Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Anthropic says it identified and disrupted seven industrial-scale attempts to extract capabilities from its Claude AI models, attributing the activity to China-based AI laboratories.

The company says the campaigns used fraudulent accounts, stolen credentials, proxy networks and automated systems to generate millions of interactions with Claude. The objective was to collect Claude's outputs and use them as training data for competing AI models.
Knowledge distillation is a legitimate machine-learning technique in which a smaller "student" model learns from a more capable "teacher" model. Anthropic says the activity it observed went beyond legitimate use, involving unauthorized, large-scale extraction of Claude's capabilities.
Seven Campaigns Identified
Anthropic linked the activity to seven China-based operations involving organizations including Alibaba, Moonshot AI, DeepSeek, Z.ai, Xiaomi, SenseTime and MiniMax.
| Organization | Reported Activity |
|---|---|
| Alibaba | Large-scale extraction of Claude reasoning and coding capabilities |
| Moonshot AI | Claude responses allegedly routed through its AI services |
| DeepSeek | Large-scale collection of Claude outputs |
| Z.ai / Zhipu | Extraction of reasoning data |
| Xiaomi | Replay of conversations and coding sessions |
| SenseTime | Acquisition of Claude transcripts through third parties |
| MiniMax | Proxy infrastructure used to obtain AI model interactions |
Anthropic says the campaigns focused on capabilities including reasoning, software engineering, agentic workflows, tool use and data analysis.
Millions of AI Exchanges
The scale of the activity was particularly significant.
Anthropic reported that some campaigns generated millions of exchanges with Claude, using large networks of accounts and automated infrastructure.
The company said attackers attempted to obtain not only normal model responses but also information that could help reproduce Claude's reasoning capabilities.
Some operators reportedly experimented with prompt-manipulation techniques designed to bypass safeguards and extract additional reasoning information.
Proxy Networks Helped Hide the Activity
According to Anthropic, several campaigns relied on intermediary proxy services to disguise the origin of requests and bypass geographic or account restrictions.
These networks could use:
- Fraudulent accounts
- Stolen payment cards
- Stolen API keys
- Compromised accounts
- Disposable email addresses
- Automated request systems
- Servers outside China
The use of proxy infrastructure makes attribution and detection more difficult because the AI provider may initially see apparently legitimate users connecting from different locations.
Privacy Risks
Anthropic also highlighted a significant data-privacy concern.
Some of the traffic reportedly involved user conversations, coding sessions and other information that could contain corporate or personal data.
This means illicit distillation can create two risks at the same time:
Model theft: AI capabilities are extracted and used to improve another model.
Data exposure: User prompts and generated responses may be collected by unauthorized intermediaries.
Why It Matters
The campaigns demonstrate that AI models themselves are becoming valuable targets for large-scale extraction.
Unlike traditional intellectual-property theft, attackers do not necessarily need access to model weights or internal infrastructure. They can attempt to reproduce useful capabilities by repeatedly querying a publicly accessible model and harvesting its responses.
For AI providers, this turns account security, API monitoring, behavioral analytics and abuse detection into critical parts of model protection.
For organizations using AI services, the incidents reinforce the need to avoid placing passwords, API keys, confidential source code or sensitive business information into untrusted AI platforms and third-party model-routing services.
Anthropic says it has disrupted the campaigns, strengthened its safeguards and shared relevant intelligence with authorities and industry partners.
The broader takeaway is clear: protecting an AI model is no longer only about securing its infrastructure. The accounts, APIs, prompts, outputs and third-party services surrounding the model have become part of the security perimeter.
SEO Meta Description:
Anthropic says seven China-based AI labs conducted industrial-scale Claude distillation campaigns using fraudulent accounts, proxies and millions of AI exchanges to extract model capabilities.
Related reporting
Attackers Use Passkey-Themed Phishing to Hijack Microsoft Cloud Accounts and Steal Data
Threat actors are using passkey-themed social engineering to compromise Microsoft 365 accounts and gain access to sensitive cloud data, according to Microsoft Threat Intelligence.
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Cybercriminals and state-sponsored threat actors are increasingly using artificial intelligence to automate portions of real-world cyberattacks, with Anthropic revealing that its Claude models were incorporated into multi-stage operations involving reconnaissance, exploitation, credential theft and data exfiltration.
Google Play Early Access Abused to Distribute Thousands of Deceptive Android Apps
Cybercriminals are exploiting Google Play's Early Access program to distribute deceptive Android applications, including fake gambling platforms, financial scams, game clones and potentially malicious utilities, while taking advantage of the lack of public ratings and reviews.


