AI Models Neutral 7

Anthropic IDs 151M-example illicit distillation of Claude

AI researchers get a rare data point: Anthropic details how Alibaba executed 151M exchanges to distill Claude into Qwen, while Moonshot and DeepSeek used live conversation routing as training data.

· 4 min read · Verified by 3 sources ·

Beat this week

Last 7 days · AI Models

10 stories
6.8 avg impact
20% positive
30% negative
vs prior 7 days +5 +5 stories vs prior 7 days

Impact 6.8/10 (+0.8 vs prior). Counts are stories in our record, not a market forecast.

Open the change report

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 10 percentage points.

  • 20% positive
  • 50% neutral
  • 30% negative

This story sits in AI Models — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.

Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.

AI briefing

Key takeaways

7 impact
Neutralsentiment
3sources
4min read
  1. AI researchers get a rare data point: Anthropic details how Alibaba executed 151M exchanges to distill Claude into Qwen, while Moonshot and DeepSeek used live conversation routing as training data.
Drawn from
  • rappler.com
  • freemalaysiatoday.com
  • livemint.com

In this briefing

Mentioned

Key Intelligence

Key Facts

  1. 1Anthropic reported disrupting malicious Claude use over an eight-month period before September 10, 2026, including activity from seven China-based labs.
  2. 2Alibaba operators allegedly ran the largest illicit distillation campaign, with more than 151 million exchanges between May and July 2026, peaking near 3 million per day from over 3,500 fraudulent accounts.
  3. 3Moonshot and DeepSeek allegedly routed live customer conversations, sometimes containing sensitive information, through Claude and used its responses as training data.
  4. 4Anthropic also linked activity to Russia-based threat actor Midnight Blizzard and highlighted the ShinyHunters cybercrime collective.
  5. 5Anthropic says humans became overseers rather than hands-on operators, as multi-agent frameworks directly executed or orchestrated attack tasks.
  6. 6The report identified a new threat actor category: AI misuse for developing software related to conventional weapons.
Tactic
Method Bulk illicit distillation Live conversation routing
Scale 151M exchanges Not quantified
Data sensitivity Claude model outputs Customer conversation data
Intent Improve Qwen models Train Kimi/DeepSeek models

The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing tasks

Anthropic Threat Intelligence Team Anthropic Threat Intelligence report

September 2026 report on AI misuse

Analysis

This is not just an enforcement announcement—it's a technical case study in adversarial distillation. The distinction between bulk query extraction and live conversation routing matters for anyone designing frontier model defenses, watermarking systems, or API monitoring pipelines.

Anthropic's September 10, 2026 threat intelligence disclosure shifts the AI security conversation from theoretical risk to documented industrial-scale exploitation. The company said it disrupted multiple malicious uses of its Claude models over the preceding eight months, including what it described as a suspected Russia-linked cyber espionage campaign and coordinated efforts by Chinese AI labs to extract and replicate Claude's capabilities. The report names seven China-based labs, singling out Alibaba, Moonshot, DeepSeek, and Xiaomi. The most detailed allegation centers on Alibaba, where Anthropic says it observed more than 151 million exchanges between May and July 2026, peaking at nearly three million per day from more than 3,500 accounts it called fraudulent. Anthropic asserted the campaign was the largest "illicit distillation" attack against Claude, aimed at improving Alibaba's Qwen models.

The report names seven China-based labs, singling out Alibaba, Moonshot, DeepSeek, and Xiaomi.

The operational detail matters. Distillation—training a smaller or cheaper model on outputs from a larger, more expensive frontier model—has become the primary vector for model capability theft. Anthropic's report distinguishes between bulk query-based distillation and a more invasive tactic: Moonshot and DeepSeek allegedly routed live customer conversations, sometimes containing sensitive information, through Claude and used its responses as training data. That claim moves beyond IP theft into potential data leakage, because real user queries and context may have been used to teach competing models. For any enterprise whose employees or customers used those services, the report raises questions about where their data ended up and how AI providers monitor intermediary traffic.

The report also highlights a shift in how attackers use AI. Anthropic said a majority of the operations were enabled by AI through direct execution or orchestration, with humans acting as overseers rather than hands-on operators. Multi-agent frameworks now allow attackers to automate account creation, query generation, response parsing, and adaptation at scale—an evolution from simple chatbot prompting. This explains the enormous volume associated with the Alibaba campaign and signals that abuse detection must move from static rate limits to behavioral and agentic-pattern analysis.

The geopolitical and criminal dimensions compound the risk. Anthropic disclosed activity by a hacking group whose tradecraft was consistent with Russia-based threat actor Midnight Blizzard, a group Microsoft and other firms have long tied to Russian intelligence. The report also highlighted ShinyHunters, a cybercrime collective known for high-profile data theft and extortion. Perhaps most concerning, Anthropic said it identified new categories of threat actors misusing AI for developing software related to conventional weapons. That introduces dual-use and export-control considerations that go well beyond commercial competition.

What to Watch

For the AI industry, the report sharpens an already contentious debate over open weights, API access, and model security. Frontier labs may accelerate output watermarking, fingerprinting, and account identity verification to detect and deter distillation. Cloud and SaaS providers that embed Claude or other models will face pressure to explain their own monitoring and data-flow controls. Investors may begin pricing security posture into AI startup valuations, particularly for companies that rely on third-party model APIs or expose proprietary data to model endpoints.

Looking forward, Anthropic's publication is likely to intensify calls for regulatory action against illicit model extraction. It may also push rival labs to issue their own threat reports, creating a public arms race in AI security transparency. The broader lesson is that frontier AI systems are now critical infrastructure, and their misuse by state actors and criminal syndicates is measurable, scalable, and increasingly automated. The next wave of AI policy will probably focus not on hypothetical existential risk but on concrete enforcement against model theft and AI-enabled espionage.

Source cluster

Primary reporting

3articles

Cite This Page

"Anthropic IDs 151M-example illicit distillation of Claude." AI Intelligence Brief, September 11, 2026. https://getaibrief.com/story/ai-model-distillation-anthropic-151m-claude

How we covered this story

Every story in our AI coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the AI space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.