The NSA, CISA, and FBI issued a joint advisory alleging that China-based AI companies have systematically extracted proprietary capabilities from U.S. frontier models since late 2024. The advisory named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, alleging campaigns targeting variants of Anthropic Claude, OpenAI ChatGPT, Google Gemini, and Grok.
The agencies said the companies allegedly generated billions of tokens and millions of model interactions through unauthorized or obscured access, distributing requests across accounts, APIs, cloud providers, aggregators, proxies, and gray-market services to evade safeguards and attribution. They characterized the activity as part of China’s AI-development strategy and urged AI developers, government agencies, and allied partners to improve detection, adjust response measures, and share threat intelligence.

Track how attackers are adapting to this technology.
9 events from the most recent confirmed update back to the earliest known activity.
Google's Threat Intelligence Group reported that threat actors were increasingly targeting proprietary AI models, source code, model weights, and cloud-compute quotas.
Anthropic said it detected and disrupted six illicit Claude-distillation campaigns by China-based AI labs since February 2026, including a 151-million-exchange Alibaba-affiliated operation and campaigns attributed to Moonshot, DeepSeek, Zhipu/Z.ai, Xiaomi, SenseTime, and MiniMax. It said it responded with account restrictions and identity verification, summarized internal reasoning, and protections against reasoning-context manipulation.
A purported Anthropic threat-intelligence report alleged that seven PRC-based AI labs ran Claude-distillation campaigns from December 2025 through August 2026. It alleged that DeepSeek and Moonshot routed customer prompts to Claude Opus without users' knowledge while extracting reasoning-related outputs, using fraudulent accounts, proxies, compromised API keys, and cross-session replay techniques.
OpenAI accused DeepSeek of conducting model distillation to extract capabilities from its models.
U.S. agencies allege that China-based AI companies began industrial-scale campaigns to extract proprietary capabilities from U.S. frontier AI models in late 2024, using billions of tokens and millions of interactions.
Chinese Foreign Ministry spokesperson Mao Ning rejected U.S. allegations that Chinese AI companies maliciously copied U.S. AI technology through model distillation. She said China's AI progress resulted from domestic scientific and technological self-reliance and called on the United States to stop what China characterized as false accusations and smears.
The NSA, CISA and FBI issued a joint advisory alleging that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI systematically targeted Claude, ChatGPT, Gemini and Grok models through APIs, cloud providers, aggregators, proxies and other routes. The advisory recommended enhanced detection, response controls and intelligence sharing among government, industry and allies.
White House Office of Science and Technology Policy Director Michael Kratsios publicly accused Moonshot AI of attempting to extract proprietary functions from Anthropic's Fable model.
Anthropic reportedly made similar accusations concerning Chinese activity intended to distill capabilities from its AI models.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
17 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourceitpro.com
Open sourcethecybersecguru.com
Open sourcetechrepublic.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcenextgov.com
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.