CISA, the NSA, and the FBI allege that China-based AI companies—including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—ran industrial-scale campaigns to extract capabilities from U.S. frontier models. The activity reportedly generated billions of tokens and millions of requests to Claude, GPT, Gemini, and Grok through coordinated API routing, cloud providers, aggregators, relays, proxy networks, and rotating vendor accounts. Anthropic said it identified seven campaigns targeting Claude since February 2026; the largest, allegedly linked to Alibaba, made more than 151 million requests between May and July.
According to the agencies and Anthropic, operators used fraudulent accounts, stolen API keys, payment and quota optimization, automated failover, and—in some cases—covert forwarding of user prompts to sustain collection and train competing models from the outputs. The activity may have exposed user-provided source code, corporate documents, personal data, and credentials. Anthropic said it blocked implicated accounts and proxy infrastructure and reduced the reasoning detail exposed by its models, while U.S. agencies recommended cross-provider sharing of high-confidence behavioral and infrastructure indicators and covert response degradation for suspected distillation operations.

Track how attackers are adapting to this technology.
10 events from the most recent confirmed update back to the earliest known activity.
CISA, NSA, and FBI issued an advisory alleging that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI conducted unauthorized industrial-scale distillation against U.S. frontier models. The advisory described centralized routing across APIs, cloud providers, aggregators, relays, and pools of vendor accounts, with automated failover, quota optimization, route switching, and output-quality evaluation.
Anthropic recorded more than 12.1 million Claude requests allegedly associated with DeepSeek during a 14-day period in July. Anthropic alleged that some DeepSeek user prompts were covertly forwarded to Claude, including one containing valid database credentials for an unnamed Russian government agency.
Anthropic recorded more than 23 million Claude requests allegedly originating from Moonshot AI from May through July. It alleged Moonshot covertly forwarded some user prompts to Claude and retained responses for model training, including a prompt containing internal code and secrets from multiple organizations.
Anthropic attributed a campaign to Alibaba that made more than 151 million requests to Claude Opus 4.6 and 4.7 from May through July, peaking near 3 million daily requests through more than 3,500 fraudulent accounts. Anthropic said the collected reasoning chains were used to train Qwen models.
Anthropic reported identifying seven Chinese laboratory campaigns that began unauthorized distillation of Claude, using access routes including APIs, cloud platforms, aggregators, and proxy services.
U.S. agencies alleged that Z.AI engineers had used billions of tokens by mid-2026 to distill data from GPT-5.5 and Claude Opus 4.8 to improve complex reasoning capabilities.
U.S. agencies reported that MiniMax used Claude Code while developing its M2 model and made prompt-injection attempts intended to have Claude Code identify itself as a MiniMax product.
CISA, NSA, and FBI assessed that unauthorized industrial-scale distillation campaigns targeting U.S. AI models had operated since at least late 2024 and may have occurred with Chinese authorities' knowledge.
Google reported detecting and disrupting model-extraction attempts by private-sector entities and researchers. It stated that the activity it described did not include direct attacks on frontier models by APT actors.
Anthropic said it blocked accounts and proxy networks associated with unauthorized model extraction and changed Claude to expose less internal reasoning detail, seeking to reduce the value of captured conversations for distillation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.