
TLDR
Moonshot AI and DeepSeek silently forwarded their customers' prompts to Anthropic's Claude, exposing PLA-linked surveillance footage and live Russian defence credentials. Alibaba ran an even larger operation, pulling 151 million exchanges over three months to train its own Qwen models.
What the distillation campaigns exposed
Three Chinese AI labs used their own commercial products as a front. Customers thought they were talking to Moonshot AI, DeepSeek or Alibaba's Qwen. They were talking to Claude.
Moonshot AI forwarded nearly 300,000 requests to Claude over ten days through 5,380 fraudulent accounts, and in the process exposed CCTV footage from hundreds of Chengdu surveillance cameras uploaded by a user Anthropic assessed as likely affiliated with the People's Liberation Army.[1] That footage was never meant to leave the Moonshot environment. It left because Moonshot's backend was Claude.
DeepSeek's relay operation exposed something more immediately dangerous: live credentials for a Russian government database, surfaced inside chain-of-thought transcripts extracted from Claude Opus.[1] A real user had pasted those credentials into a DeepSeek prompt, with no idea that prompt would travel to a US frontier model and back. Anthropic's platform now embeds summarised thinking blocks and reasoning signatures specifically to block unauthorised exfiltration of chain-of-thought reasoning.[4]
Scale of the Alibaba operation
The Moonshot and DeepSeek campaigns were serious. The Alibaba campaign was a different order of magnitude.
Operators affiliated with Alibaba generated over 151 million exchanges between May and July 2026, running more than 3,500 fraudulent accounts and pushing peaks close to three million Claude queries per day, all to harvest reasoning data for training Qwen models.[1] Distillation attacks work by capturing a frontier model's internal reasoning, the step-by-step logic it uses to reach an answer, and feeding that data into a competing system at a fraction of the compute cost required to generate it from scratch.
Anthropic's Threat Intelligence team said the cases in its September 2026 report represent the most notable and novel threat activity identified to date. The team said: "We're publishing this work because we believe we have a responsibility to disclose malicious misuse of our services. As models become increasingly capable, their risks will increase, unless AI developers and society's defenders act to make them safer."[1]
AI-enabled cyber operations and zero-day findings
The distillation campaigns sit alongside a separate and more direct threat documented in the same report. GTG-20006, a Russian-linked threat actor, used AI-driven workflows to automate reconnaissance, phishing and implant development against more than 20 government and defence bodies across Ukraine and Europe.[1] Each step of the attack chain that previously required a team ran with minimal human oversight.
A separate autonomous workflow targeting security appliances produced more than a dozen previously unknown zero-day vulnerabilities inside a single month.[1] Open-source frameworks such as PentAGI, available publicly on GitHub, already automate the same kill-chain steps used by these real-world actors, so the capability is no longer confined to well-resourced state groups.[3]
The report also documents a state military laboratory using Claude to research mutations of chikungunya, a mosquito-borne virus that causes severe joint pain and fever and for which no approved antiviral treatment exists.[2] Anthropic did not name the state or the laboratory.
The practical signal for any operator building on a third-party AI API is direct: your users' prompts may travel further than the endpoint you think you are calling. Anthropic's September 2026 report covers activity through the end of July, with further disclosures planned as analysis continues.[1]
KEY TAKEAWAYS
SOURCES & CITATIONS
FREQUENTLY ASKED QUESTIONS
How did Chinese AI labs access Anthropic's Claude without authorisation?
What sensitive data was exposed in these operations?
What is AI model distillation and why does it matter?
What AI-enabled cyber threats did Anthropic's report identify beyond distillation?

Takeshi Mori writes about technology and start-ups. He is curious about how products get built and who they are really for, and he would rather see a thing working than hear it described.




