Anthropic IDs 151M-example illicit distillation of Claude
AI researchers get a rare data point: Anthropic details how Alibaba executed 151M exchanges to distill Claude into Qwen, while Moonshot and DeepSeek used live conversation routing as training data.
Beat this week
Last 7 days · AI Models
Impact 6.8/10 (+0.8 vs prior). Counts are stories in our record, not a market forecast.
Open the change reportCoverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 10 percentage points.
This story sits in AI Models — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.
Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.
AI briefing
Key takeaways
- AI researchers get a rare data point: Anthropic details how Alibaba executed 151M exchanges to distill Claude into Qwen, while Moonshot and DeepSeek used live conversation routing as training data.
- rappler.com
- freemalaysiatoday.com
- livemint.com
In this briefing
Mentioned
Key Intelligence
Key Facts
- 1Anthropic reported disrupting malicious Claude use over an eight-month period before September 10, 2026, including activity from seven China-based labs.
- 2Alibaba operators allegedly ran the largest illicit distillation campaign, with more than 151 million exchanges between May and July 2026, peaking near 3 million per day from over 3,500 fraudulent accounts.
- 3Moonshot and DeepSeek allegedly routed live customer conversations, sometimes containing sensitive information, through Claude and used its responses as training data.
- 4Anthropic also linked activity to Russia-based threat actor Midnight Blizzard and highlighted the ShinyHunters cybercrime collective.
- 5Anthropic says humans became overseers rather than hands-on operators, as multi-agent frameworks directly executed or orchestrated attack tasks.
- 6The report identified a new threat actor category: AI misuse for developing software related to conventional weapons.
| Tactic | ||
|---|---|---|
| Method | Bulk illicit distillation | Live conversation routing |
| Scale | 151M exchanges | Not quantified |
| Data sensitivity | Claude model outputs | Customer conversation data |
| Intent | Improve Qwen models | Train Kimi/DeepSeek models |
The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing tasks
September 2026 report on AI misuse
Analysis
This is not just an enforcement announcement—it's a technical case study in adversarial distillation. The distinction between bulk query extraction and live conversation routing matters for anyone designing frontier model defenses, watermarking systems, or API monitoring pipelines.
Anthropic's September 10, 2026 threat intelligence disclosure shifts the AI security conversation from theoretical risk to documented industrial-scale exploitation. The company said it disrupted multiple malicious uses of its Claude models over the preceding eight months, including what it described as a suspected Russia-linked cyber espionage campaign and coordinated efforts by Chinese AI labs to extract and replicate Claude's capabilities. The report names seven China-based labs, singling out Alibaba, Moonshot, DeepSeek, and Xiaomi. The most detailed allegation centers on Alibaba, where Anthropic says it observed more than 151 million exchanges between May and July 2026, peaking at nearly three million per day from more than 3,500 accounts it called fraudulent. Anthropic asserted the campaign was the largest "illicit distillation" attack against Claude, aimed at improving Alibaba's Qwen models.
The report names seven China-based labs, singling out Alibaba, Moonshot, DeepSeek, and Xiaomi.
The operational detail matters. Distillation—training a smaller or cheaper model on outputs from a larger, more expensive frontier model—has become the primary vector for model capability theft. Anthropic's report distinguishes between bulk query-based distillation and a more invasive tactic: Moonshot and DeepSeek allegedly routed live customer conversations, sometimes containing sensitive information, through Claude and used its responses as training data. That claim moves beyond IP theft into potential data leakage, because real user queries and context may have been used to teach competing models. For any enterprise whose employees or customers used those services, the report raises questions about where their data ended up and how AI providers monitor intermediary traffic.
The report also highlights a shift in how attackers use AI. Anthropic said a majority of the operations were enabled by AI through direct execution or orchestration, with humans acting as overseers rather than hands-on operators. Multi-agent frameworks now allow attackers to automate account creation, query generation, response parsing, and adaptation at scale—an evolution from simple chatbot prompting. This explains the enormous volume associated with the Alibaba campaign and signals that abuse detection must move from static rate limits to behavioral and agentic-pattern analysis.
The geopolitical and criminal dimensions compound the risk. Anthropic disclosed activity by a hacking group whose tradecraft was consistent with Russia-based threat actor Midnight Blizzard, a group Microsoft and other firms have long tied to Russian intelligence. The report also highlighted ShinyHunters, a cybercrime collective known for high-profile data theft and extortion. Perhaps most concerning, Anthropic said it identified new categories of threat actors misusing AI for developing software related to conventional weapons. That introduces dual-use and export-control considerations that go well beyond commercial competition.
What to Watch
For the AI industry, the report sharpens an already contentious debate over open weights, API access, and model security. Frontier labs may accelerate output watermarking, fingerprinting, and account identity verification to detect and deter distillation. Cloud and SaaS providers that embed Claude or other models will face pressure to explain their own monitoring and data-flow controls. Investors may begin pricing security posture into AI startup valuations, particularly for companies that rely on third-party model APIs or expose proprietary data to model endpoints.
Looking forward, Anthropic's publication is likely to intensify calls for regulatory action against illicit model extraction. It may also push rival labs to issue their own threat reports, creating a public arms race in AI security transparency. The broader lesson is that frontier AI systems are now critical infrastructure, and their misuse by state actors and criminal syndicates is measurable, scalable, and increasingly automated. The next wave of AI policy will probably focus not on hypothetical existential risk but on concrete enforcement against model theft and AI-enabled espionage.
Source cluster
Primary reporting
- freemalaysiatoday.comAnthropic disrupts Russian , Chinese AI campaigns targeting Claude models
Cite This Page
"Anthropic IDs 151M-example illicit distillation of Claude." AI Intelligence Brief, September 11, 2026. https://getaibrief.com/story/ai-model-distillation-anthropic-151m-claude
How we covered this story
Every story in our AI coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the AI space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled AI-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |