Unauthorized Data Usage Discovered
Anthropic reports that Chinese artificial intelligence labs have conducted large-scale unauthorized usage of its Claude models. The activity involves what the company labels as illicit distillation. This process uses outputs from high-performance AI models to train other systems and replicate their logic. Anthropic detected the campaign between December 2025 and August 2026. The findings come from a security threat report released by the San Francisco-based firm on Thursday.
Alibaba, Moonshot, and DeepSeek appear prominently in the investigation. Anthropic claims these companies accessed its service to siphon capabilities into their own proprietary models. The report states that this unauthorized traffic included sensitive information from individual users and large corporations. These actions likely violate established privacy laws and standard service terms governing AI platform use.
Specific Tactics Used by Chinese Labs
The most significant campaign identified involved Alibaba. Operators tied to the firm processed more than 151 million exchanges with Claude over a three-month window. This activity reached a high of three million exchanges per day, flowing through roughly 3,500 fraudulent accounts. Anthropic observed these accounts using Claude outputs for reinforcement learning and model architecture updates.
Moonshot AI, based in Beijing, took a different approach to hide its tracks. The company redirected customer requests intended for its Kimi model to Claude and then fed the Claude response back to the end user. This made it appear as though the user was interacting with Kimi. In a single 10-day window, Moonshot relayed nearly 300,000 queries. Most of these requests passed through over 5,000 deceptive accounts located in Singapore and Japan. Data from these exchanges helped build the training set for Moonshot’s internal models.
DeepSeek also utilized similar redirection tactics. Anthropic recorded more than 12 million distillation attacks linked to DeepSeek during a 14-day period in July. The company did not disclose whether these platforms informed their users that their private queries were being routed through a third-party American AI system.
Implications for Industry Standards
The report underscores the difficulty of securing AI infrastructure against automated data scraping. As models gain popularity, they become targets for labs seeking to reduce training costs by stealing reasoning data from more advanced counterparts. This activity forces developers to implement tighter controls on API access and user authentication.
Anthropic’s investigation spanned seven distinct threat categories. These include cyber operations, influence campaigns, and potential threats to conventional weapons development. The company continues to monitor these patterns to maintain the integrity of its platform. None of the named companies responded to requests for comment regarding the findings. Market observers now watch for potential regulatory responses or technical shifts in how AI labs protect their proprietary data from such extraction attempts.

