<cite index="37-1">Anthropic accused five China-based AI companies of conducting unauthorized large-scale campaigns to extract Claude's capabilities and use them to train competing models, with combined activity totaling nearly 200 million exchanges linked to distillation attacks.</cite> <cite index="37-4,37-5">Anthropic described Alibaba's operation as the single largest distillation campaign it has ever documented, with accounts tied to Alibaba generating more than 151 million Claude interactions from May through July 2026, spread across upward of 3,500 fraudulent accounts.</cite> <cite index="42-4">The FBI, the National Security Agency and the Cybersecurity and Infrastructure Security Agency issued a joint advisory warning that China-based artificial intelligence companies are conducting industrial-scale knowledge distillation campaigns against U.S. frontier models.</cite>
<cite index="37-2">Anthropic's threat intelligence report, released Thursday, named Alibaba, Moonshot AI, DeepSeek, Xiaomi, and Zhipu as the parties behind illicit distillation campaigns—a technique whereby one lab feeds another model's outputs into its own training pipeline without permission.</cite> <cite index="37-3">The report said the campaigns targeted Claude's most valuable capabilities, including agentic reasoning, software engineering, and logical reasoning.</cite>
<cite index="37-5,37-6">Alibaba generated more than 151 million Claude interactions from May through July 2026, with daily volume cresting at close to 3 million from more than 3,500 fraudulent accounts, and Anthropic said those transcripts were used to help train Alibaba's Qwen models.</cite> <cite index="37-7,37-8,37-9">Moonshot AI took a different approach by routing some Kimi user requests to Claude without informing customers, then displaying Claude's responses as if they were Kimi's, relaying nearly 300,000 customer requests to Anthropic over one 10-day period through a network of 5,380 fraudulent accounts.</cite>
<cite index="38-4">According to Anthropic's report, unauthorized labs have developed increasingly sophisticated methods to circumvent defenses and harvest the capabilities of U.S. frontier models.</cite> <cite index="42-1">Anthropic tracked nearly 200 million exchanges linked to distillation attacks across five separate campaigns and disrupted attacks from seven China-based labs during the eight-month period.</cite> <cite index="43-6">U.S. intelligence assesses that distillation activities likely occur with Chinese government awareness.</cite>
The scale and coordination of these campaigns underscore a strategic effort to bypass the capital expenditure required to develop frontier AI models independently. The disclosure marks an escalation in acknowledged intellectual property theft within the AI industry, prompting coordinated U.S. government warnings and raising questions about the sustainability of open API access for frontier models deployed globally.