Anthropic Says Alibaba, DeepSeek Used Claude to Train Rival Models
China

Martin LELIEVRE / AFP via Getty Images/Getty
Source Analysis
What Happened
What Happened
Where Sources Agree
- arrows_inputAlibaba's Large-Scale Distillation Campaign: Coverage highlights that Alibaba conducted the largest distillation campaign observed, involving over 151 million exchanges across 3,500 fraudulent accounts between May and July to train its Qwen models, according to Anthropic's threat intelligence report.
- arrows_inputAI-Driven Cyber Espionage: Various sources indicate that the Russia-linked Midnight Blizzard group utilized AI to orchestrate cyber-espionage campaigns against Ukrainian government and military entities; the group employed multi-agent frameworks to automate malware code rewriting for detection evasion, according to Anthropic's threat intelligence report.
- arrows_inputUS Government Sanction Considerations: Various reports document that the US government is considering sanctions and Entity List designations for companies engaged in illicit AI distillation; Treasury Secretary Scott Bessent confirmed these measures are "on the table" for intellectual property theft.
Where Sources Disagree
- arrows_outputFraudulent Account Count Discrepancy: Some outlets report that DeepSeek, Moonshot, and MiniMax utilized 24,000 fraudulent accounts for distillation campaigns. Conversely, other reports cite a smaller network of 5,000 to 5,380 accounts used by Moonshot and DeepSeek.
- arrows_outputMoonshot Distillation Volume: Reports vary on the total volume of distillation exchanges attributed to Moonshot AI, with some sources citing over 3.4 million exchanges while others report the figure reached over 23 million during the same period.
- arrows_outputDistillation Attack Figures: Reports vary slightly regarding the total volume of distillation attacks identified, with some sources citing nearly 190 million exchanges while others report the figure closer to 200 million.
Timeline
September 11, 2026
September report and responses: On September 11, 2026 Anthropic released a Threat Intelligence report naming Alibaba, Moonshot, DeepSeek, Xiaomi and Zhipu and saying the five labs launched nearly 190 million distillation exchanges (part of ~200 million total across five campaigns); the company said it had banned associated accounts, added safeguards (including producing less-detailed reasoning transcripts) and engaged authorities. The disclosures prompted joint accusations by U.S. agencies and raised the prospect of sanctions or Entity List actions for firms found to have crossed into IP theft.
July 31, 2026
May–July large-scale campaigns: Between May and July 2026 Anthropic observed massive distillation activity: operators linked to Alibaba generated more than 151 million Claude exchanges (peaking near 3 million/day across ~3,500 fraudulent accounts), Moonshot accounted for over 23 million exchanges, and DeepSeek produced more than 12 million exchanges over a 14-day span. Anthropic said these campaigns targeted Claude's advanced capabilities and in some cases relayed live customer conversations without users' knowledge.
June 05, 2026
June letter to lawmakers: In a June letter to U.S. senators Anthropic's head of policy said Alibaba illicitly ran roughly 28.8 million exchanges with Claude between April 22 and June 5, calling for legislation to curb such attacks. That disclosure preceded the wider threat-intelligence report and signaled the issue moving into policy debates.
Summaries by Ground AI
Sources
See All 49Most Written About
The stories getting the most coverage from the last 24 hours
Source Analysis
Timeline
September 11, 2026
September report and responses: On September 11, 2026 Anthropic released a Threat Intelligence report naming Alibaba, Moonshot, DeepSeek, Xiaomi and Zhipu and saying the five labs launched nearly 190 million distillation exchanges (part of ~200 million total across five campaigns); the company said it had banned associated accounts, added safeguards (including producing less-detailed reasoning transcripts) and engaged authorities. The disclosures prompted joint accusations by U.S. agencies and raised the prospect of sanctions or Entity List actions for firms found to have crossed into IP theft.
July 31, 2026
May–July large-scale campaigns: Between May and July 2026 Anthropic observed massive distillation activity: operators linked to Alibaba generated more than 151 million Claude exchanges (peaking near 3 million/day across ~3,500 fraudulent accounts), Moonshot accounted for over 23 million exchanges, and DeepSeek produced more than 12 million exchanges over a 14-day span. Anthropic said these campaigns targeted Claude's advanced capabilities and in some cases relayed live customer conversations without users' knowledge.
June 05, 2026
June letter to lawmakers: In a June letter to U.S. senators Anthropic's head of policy said Alibaba illicitly ran roughly 28.8 million exchanges with Claude between April 22 and June 5, calling for legislation to curb such attacks. That disclosure preceded the wider threat-intelligence report and signaled the issue moving into policy debates.










