Anthropic said it identified and disrupted industrial-scale “distillation” attacks against its Claude models originating from seven China-based AI labs, according to a threat intelligence report the company released on September 11, 2026, and covered by The Hacker News. The company named Alibaba, Moonshot AI, DeepSeek, Xiaomi and Zhipu, also known as Z.ai, among the labs involved, saying they routed user conversations through Claude and used its responses as training data to improve their own models in violation of Anthropic’s terms of service.
Anthropic said the campaigns specifically targeted Claude’s most commercially valuable capabilities, including agentic reasoning, coding and tool use, and that some of the intercepted exchanges contained sensitive information belonging to individual users, multinational companies and state-affiliated actors. According to reporting on the report, Moonshot alone routed nearly 300,000 customer requests to Claude over a 10-day period through a network of more than 5,000 fraudulent accounts, with total distillation activity exceeding 23 million exchanges between May and July.
Anthropic said labs used commercial proxy services and account networks to evade detection, allowing new fraudulent accounts to replace banned ones without interruption. The disclosure adds to a pattern of Western frontier labs publicly accusing competitors of extracting model capabilities without authorization, a dynamic that is intensifying as US and Chinese AI companies compete for enterprise and developer market share.
Why it matters
Routing third-party traffic through a commercial model’s API to harvest its outputs is itself a data-handling risk for the end users caught in the middle, since their prompts and outputs can transit infrastructure they never consented to; enterprises building on any AI API should ask vendors directly what abuse-detection and data-isolation controls apply to their traffic.

Leave a Reply