Anthropic Reports 200M Unauthorized Exchanges in Chinese AI Distillation Campaign
Five China-based companies allegedly extracted Claude's capabilities through fraudulent accounts to train competing models, exposing sensitive user data in the process.

Anthropic has documented what it describes as the largest unauthorized AI model distillation campaign in its history, involving five China-based companies that collectively generated nearly 200 million exchanges with its Claude AI system to extract capabilities for their own competing models.
The company's threat intelligence report, released Thursday, identified Alibaba, Moonshot AI, DeepSeek, Xiaomi, and Zhipu as conducting what Anthropic terms "illicit distillation" — a technique where one organization feeds another model's outputs into its own training pipeline without authorization. The campaigns specifically targeted Claude's most advanced capabilities, including agentic reasoning, software engineering, and logical reasoning.
Alibaba's record-breaking operation
Alibaba's operation represented the single largest distillation campaign Anthropic has ever documented. Between May and July 2026, accounts linked to Alibaba generated more than 151 million Claude interactions, with daily volumes reaching approximately 3 million exchanges. The activity was distributed across more than 3,500 accounts that Anthropic identified as fraudulent. According to the report, Alibaba used these transcripts to help train its Qwen models and for broader AI research and development work.
Covert routing exposed customer data
Moonshot AI and DeepSeek employed a different tactic that raised additional privacy concerns. Rather than simply querying Claude directly, these companies allegedly routed their own users' requests to Claude without disclosure, then presented Claude's responses as their own model's output.
Moonshot relayed nearly 300,000 customer requests to Claude over a single 10-day period through a network of 5,380 fraudulent accounts, according to Anthropic. The company's total distillation activity exceeded 23 million exchanges during the May-to-July timeframe.
DeepSeek conducted similar operations, with Anthropic logging more than 12 million exchanges connected to DeepSeek's distillation activity over a two-week period in July 2026.
Sensitive data exposure
The covert routing operations exposed sensitive customer information. Anthropic reported that Moonshot relayed a request from a user it assessed was affiliated with the People's Liberation Army, asking Claude to analyze CCTV surveillance footage from hundreds of cameras in Chengdu. DeepSeek relayed requests that exposed live credentials for a Russian government database.
Anthropic stated in its report that "these practices are likely inconsistent with privacy laws and the labs' own terms of service."
Why it matters
This disclosure marks a significant escalation in the ongoing tension between U.S. and Chinese AI development. The scale of the operations — particularly Alibaba's 151 million exchanges — demonstrates industrial-level systematic extraction of proprietary AI capabilities. The covert routing tactics employed by Moonshot and DeepSeek raise serious questions about user privacy and data sovereignty, as customers unknowingly had their queries processed by foreign AI systems. The exposure of sensitive military and government data through these operations adds national security dimensions to what might otherwise be treated as intellectual property disputes.
Government response
The National Security Agency, FBI, and Cybersecurity and Infrastructure Security Agency jointly accused six Chinese AI companies this week of conducting systematic distillation campaigns against U.S. AI firms at industrial scale. The agencies concluded that distillation serves as "the critical core" of these companies' development programs. Treasury Secretary Scott Bessent indicated that sanctions and Entity List designations would be "on the table" for companies found to have engaged in IP theft.
The current disclosure represents a substantial expansion from Anthropic's June letter to U.S. senators, which reported that Alibaba-affiliated entities had run approximately 28.8 million exchanges over six weeks using roughly 25,000 fraudulent accounts. That earlier disclosure prompted Alibaba to ban Claude Code for employees, citing security risks.
These details were first reported by Quartz, based on Anthropic's threat intelligence report.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call

