{"id":2812,"date":"2026-09-11T18:40:15","date_gmt":"2026-09-11T18:40:15","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2812"},"modified":"2026-09-11T18:40:15","modified_gmt":"2026-09-11T18:40:15","slug":"anthropic-says-seven-china-based-ai-labs-ran-industrial-scale-claude-distillation-attacks","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2812","title":{"rendered":"Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 11, 2026<\/span><\/span><span class=\"p-tags\">Artificial Intelligence \/ Cybercrime<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgIEiaJBfFrHCrYlSFKWGSRYD6CW_EeKfmYWCZw4jm5c9hyphenhyphenDVbaSIhyphenhyphenXwFB0ncQOoB10crmwgJV9nsvhQzJNuVMsDh6jPVt2ep23r0A2PB7ZhLfTroa0Ff__kyjjX2MjP4ok4DtBwFEF1VZC7b5OOCkibJBbwECsR0Y_9S1-NpdEIw04J5FtY9OloB084t_\/s1700-nu-rw-lo-l85-e365\/claude-china.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax.<\/p>\n<p>Knowledge distillation by itself is a <a href=\"https:\/\/www.gov.uk\/government\/publications\/ai-insights\/ai-insights-model-distillation-html\" target=\"_blank\">legitimate training method<\/a>. It refers to a <a href=\"https:\/\/www.ibm.com\/think\/topics\/knowledge-distillation\" target=\"_blank\">machine learning technique<\/a> where a large, powerful AI model assumes the role of a \u00abteacher\u00bb to train a smaller, less-capable or faster \u00abstudent\u00bb model to copy its capabilities.<\/p>\n<p>Illicit distillation, on the other hand, is an industrial-scale campaign that covertly extracts a model&#8217;s capabilities and replicates them in another model without authorization, typically by making use of networks of fake accounts created with stolen credit cards, login credentials, and API keys.<\/p>\n<p>Frontier AI labs in the West, including those from Google and OpenAI, have repeatedly called out distillation attacks aimed at their models. Anthropic said it has observed unauthorized labs employing \u00abincreasingly sophisticated methods\u00bb to get around defenses and harvest its capabilities, such as agentic capabilities and tool use, coding and data analysis, and logical reasoning, through prompt manipulation tricks.<\/p>\n<p>\u00abDeepSeek, Xiaomi, and Moonshot fed conversations between their own models and users into Claude,\u00bb Anthropic <a href=\"https:\/\/www.anthropic.com\/threat-intelligence-report-september-2026#illicit-distillation-sep-26\" target=\"_blank\">said<\/a>. \u00abThese labs then used Claude\u2019s responses as training data with which to distill Claude&#8217;s capabilities. Some of these exchanges included sensitive information, including from individual users, major multinational companies, and state-affiliated actors.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The AI company said these labs generally gain access to its models by routing requests through proxy services, also referred to as transfer or relay stations, which create thousands of new accounts under fictitious identities, fake or stolen credit cards, and illegally harvested API keys that belong to legitimate companies or individuals.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>According to Anthropic, unauthorized AI labs also acquire transcripts of user exchanges with U.S. frontier models by purchasing them off third-party resellers, who are the operators of proxy services that save such conversations without the users&#8217; knowledge or consent.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg7SKodqncnaOkk3eGOm-QIMJJpJhVG4RBKHDcke6EgphIXDIn519hHjZMZGkr8PuqZWGhxmiacT6dzzS_hMsjYMPv6I4lYUi2PuHjdQNqUeGVcHvO3ErAJeR4SV-GRFOhOUAcgNZGRXvHHS4KhK1UvnRJD5M7KGKZgzvjjYiHWAY070w4hlWLHjlVpJaSM\/s1700-nu-rw-lo-l85-e365\/dist.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg7SKodqncnaOkk3eGOm-QIMJJpJhVG4RBKHDcke6EgphIXDIn519hHjZMZGkr8PuqZWGhxmiacT6dzzS_hMsjYMPv6I4lYUi2PuHjdQNqUeGVcHvO3ErAJeR4SV-GRFOhOUAcgNZGRXvHHS4KhK1UvnRJD5M7KGKZgzvjjYiHWAY070w4hlWLHjlVpJaSM\/s1700-nu-rw-lo-l85-e365\/dist.jpg\" alt=\"\" border=\"0\" data-original-height=\"631\" data-original-width=\"1920\"\/><\/a><\/div>\n<p>\u00abIn other cases, unauthorized labs rerouted requests from their users to Claude &#8212; without the knowledge or permission of those users &#8212; to harvest exchanges between users and Claude for training,\u00bb Anthropic pointed out.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiT2BEykvvmFFID5n-_X_olvTLkSuLGZUwtxCkZ-6_a9KbP89ajlQYjRTHI_RPVflm2fXzarB09qDaAU7BzdIZAJIxJDajimi1PooompbHtV5kYwM8kPSL2Dtc7_MouM5Lqkb4DmsT8YevEgZCQJW84jkebcC8P74NTAbrVvXFSi6__STzPxLWYuSK0WBDV\/s1700-nu-rw-lo-l85-e365\/training.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiT2BEykvvmFFID5n-_X_olvTLkSuLGZUwtxCkZ-6_a9KbP89ajlQYjRTHI_RPVflm2fXzarB09qDaAU7BzdIZAJIxJDajimi1PooompbHtV5kYwM8kPSL2Dtc7_MouM5Lqkb4DmsT8YevEgZCQJW84jkebcC8P74NTAbrVvXFSi6__STzPxLWYuSK0WBDV\/s1700-nu-rw-lo-l85-e365\/training.jpg\" alt=\"\" border=\"0\" data-original-height=\"470\" data-original-width=\"1920\"\/><\/a><\/div>\n<p>Since February 2026, the AI company said it has detected six illicit distillation campaigns that were conducted by China-based AI labs to advance their own models &#8211;<\/p>\n<ul>\n<li><strong>GTG-16005<\/strong> (151 million exchanges observed between May and July 2026), in which a cluster of Alibaba-affiliated operators targeted the chain-of-thought (CoT) reasoning transcripts of Claude Opus 4.6 and 4.7 in what has been described as the \u00ablargest distillation attack we have ever measured.\u00bb It peaked at roughly 3 million exchanges per day launched from more than 3,500 fraudulent accounts targeting agentic tasks, software engineering, kernel development, and long-horizon tasks.<\/li>\n<li><strong>GTG-16002<\/strong> (23 million exchanges observed between May and July 2026), in which Moonshot AI stealthily rerouted customer requests to Claude as opposed to processing them using Kimi, and then displayed responses from Claude to users. In tandem, a subset of these exchanges were captured and saved to train its CoT model. Over a 10-day period, Moonshot is said to have relayed almost 300,000 customer requests to Anthropic using a proxy service network of 5,380 fraudulent accounts, most of them located in Singapore and Japan.<\/li>\n<li><strong>GTG-16001<\/strong> (More than 12.1 million exchanges observed over 14 days in July 2026), in which DeepSeek followed the same approach as Moonshot AI to silently relay exchanges to Claude without informing its customers and extract CoT transcripts.<\/li>\n<li><strong>GTG-16006<\/strong> (More than 3.4 million exchanges observed over 17 days in June and July 2026), in which Zhipu (aka Z.ai) ran a CoT extraction pipeline and replayed Claude reasoning traces through Claude to train its models. The activity took place by rotating through 273 fraudulent accounts.<\/li>\n<li><strong>GTG-16008<\/strong> (More than 400,000 exchanges observed over 20 days in March and April 2026), in which Xiaomi replayed user conversations and coding sessions from its own MiMo models to Claude, through OpenClaw and OpenCode coding harnesses, to bolster training data used for future models.<\/li>\n<li><strong>GTG-16012<\/strong>, in which SenseTime purchased transcripts of user exchanges with Claude from third-party data vendors.<\/li>\n<li><strong>GTG-16003<\/strong>, in which MiniMax built its own proxy network service through a shell company that offers access to models developed by Anthropic and OpenAI, likely with an aim to collect exchanges between users and U.S. frontier models to train its models.<\/li>\n<\/ul>\n<p>\u00abThe proliferation of proxy services to circumvent Anthropic access restrictions has created a secondary market through which labs can purchase or otherwise acquire harvested exchanges between users and Claude,\u00bb Anthropic said. \u00abSome proxy networks both provide Claude access to users in unsupported regions, and also save exchanges in order to sell them to other labs.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>To counter illicit distillation, the company said it bans reseller accounts or accounts operating from unsupported regions like China, Iran, and Russia when users fail to verify their identity. To make it harder for unauthorized labs to distill Claude&#8217;s capabilities, the model has been updated to summarize its internal reasoning before responding, thereby making stolen transcripts less useful for follow-on training.<\/p>\n<p>\u00abAnd with Fable 5.1 we introduced preserved thinking, which stops new API accounts from altering the system prompt, tools, or messages that precede Claude&#8217;s reasoning in multi-turn conversations,\u00bb the company added. \u00abThat reasoning is encrypted, but editing the context before it is a common technique attackers use to make Claude reveal it.\u00bb<\/p>\n<p>The development comes as Anthropic said it took down a number of accounts that tried to use its models to surveil their citizens and to research diseases in ways that could support biological weapons. Earlier this week, U.S. cybersecurity and intelligence agencies accused China-based artificial intelligence (AI) companies of conducting \u00absystematic extraction\u00bb of proprietary functionalities and capabilities of American frontier models through distillation attacks.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 11, 2026Artificial Intelligence \/ Cybercrime Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot,&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2813,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[105,24,3390,9,3393,3392,2474,3391],"class_list":["post-2812","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-anthropic","tag-attacks","tag-chinabased","tag-claude","tag-distillation","tag-industrialscale","tag-labs","tag-ran"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2812","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2812"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2812\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2813"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2812"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2812"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2812"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}