Anthropic announced that it had detected and disrupted a large-scale unauthorized effort by a China-based AI research institute. alibabaMoonshot and DeepSeek use Claude to train their models.
The US AI company said in a threat intelligence report released Thursday that it was involved in what it called “illicit distillation.” This process involves using the output from a more powerful AI model to train another model and duplicating some of its functionality without permission.
“Some of these exchanges included sensitive information from individual users, large multinational corporations, and state-affiliated actors. … These activities are likely to be inconsistent with privacy laws and the institute’s own terms of service,” the report said.
According to Anthropic, carriers partnered with Alibaba used Claude’s output to help train their Qwen models, and Moonshot routed some Kimi user requests to Claude and used some of the resulting exchanges to train its own models.
Alibaba’s operation is the largest distillation campaign measured by Anthropic, with more than 151 million interactions with Claude between May and July.
The activity peaked at nearly 3 million exchanges per day from more than 3,500 fraudulent accounts, according to the report. Alibaba also uses Claude for a wide range of AI research, including reinforcement learning and model architecture, the company said.
moonshot and deep seek
Anthropic also detailed the activities involved in Moonshot AI, the Beijing-based company that is developing the Kim family of AI models.
According to the report, Moonshot silently forwarded some customer requests intended for Kimi to Claude and displayed Claude’s responses to users who thought they were using the Kimi model.
Moonshot relayed approximately 300,000 customer requests to Anthropic over a 10-day period, with the majority going to the Claude Opus model. The requests were routed through a network of 5,380 accounts that Anthropic described as fraudulent, most of which appeared to be in Singapore and Japan.
Moonshot saved at least some of these interactions and extracted Claude’s reasoning records to use as training data for its own models, according to the report.
According to the report, more than 23 million transactions were attributed to moonshots from May to July.
Some of the customer requests sent to Claude contained confidential information. The company said it was unclear whether Moonshot notified customers that their requests would be sent to Anthropic.
DeepSeek, which rose to prominence last year for its features and low costs, used a similar tactic to Moonshot, transferring its exchange to Claude without notifying DeepSeek customers, the company said. Anthropic announced that it observed over 12 million distillation attacks attributed to DeepSeek in a 14-day period in July 2026.
The report names several other major Chinese AI companies and covers the activities they said they disrupted in seven areas from December 2025 to August 2026, including cyber operations, influence operations, surveillance, fraud and deception, biological abuse, conventional weapons development, and distillation.
Alibaba, Moonshot, DeepSeek, Xiaomi and Anthropic did not immediately respond to CNBC’s requests for comment.
