Friday, September 11, 2026
Privacy-First Edition
Back to NNN
Technology

Anthropic caught Chinese AI labs carrying out massive ‘distillation attack’ to rip off its technology

Add The New York Post on Google Anthropic says it caught and shut down large-scale attempts by Chinese AI labs including Alibaba, Moonshot and DeepSeek to use Claude to train their own AI models — the largest “illicit distillation” attack yet aimed at ripping off Anthropic’s more advanced technology.

Anthropic said Thursday it detected the practice in which a less-capable AI model is trained using the outputs of a more advanced system to copy its capabilities without permission.

In one particularly egregious incident that took place over a 10-day stretch this year, Beijing-based Moonshot rerouted 300,000 of its own customer inquiries to Claude and then showed its customers those responses without telling them, according to the report.

Moonshot used 5,380 phony accounts based in Singapore and Japan and saved the exchanged to use as training data.

The attacks are the latest attempts by lower performing Chinese AI companies to rip off leading US AI tech – a growing concern for US AI juggernauts as they race to build the most advanced AI systems.

Anthropic, led by CEO Dario Amodei, called Alibaba’s attack the largest distillation operation it has seen, which involved more than 151 million exchanges with Claude between May and July. Operators linked to Alibaba used Claude-generated responses to train its Qwen models.

“Some of these exchanges included sensitive information, including from individual users, major multinational companies, and state-affiliated actors, Anthropic said in a threat intelligence report. “These practices are likely inconsistent with privacy laws and the labs’ own terms of service.”

The activity reached nearly 3 million exchanges a day and involved more than 3,500 fraudulent accounts, Anthropic said. Alibaba also used Claude for broader AI research, including to improve its model architecture.

In the Moonshot attack, more than 23 million exchanges were linked to Moonshot between May and July, according to the report. Some of the customer prompts sent to Claude contained sensitive information. Anthropic said it did not know whether Moonshot told its customers that their requests were being forwarded to Anthropic.

DeepSeek – the Chinese AI company that took the AI world by storm last year with its low cost models – allegedly used tactics similar to Moonshot, Anthropic said.

DeepSeek also swapped exchanges over to Claude without notifying its customers and Anthropic said it detected more than 12 million distillation attacks by the company over two weeks in July.

The report also called out other major Chinese AI companies for attacks on its AI it said it disrupted between December 2025 and August 2026. The activity included cyber operations, surveillance, scams and fraud, biological misuse, conventional weapons development and distillation.

Alibaba, Moonshot, DeepSeek, Xiaomi and Anthropic did not immediately respond to requests for comment by The Post.

Read original at New York Post

The Perspectives

0 verified voices · Three viewpoints · Real discourse

Left
0
Be the first to share a left perspective
Center
0
Be the first to share a center perspective
Right
0
Be the first to share a right perspective

Related Stories