US Edition
Your source for latest news
TechnologyAI Security

Anthropic says seven Chinese AI labs ran industrial-scale campaigns to copy Claude

A threat report from Anthropic, following a joint FBI-NSA-CISA advisory, describes nearly 200 million exchanges in which Alibaba, DeepSeek, Moonshot AI and four other Chinese labs allegedly harvested Claude's outputs to train their own models, sometimes exposing sensitive government and corporate data in the process.

PT
By PressTemps Technology DeskPublished Yesterday, 21:26 ET · 6 min read
Anthropic says seven Chinese AI labs ran industrial-scale campaigns to copy Claude
Alibaba Group's Beijing offices at Greenland Center, Wangjing. File photo; Anthropic said Alibaba ran the largest of the distillation campaigns it documented. Photo: N509FZ / Wikimedia Commons, CC BY-SA 4.0
What to know
Anthropic attributed distillation campaigns to seven China-based AI companies: Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax, totaling nearly 200 million exchanges.
The largest campaign, tied to Alibaba, generated more than 151 million exchanges between May and July 2026 through over 3,500 fraudulent accounts routed via proxy services.
A joint CISA, NSA and FBI advisory issued September 8 separately named six Chinese firms and said they extracted billions of tokens from Claude, GPT, Gemini and Grok since late 2024.
China's Commerce Ministry rejected the claims as groundless and warned of "resolute countermeasures" if used to justify new restrictions on Chinese AI companies.

Anthropic said this week that seven China-based artificial intelligence companies ran sustained campaigns to siphon the reasoning and coding abilities of its Claude models and feed them into their own systems, in what the company called the largest such effort it has ever documented. The disclosure, published in a threat-intelligence report on September 10, came two days after the National Security Agency, the FBI and the Cybersecurity and Infrastructure Security Agency jointly warned that Chinese AI developers had been extracting capabilities from American frontier models on an "industrial scale" since late 2024.

The practice, known as distillation, involves feeding one model's outputs into another company's training pipeline so the second model mimics the first without the underlying research cost. It is a common and often legal technique within a single company; Anthropic's complaint is that the accounts used to harvest its outputs were fraudulent, that some of the resulting traffic exposed sensitive third-party data, and that the scale involved went well beyond ordinary use of a chatbot.

The numbers behind the campaigns

Anthropic's report names Alibaba, Moonshot AI, DeepSeek, Zhipu (marketed outside China as Z.ai), Xiaomi, SenseTime and MiniMax. The largest campaign, which Anthropic attributed to Alibaba, generated more than 151 million exchanges with Claude between May and July, peaking at roughly 3 million exchanges a day and drawing on more than 3,500 fraudulent accounts routed through proxy services the report calls "transfer stations." When Anthropic banned that pool of accounts, the traffic shifted to a second pool, some of which was also found funneling requests on behalf of DeepSeek and Xiaomi — evidence, Anthropic said, that rival Chinese labs share the same underlying proxy infrastructure.

Moonshot AI, maker of the Kimi models, was accused of silently rerouting some Kimi user requests to Claude and returning Claude's answers to customers as if they were Kimi's own, generating more than 23 million exchanges over the same window through roughly 5,380 accounts. Anthropic attributed more than 12.1 million exchanges over 14 days in July to DeepSeek, which it said built a pipeline to extract Claude's internal reasoning traces and separately rerouted users of its own models, when it detected they were working through coding tools such as Claude Code or OpenCode, to Claude Opus without telling them. Zhipu was tied to roughly 3.4 million exchanges over 17 days in June and July, Xiaomi to more than 400,000 over 20 days in March and April, and SenseTime and MiniMax to smaller campaigns built respectively on purchased transcripts and a proxy network run through a shell company. Combined, Anthropic said, the activity totals nearly 200 million exchanges.

Sensitive data caught in the middle

Anthropic's report says some of the rerouted traffic carried information its intended recipients never expected to leave their own systems. In one case tied to DeepSeek's rerouting, a foothold in a Chinese technology company's internal tools exposed the specifications and strategic plans of what Anthropic described as a flagship AI program; in another, credentials for a database belonging to a Russian government body linked to its defense ministry were exposed; in a third, engineers building a case-management system for a Chinese municipal public security bureau had queries — comparing residents' movements against police records by national ID number — relayed to Claude. Xiaomi's campaign, Anthropic said, separately swept up names, contact details and corporate data belonging to hundreds of the company's own users in more than a dozen languages.

Anthropic said it has responded by tightening account verification, banning resellers operating in regions where it does not officially support access, and changing how its models handle internal reasoning so that fewer raw traces can be captured and replayed. The company first flagged distillation activity in a report published in February 2026; the new disclosure describes a marked escalation since then.

A warning from Washington came first

Anthropic's findings landed just after a joint cybersecurity advisory issued on September 8 by CISA, the NSA and the FBI, which named six Chinese firms — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI — and said they had extracted "billions of tokens" from Claude, OpenAI's GPT models, Google's Gemini and xAI's Grok, likely with the Chinese government's awareness. The advisory, unusually, told American AI companies not simply to block suspected distillation accounts outright but to consider quietly degrading their outputs instead, on the theory that overt bans tip off operators to switch tactics. In an accompanying announcement, CISA's acting director framed the stakes in terms of competitive advantage rather than data theft alone.

"We strongly urge AI companies to take immediate steps to safeguard their platforms against knowledge distillation campaigns that threaten to close the gap in advancements made by American companies," said Nick Andersen, CISA's acting director.

Reporting on Anthropic's findings by TechCrunch, NBC News and The Hacker News noted that none of the seven companies named responded to requests for comment on the specific allegations.

Beijing calls the accusations a pretext

China's Commerce Ministry rejected the joint US advisory within a day of its release, calling the claims groundless and accusing Washington of pursuing a "monopoly of the AI industry" while showing "anxiety and double standards," according to wire reporting carried by KSAT. The ministry described distillation as a common technical method used by AI developers worldwide and warned that if the United States used the issue as a pretext to restrict Chinese AI firms, China would take "resolute countermeasures."

The dispute is unfolding as President Trump and Chinese leader Xi Jinping are expected to hold talks later this month in which AI policy is likely to come up. Treasury Secretary Scott Bessent, speaking separately in Dallas, argued that reliance on distillation put a ceiling on how far Chinese AI development could go, saying China "can never get ahead" of the United States because "the Chinese distill our models."

Who is most directly affected are the American AI labs whose models are being copied, the downstream customers of the accused Chinese products whose queries were allegedly rerouted without their knowledge, and the individuals and organizations — including, in Anthropic's telling, agencies inside China and Russia — whose data passed through those pipelines. Enterprise customers of Kimi, DeepSeek and Xiaomi's models may now face questions about where their prompts actually went.

Anthropic said it will keep publishing periodic threat updates and continue adjusting its models' handling of internal reasoning to make wholesale copying harder without degrading service for legitimate users. The CISA-led advisory asked frontier AI providers to share indicators of suspected distillation activity with each other and with the government, a step that would formalize the kind of account-banning and traffic-pattern analysis Anthropic says it has already been doing. With no independent verification of Anthropic's attributions available and the named companies silent, the immediate dispute is likely to play out in the run-up to the Trump-Xi meeting, where AI competitiveness is expected to be treated as a matter of national strategy rather than a private commercial disagreement between Silicon Valley and its Chinese rivals.

More on this story

All Technology