China Based AI Labs Face Anthropic Claims Over Claude Distillation Campaigns

Published:

Anthropic has revealed that it identified and disrupted multiple industrial scale illicit distillation campaigns that allegedly targeted its Claude artificial intelligence models. According to the company, seven China based AI labs, including Alibaba, Moonshot AI, DeepSeek, Z.ai (Zhipu), MiniMax, SenseTime, and Xiaomi, were linked to activities designed to replicate Claude’s capabilities without authorization. While knowledge distillation is widely recognized as a legitimate machine learning technique used to transfer knowledge from a larger model to a smaller one, Anthropic said these operations crossed into unauthorized territory by covertly extracting model outputs through large scale automated campaigns. The company added that the activity relied on networks of fraudulent accounts, stolen or fake payment methods, compromised login credentials, and unlawfully obtained API keys to gain repeated access to Claude’s services.

Anthropic explained that unauthorized AI developers have adopted increasingly advanced methods to bypass security controls and gather high quality training data from frontier AI models. According to the company, some operators routed requests through proxy or relay services that generated thousands of fictitious accounts to avoid detection. These proxy networks allegedly enabled continuous access to Claude while masking the identity of the actual users. Anthropic also stated that several organizations captured conversations between their own AI systems and Claude, then used Claude’s responses to improve their own models. In some cases, the exchanges reportedly contained sensitive information originating from individuals, multinational companies, and state affiliated entities. The company further claimed that unauthorized labs acquired conversation transcripts from third party proxy service operators that stored user interactions without users being aware of the practice. Anthropic also noted that some customer requests were silently redirected to Claude instead of being processed by the providers’ own AI models, allowing conversation data to be collected and later incorporated into model training.

Since February 2026, Anthropic said it has tracked several large scale campaigns involving different organizations. The largest activity, identified as GTG 16005, was attributed to Alibaba affiliated operators and reportedly involved approximately 151 million exchanges between May and July 2026. Anthropic described it as the largest distillation campaign it has measured, with activity reaching around three million exchanges per day across more than 3,500 fraudulent accounts focused on software engineering, agentic tasks, kernel development, and advanced reasoning. GTG 16002, linked to Moonshot AI, allegedly rerouted customer requests intended for its Kimi platform to Claude and stored portions of the responses for model training. Anthropic estimated that nearly 300,000 customer requests were relayed during a ten day period using more than 5,000 fraudulent accounts operating mainly from Singapore and Japan. Similar methods were reportedly observed in GTG 16001 involving DeepSeek, while GTG 16006 focused on Zhipu using hundreds of fraudulent accounts to collect reasoning traces. Additional campaigns involved Xiaomi, which reportedly replayed coding sessions from its MiMo models, SenseTime, which allegedly obtained conversation transcripts from third party data vendors, and MiniMax, which was said to have established its own proxy service infrastructure to gather exchanges involving Claude and other United States frontier AI models.

To reduce the effectiveness of these campaigns, Anthropic said it has strengthened its security measures by banning reseller accounts and accounts operating from unsupported regions such as China, Iran, and Russia when identity verification requirements are not met. The company has also modified Claude so that it summarizes its internal reasoning before providing responses, making captured transcripts less valuable for future training. In addition, Anthropic introduced preserved thinking in Fable 5.1, a feature that encrypts model reasoning and prevents newly created API accounts from altering system prompts or conversation context in ways that could expose internal reasoning processes. The announcement follows Anthropic’s recent disclosure that it removed accounts attempting to use its AI models for surveillance activities and research that could support biological threats. Earlier this week, United States cybersecurity and intelligence agencies also publicly accused several China based AI companies of conducting systematic extraction of proprietary capabilities from American frontier AI models through unauthorized distillation campaigns.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img