Security

Anthropic Disrupts Seven China-Based AI Labs Stealing Claude Data

The company detected 151 million unauthorized exchanges in the largest distillation attack ever measured, with labs routing user conversations without consent.

Omega Editorial· September 11, 2026· 3 min read

Major AI Labs Caught in Industrial-Scale Data Theft

Anthropic has identified and shut down sophisticated campaigns by seven China-based AI laboratories that illicitly extracted capabilities from its Claude models through what the company calls industrial-scale distillation attacks. The labs—including Alibaba, DeepSeek, Moonshot AI, Zhipu (Z.ai), MiniMax, Xiaomi, and SenseTime—used networks of fraudulent accounts and proxy services to harvest millions of user conversations without authorization.

The attacks represent a significant escalation in AI model theft. While knowledge distillation is a legitimate training technique where one model learns from another, these campaigns involved covert extraction using stolen credit cards, compromised API keys, and fake identities to bypass access restrictions.

Why it matters

These attacks expose fundamental vulnerabilities in how frontier AI models are protected and reveal a systematic effort by Chinese labs to replicate Western AI capabilities without investing in the underlying research. The theft of user data—including conversations from multinational companies and state-affiliated actors—raises serious privacy and national security concerns. As AI becomes central to economic competitiveness, protecting model capabilities and user data from unauthorized extraction will require both technical defenses and policy coordination.

The Scale of the Theft

The largest attack, designated GTG-16005 and linked to Alibaba-affiliated operators, involved 151 million exchanges between May and July 2026. At its peak, the campaign generated roughly 3 million exchanges per day from more than 3,500 fraudulent accounts, specifically targeting Claude's chain-of-thought reasoning capabilities for tasks including software engineering and kernel development.

Moonshot AI and DeepSeek employed particularly deceptive tactics. Rather than processing user requests with their own models, they silently rerouted customer queries to Claude, displayed Claude's responses to users, and captured the exchanges for training data—all without informing their customers. Moonshot relayed nearly 300,000 customer requests over just 10 days using a network of 5,380 fraudulent accounts.

How the Attacks Worked

The unauthorized labs gained access through proxy services—intermediary networks that create thousands of accounts under fictitious identities. These "transfer stations" serve dual purposes: providing Claude access to users in restricted regions like China, Iran, and Russia, while simultaneously harvesting and selling conversation transcripts to AI labs.

Some labs purchased stolen transcripts directly from third-party data vendors rather than conducting the extraction themselves. According to Anthropic's findings, these proxy networks have created a secondary market for harvested AI exchanges.

Anthropic's Response

The company has implemented multiple countermeasures. It now bans reseller accounts and users from unsupported regions who fail identity verification. Claude has been updated to summarize internal reasoning before responding, making stolen transcripts less useful for training. The Fable 5.1 release introduced "preserved thinking," which prevents new API accounts from altering system prompts or messages that precede Claude's reasoning in conversations.

The company also took down accounts attempting to use its models for citizen surveillance and biological weapons research.

The findings align with warnings issued this week by U.S. cybersecurity and intelligence agencies, which accused China-based AI companies of conducting systematic extraction of American frontier model capabilities. Western AI labs including Google and OpenAI have previously reported similar distillation attacks targeting their models.

These details were first reported by The Hacker News.

#ai security#model distillation#anthropic#claude#china ai#data theft

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

OpenAI and Anthropic Eye Cybersecurity as Next Revenue Driver

As AI models excel at finding system vulnerabilities, the labs that built them are positioning cyber-defense tools as a major new business line.

Via AI Watch · Sep 11, 2026
Security· 3 min read

CIS, OpenAI pilot AI tools for under-resourced government cyber teams

New program tests whether AI can help state and local defenders detect threats faster and prioritize security actions with limited staff and budgets.

Via AI Watch · Sep 11, 2026
Security· 3 min read

Anthropic Reports Yemen Militants Used Claude AI for Weapons Code

The AI safety company disclosed that Houthi rebels attempted to develop location-guidance software for rockets and missiles using its coding assistant.

Via AI Watch · Sep 11, 2026