Anthropic’s September 10, 2026 threat-intelligence report alleges that Alibaba-linked operators, Moonshot AI, DeepSeek and four other China-based AI labs used Claude at industrial scale to extract capabilities for competing models. The report describes fraudulent accounts, proxy networks, coordinated prompts and customer-query routing; a September 8 advisory from the NSA, CISA and FBI separately describes industrial-scale distillation campaigns against U.S. AI companies.
The allegations cover activity from late 2025 through August 2026, with the largest quantified campaigns taking place in 2026. China’s Ministry of Commerce rejected the U.S. allegations on September 9 and warned of countermeasures if Chinese AI companies were suppressed on that basis.
What happened, and who is making the allegations?
Anthropic says its investigation identified seven China-based labs or companies linked to campaigns targeting Claude: Alibaba, Moonshot AI, DeepSeek, Zhipu/Z.AI, Xiaomi, MiniMax and SenseTime. The U.S. advisory names a partly overlapping group of six: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI.
The different lists reflect the scope of each document. Anthropic’s report focuses on activity against Claude, while the government advisory describes a broader campaign against U.S. AI companies. The advisory says the activity began at least by late 2024 and was likely conducted with Chinese government awareness, a deliberately qualified assessment that does not say Beijing directed every operation.
Anthropic says the activity was disrupted and that it responded with behavioral classifiers, organization-level bans, stronger identity checks, intelligence sharing and changes that reduce the detail or usefulness of reasoning traces.
What does AI model distillation mean?
Model distillation is a standard training technique: a smaller “student” model learns from outputs generated by a larger, more capable “teacher” model. The technique itself is not inherently illicit. Anthropic and the U.S. agencies characterize the reported campaigns as unauthorized because they allege the operators used fraudulent accounts, geographic-restriction evasion, proxy services, automated failover and coordinated prompts to extract capabilities at scale.
The targeted capabilities allegedly included reasoning, coding, tool use, agentic workflows, computer use, data analysis, computer vision and software engineering. Some prompts allegedly sought detailed reasoning traces or recognizable patterns in a model’s reasoning, while other systems repeatedly queried Claude and retained its outputs for model development.
The main campaigns attributed to Anthropic
| Attributed actor | Period | Reported activity | Alleged use |
| Alibaba-linked operators | May–July 2026 | More than 151 million Claude exchanges through more than 3,500 fraudulent accounts | Supporting development of Qwen models |
| Moonshot AI | May–July 2026 | More than 23 million exchanges; nearly 300,000 customer requests allegedly routed through Claude during 10 days | Capturing Claude outputs for Kimi-related model development |
| DeepSeek | 14 days in July 2026 | More than 12.1 million Claude exchanges | Extracting capabilities for a competing model |
| Zhipu/Z.AI | June–July 2026 | More than 3.4 million exchanges over 17 days through 273 rotating accounts | Extracting and refining reasoning traces |
| Xiaomi | March–April 2026 | More than 400,000 exchanges over 20 days | Replaying MiMo conversations and coding sessions through Claude |
Anthropic also disclosed an earlier February campaign involving DeepSeek, Moonshot AI and MiniMax. It attributed more than 16 million exchanges to those campaigns and cited approximately 24,000 fraudulent accounts.
Why the customer-query allegation matters
Anthropic alleges that Moonshot AI and DeepSeek routed some real customer requests through Claude without users’ knowledge. For Moonshot, Anthropic says nearly 300,000 customer requests passed through Claude during one 10-day period. The claim matters because the requests could contain names, email addresses or corporate material rather than carefully designed benchmark prompts.
That alleged routing changes the dispute from model benchmarking to data handling and customer trust. A user asking Kimi or another assistant for help could, under the allegation, have part of the interaction processed by Claude through an intermediary. Anthropic has not said that every user or every request was affected.
Why chip controls may not close this route
The alleged extraction route operates through APIs, cloud providers, third-party aggregators and proxy services. It transfers model behavior through requests and outputs rather than through the physical movement of advanced chips. That is why the U.S. advisory treats API access and identity controls as part of the security problem alongside hardware export restrictions.
The advisory recommends detecting coordinated account activity, tightening responses to evasion techniques and sharing intelligence about access networks. Anthropic’s countermeasures follow the same logic: identify clusters of accounts and organizations, block them at the organization level and reduce the value of reasoning traces that can be harvested.
The political response
The September 8 advisory from the NSA, CISA and FBI called the activity industrial-scale distillation and named six Chinese companies. On September 9, China’s Ministry of Commerce rejected the U.S. allegations as unfounded in fact and law and warned that China would take countermeasures if the United States used model-distillation concerns to suppress Chinese AI companies.
The dispute has produced corporate allegations, a U.S. government advisory and a diplomatic response. As of September 12, 2026, the reported cases had not produced a court judgment or criminal conviction against the named companies.