> ## Content Index
> Fetch the complete content index at: https://www.bushletter.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Chinese AI labs route customer chats to Claude without consent
- URL: https://www.bushletter.com/chinese-ai-labs-relayed-users-chats-to-claude-without-telling-them/
- Published: 2026-09-12T21:00:00.000Z
- Updated: 2026-09-24T09:32:21.000Z
- Description: Alibaba extracted 151 million exchanges to train its Qwen models, while other operations exposed live Russian defence credentials and surveillance footage linked to the People's Liberation Army.
- Author: Editor
- Tags: Cybersecurity, China, Anthropic

![Takeshi Mori](https://res.cloudinary.com/dz77sb7j1/image/upload/v1774262608/bushletter/authors/takeshi-mori.png)

By **Takeshi Mori** · 2026-09-11

TLDR

Moonshot AI and DeepSeek silently forwarded their customers' prompts to Anthropic's Claude, exposing PLA-linked surveillance footage and live Russian defence credentials. Alibaba ran an even larger operation, pulling 151 million exchanges over three months to train its own Qwen models.

## What the distillation campaigns exposed

Three Chinese AI labs used their own commercial products as a front. Customers thought they were talking to Moonshot AI, DeepSeek or Alibaba's Qwen. They were talking to Claude.

Moonshot AI forwarded nearly 300,000 requests to Claude over ten days through 5,380 fraudulent accounts, and in the process exposed CCTV footage from hundreds of Chengdu surveillance cameras uploaded by a user Anthropic assessed as likely affiliated with the People's Liberation Army.[\[1\]](https://www.anthropic.com/threat-intelligence-report-september-2026?ref=bushletter.com) That footage was never meant to leave the Moonshot environment. It left because Moonshot's backend was Claude.

DeepSeek's relay operation exposed something more immediately dangerous: live credentials for a Russian government database, surfaced inside chain-of-thought transcripts extracted from Claude Opus.[\[1\]](https://www.anthropic.com/threat-intelligence-report-september-2026?ref=bushletter.com) A real user had pasted those credentials into a DeepSeek prompt, with no idea that prompt would travel to a US frontier model and back. Anthropic's platform now embeds summarised thinking blocks and reasoning signatures specifically to block unauthorised exfiltration of chain-of-thought reasoning.[\[4\]](https://platform.claude.com/?ref=bushletter.com)

## Scale of the Alibaba operation

The Moonshot and DeepSeek campaigns were serious. The Alibaba campaign was a different order of magnitude.

Operators affiliated with Alibaba generated over 151 million exchanges between May and July 2026, running more than 3,500 fraudulent accounts and pushing peaks close to three million Claude queries per day, all to harvest reasoning data for training Qwen models.[\[1\]](https://www.anthropic.com/threat-intelligence-report-september-2026?ref=bushletter.com) Distillation attacks work by capturing a frontier model's internal reasoning, the step-by-step logic it uses to reach an answer, and feeding that data into a competing system at a fraction of the compute cost required to generate it from scratch.

Anthropic's Threat Intelligence team said the cases in its September 2026 report represent the most notable and novel threat activity identified to date. The team said: "We're publishing this work because we believe we have a responsibility to disclose malicious misuse of our services. As models become increasingly capable, their risks will increase, unless AI developers and society's defenders act to make them safer."[\[1\]](https://www.anthropic.com/threat-intelligence-report-september-2026?ref=bushletter.com)

Threat Intelligence: How Anthropic stops AI cybercrime

## AI-enabled cyber operations and zero-day findings

The distillation campaigns sit alongside a separate and more direct threat documented in the same report. GTG-20006, a Russian-linked threat actor, used AI-driven workflows to automate reconnaissance, phishing and implant development against more than 20 government and defence bodies across Ukraine and Europe.[\[1\]](https://www.anthropic.com/threat-intelligence-report-september-2026?ref=bushletter.com) Each step of the attack chain that previously required a team ran with minimal human oversight.

A separate autonomous workflow targeting security appliances produced more than a dozen previously unknown zero-day vulnerabilities inside a single month.[\[1\]](https://www.anthropic.com/threat-intelligence-report-september-2026?ref=bushletter.com) Open-source frameworks such as PentAGI, available publicly on GitHub, already automate the same kill-chain steps used by these real-world actors, so the capability is no longer confined to well-resourced state groups.[\[3\]](https://github.com/robustness-ai/PentAGI?ref=bushletter.com)

The report also documents a state military laboratory using Claude to research mutations of chikungunya, a mosquito-borne virus that causes severe joint pain and fever and for which no approved antiviral treatment exists.[\[2\]](https://www.who.int/en/news-room/fact-sheets/detail/chikungunya?ref=bushletter.com) Anthropic did not name the state or the laboratory.

The practical signal for any operator building on a third-party AI API is direct: your users' prompts may travel further than the endpoint you think you are calling. Anthropic's September 2026 report covers activity through the end of July, with further disclosures planned as analysis continues.[\[1\]](https://www.anthropic.com/threat-intelligence-report-september-2026?ref=bushletter.com)

KEY TAKEAWAYS

01DeepSeek rerouted user requests to Claude Opus, leaking live Russian defence ministry database credentials.

02Alibaba's distillation campaign generated 151 million illicit exchanges, peaking near three million Claude queries daily.

03Moonshot AI exposed CCTV footage from hundreds of Chengdu cameras via 5,380 fraudulent accounts over ten days.

04A single autonomous workflow produced more than a dozen zero-day vulnerabilities against security appliances in one month.

05Anthropic says AI has collapsed the skill gap between state-sponsored hackers and lone operators.

SOURCES & CITATIONS

1. [Anthropic Threat Intelligence Report, September 2026](https://www.anthropic.com/threat-intelligence-report-september-2026?ref=bushletter.com)
2. [WHO Fact Sheet: Chikungunya](https://www.who.int/en/news-room/fact-sheets/detail/chikungunya?ref=bushletter.com)
3. [PentAGI, open-source autonomous penetration-testing framework](https://github.com/robustness-ai/PentAGI?ref=bushletter.com)
4. [Anthropic Claude Platform](https://platform.claude.com/?ref=bushletter.com)

FREQUENTLY ASKED QUESTIONS

How did Chinese AI labs access Anthropic's Claude without authorisation?

Moonshot AI, DeepSeek and Alibaba-affiliated operators created thousands of fraudulent accounts on Anthropic's platform and routed their own customers' prompts through those accounts, returning Claude's answers as if they came from their own models.

What sensitive data was exposed in these operations?

Moonshot AI's relay exposed CCTV footage from hundreds of Chengdu surveillance cameras linked to a likely PLA-affiliated user. DeepSeek's operation surfaced live credentials for a Russian government database inside chain-of-thought transcripts.

What is AI model distillation and why does it matter?

Distillation is the practice of capturing a frontier model's internal step-by-step reasoning and using that data to train a competing model, at far lower compute cost than generating equivalent capability from scratch. Alibaba's campaign extracted 151 million such exchanges to train its Qwen models.

What AI-enabled cyber threats did Anthropic's report identify beyond distillation?

A Russian-linked group used AI workflows to automate attacks against 20-plus European and Ukrainian government bodies. A separate autonomous workflow found more than a dozen zero-day vulnerabilities in security appliances within one month.

![Takeshi Mori](https://res.cloudinary.com/dz77sb7j1/image/upload/v1774262608/bushletter/authors/takeshi-mori.png)

[Takeshi Mori](https://bushletter.com/author/takeshi-mori/?ref=bushletter.com)

Takeshi Mori writes about technology and start-ups. He is curious about how products get built and who they are really for, and he would rather see a thing working than hear it described.