, , , ,

Anthropic Uncovers Massive Illicit AI Distillation Campaigns by Chinese Tech Giants

Leading artificial intelligence developer Anthropic has released a comprehensive threat intelligence report detailing unauthorized large-scale distillation activities conducted by prominent China-based AI laboratories, including Alibaba, Moonshot, and DeepSeek. The report outlines how these organizations allegedly leveraged millions of interactions with the Claude model family between December 2025 and August 2026 to extract advanced capabilities and train their own proprietary systems without permission.

According to the findings, the operation orchestrated by entities linked to Alibaba represented the largest measured distillation campaign, involving over 151 million exchanges with Claude from May through July. This activity reportedly peaked at roughly 3 million daily interactions utilizing more than 3,500 fraudulent accounts. The captured outputs were allegedly integrated into the training pipelines of Alibaba’s Qwen models and applied to broader foundational research endeavors, such as reinforcement learning.

Meanwhile, investigators uncovered deceptive routing practices employed by Moonshot AI and DeepSeek. Moonshot allegedly intercepted user queries intended for its Kimi chatbot, silently forwarded them to Claude, and subsequently presented the imported responses to unsuspecting consumers. This relay network funneled hundreds of thousands of customer requests through overseas proxies, capturing underlying reasoning transcripts for model training. DeepSeek engaged in similar covert rerouting tactics, generating millions of unauthorized distillation attempts over short operational windows.

Anthropic emphasized that these practices not only violate established terms of service but also raise serious data privacy concerns. The harvested exchanges frequently contained sensitive corporate and individual information, creating potential compliance vulnerabilities for global users whose data was redirected across international borders without explicit consent.

Key Takeaways

  • Anthropic reported that major Chinese AI labs, including Alibaba, Moonshot, and DeepSeek, engaged in unauthorized 'distillation' using Claude models.
  • Alibaba operated the largest campaign, generating over 151 million exchanges through thousands of fraudulent accounts to train Qwen models.
  • Moonshot and DeepSeek silently rerouted customer queries to Claude to harvest training data and reasoning transcripts without user consent.

Editor’s Analysis & Impact

This revelation highlights a growing trend of model distillation and intellectual property extraction within the fiercely competitive global generative AI landscape. As foundational models become increasingly expensive and difficult to train from scratch, rival labs face mounting pressure to accelerate development cycles, sometimes resorting to unauthorized cross-platform data harvesting. The inclusion of sensitive user data in these covert transfers underscores an urgent need for stricter cross-border data governance and advanced detection mechanisms. Moving forward, AI developers will likely invest heavily in defensive perimeter security to safeguard proprietary architectures against automated scraping and surrogate model training.

Frequently Asked Questions

Q: What is AI model distillation?
A: Model distillation is a process where the outputs, capabilities, or reasoning steps of a more advanced AI model are used to train and improve a separate, often less sophisticated model.

Q: Which companies were implicated in the Anthropic report?
A: The report specifically named Chinese AI laboratories including Alibaba, Moonshot AI, and DeepSeek as being involved in unauthorized data extraction and distillation activities.

Q: How did Moonshot AI acquire training data from Claude?
A: Moonshot allegedly intercepted user prompts intended for its Kimi models, secretly forwarded them to Claude, and then fed the resulting responses back to users while saving the data for training.

AI Disclosure: This article is based on verified data and official reports. Our Team and AI have cross-referenced every financial detail with primary sources to ensure total accuracy.