Security

Chinese AI Labs Hit Anthropic with 190M Distillation Attacks

DeepSeek, Moonshot, Alibaba, and others allegedly used Claude outputs to train competing models, exposing sensitive government data in the process.

Omega Editorial· September 11, 2026· 3 min read

Major Chinese AI Companies Targeted Claude

Anthropic disclosed Thursday that five leading Chinese AI laboratories conducted nearly 190 million distillation attacks against its Claude model during a three-month period this summer. The campaign involved Alibaba, Moonshot, DeepSeek, Zhipu, and Xiaomi systematically extracting outputs from Claude to improve their own competing AI systems.

Distillation attacks exploit advanced AI models by feeding them queries and using the responses as training data for less capable models. The practice allows competitors to capture the knowledge and reasoning capabilities of frontier systems without investing in the underlying research and compute resources.

According to Anthropic's report, DeepSeek and Moonshot AI redirected their own users' requests to Claude rather than processing them through their native models. Moonshot rerouted 23 million queries between May and July, while DeepSeek redirected 12.1 million requests during a two-week span in July alone.

Sensitive Government Data Exposed

The redirection scheme inadvertently exposed classified information from Chinese and Russian government sources. Anthropic documented instances where requests meant for Chinese AI assistants instead flowed through Claude, including CCTV surveillance footage uploaded by a user affiliated with the People's Liberation Army through Moonshot's Kimi interface. A Russian military contractor also submitted details about a Russian government database that ended up processed by Claude.

Alibaba conducted what Anthropic characterized as the largest distillation attack the company has ever measured. Over 151 million exchanges occurred between May and July, orchestrated through 3,500 fraudulent accounts. These accounts specifically prompted Claude to articulate its reasoning processes, which Alibaba then used to train its Qwen model family.

Xiaomi took a different approach, recording actual user conversations with its MiMo models and feeding those dialogues into Claude to generate training datasets. Anthropic also flagged Z.ai—recently notable for its Ox Alpha model—for conducting attacks similar to Alibaba's operation.

Why It Matters

The scale of these attacks highlights a fundamental tension in AI development: frontier labs invest billions in compute and research, while competitors can potentially shortcut that investment by systematically harvesting outputs. For enterprise leaders evaluating AI vendors, this episode underscores questions about model provenance and the security implications of data routing through undisclosed third-party systems. The inadvertent exposure of government and military data also demonstrates how AI supply chains can create unexpected intelligence risks.

New Safeguards Implemented

In response, Anthropic has deployed multiple countermeasures. The company now bans suspicious activity patterns, reduced the detail level in Claude's reasoning transcripts to make them less useful for training purposes, and implemented identity verification requirements for users appearing to operate from China, Russia, or Iran—jurisdictions where Claude is not officially available.

None of the named Chinese companies responded to requests for comment from Business Insider. Anthropic also did not provide additional comment beyond its published report.

This marks Anthropic's second public disclosure about Chinese distillation campaigns. In June, the company's head of policy Sarah Heck told lawmakers that Alibaba had conducted 28.8 million illicit exchanges with Claude between late April and early June, urging legislation to address such attacks.

These details were first reported by Business Insider.

#anthropic#claude#distillation attacks#chinese ai#deepseek#model training

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

WithSecure Maps Trust Relationships in Salesforce AI Environments

New framework addresses governance challenges when AI agents and integrations extend beyond traditional identity and access controls.

Via AI Watch · Sep 11, 2026
Security· 3 min read

Anthropic Blocks AI Misuse in Weapons Development and Espionage

The company's first threat intelligence report details disrupted attempts to use Claude for biological weapons research, surveillance, and state-sponsored hacking campaigns.

Via AI Watch · Sep 11, 2026
Security· 3 min read

Anthropic Disrupts Chinese AI Labs' Unauthorized Model Training

Alibaba, Moonshot, and DeepSeek allegedly used Claude outputs to train competing models without permission, exposing user data in the process.

Via AI Watch · Sep 11, 2026