apps Ran 100,000 AI Chats a Day
Image by JESHOOTS-com from Pixabay

Anthropic traced a prepaid account generating more than 100,000 Claude API requests per day, automated calls from software to the AI model, to a network of around 28 fraudulent dating apps powered by autonomous AI personas, profiles that converse without human help. The discovery was described by Anthropic threat intelligence researcher Chris Cronbaugh, and shifts romance fraud from manual catfishing to automated operation at scale. The Verge

Cronbaugh presented the operation in a talk titled "Swipe Right, Pay Up: Industrial-Scale AI Catfishing" at the Sleuthcon cybersecurity conference. Anthropic published its findings in the scams and fraud section of its "Detecting and countering misuse of AI: September 2026" report.

The network relied on AI personas to carry out conversations with users across the 28 apps. The majority of chats involved no human agent at all. Automation handled first contact, small talk, persistence and escalation without operator intervention.

Only one in four matches were real people. Those people were paid gig workers rather than dating users. They existed inside the workflow to clear trust gates that pure software still fails.

The gig workers were hired to pass liveness checks on video, short live-video tests meant to confirm a real person is present. Once past that control, they did not write their own comments. They responded by selecting from three pregenerated replies. That constraint kept output consistent, reduced language errors and limited the need for trained operators.

Security researcher Matthew "Zigula" Gore-Kormanik encountered the system while analyzing Dora, one of the fraudulent apps. During his analysis he received a call notification from a persona named Jennifer.

Jennifer's bio described her as a 41-year-old Sagittarius with red hair, blue eyes and piercings. It listed interests in music, horror movies, nightlife and sports. The profile structure was conventional. Nothing in the metadata, the background data attached to the profile, signaled automation.

When Gore-Kormanik answered the call, his video feed showed a moving tapestry rather than Jennifer, with distorted background audio. No human was on the other end. The session behaved like a broken WebRTC negotiation, a failed setup for a browser-based video call, grafted onto a scripted persona.

After the call, Jennifer messaged Gore-Kormanik saying his voice was better than expected, although his microphone had not been connected. The comment was impossible in context. It exposed a state tracking failure between the voice, video and chat components, which were not sharing the same record of what had happened.

McAfee had described a wider pattern in Valentine's Day 2026 research on romance scams across dating and social apps, which found AI bots and fake profiles driving fraud. McAfee

The broader context here is operational, not just technical. API telemetry, the usage logs seen by the AI provider, provided the initial signal. Request volume, prepaid billing and uniform prompt patterns are easier to detect at the provider layer than fake profiles are to detect at the app layer. For defenders who work with LLM operations, rate limiting, caps on how many requests an account can make, use-case attestation, asking customers to state their planned use, and behavioral clustering, grouping accounts by similar activity, matter as much as content moderation.

Looking at what this means for authentication, liveness checks alone no longer settle the question of who is present. The workers passed the video gate, then the model resumed control of the conversation. That split, human for biometric proof and machine for dialogue at scale, suggests future controls will need continuous verification tied to session behavior rather than a single check at onboarding. The long-term advantage still favors defenders who can correlate identity, device, network and language signals, because industrial fraud leaves industrial traces.