Anthropic alleged that three China-based AI labs—DeepSeek, Moonshot AI, and MiniMax—used roughly 24,000 fraudulent accounts to generate more than 16 million interactions with Claude in a coordinated effort to extract the model’s advanced reasoning, coding, and tool-use capabilities. The company said it linked the activity through IP correlations, request metadata, and infrastructure indicators, and warned that large-scale unauthorized distillation could remove safety guardrails and enable copied capabilities to be used in offensive cyber operations, disinformation, intelligence collection, and mass surveillance. Anthropic said it shared its findings with U.S. government entities and industry partners, while noting it had no evidence that the Chinese government directly coordinated the campaigns.
The allegations surfaced as Anthropic remains in a separate high-stakes dispute with the U.S. Department of Defense, which on June 4 refused to reverse the company’s designation as a supply-chain risk. Anthropic is challenging the Pentagon’s March blacklisting after Defense Secretary Pete Hegseth invoked emergency powers following failed talks over limits on Claude’s use for domestic surveillance and autonomous weapons. Federal attorneys told the court the procedural dispute over administrative remedies is now moot because the secretary has denied reconsideration, and reporting indicates a majority of the appellate panel appeared inclined to let the designation stand while the case proceeds.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
According to a June 4, 2026 court filing, the U.S. Department of Defense denied Anthropic’s administrative request to reverse its supply-chain risk designation. Federal attorneys argued this denial mooted the question of whether Anthropic had sued before exhausting administrative remedies.
A three-judge federal appeals panel heard arguments in Washington, D.C., in May 2026 over Anthropic’s challenge to the Pentagon blacklisting. According to the report, a majority of the panel appeared inclined to allow Hegseth to proceed with the designation.
In March 2026, Defense Secretary Pete Hegseth invoked emergency powers to designate Anthropic as a supply-chain risk after talks failed over limits on use of Claude for domestic surveillance and autonomous weapons. Anthropic later challenged the designation in federal appeals court.
Anthropic said three China-based AI labs—DeepSeek, Moonshot AI, and MiniMax—used about 24,000 fraudulent accounts to generate more than 16 million exchanges with Claude in an effort to extract advanced model capabilities. The company said it identified the activity through IP correlations, request metadata, and infrastructure indicators and shared its findings with U.S. government entities and industry partners.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcefoxnews.com
Open sourceismg-cdn.nyc3.cdn.digitaloceanspaces.com
Open sourceismg-cdn.nyc3.cdn.digitaloceanspaces.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.