Anthropic thwarts Alibaba-led Claude distillation attacks
Anthropic on Thursday said it had disrupted several allegedly malicious uses of its Claude models over the past eight months, including a suspected Russia-linked cyber espionage campaign and efforts by Chinese AI firms it accused of trying to extract and replicate Claude’s capabilities. The company’s September threat intelligence report covers activity it disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation.

Cybercriminals and state-backed hackers were increasingly using AI not just to assist with tasks but to orchestrate and execute large portions of cyberattacks, Anthropic said in its latest Threat Intelligence report. Jacob Klein, head of threat intelligence at Anthropic, said in an interview that models have become more capable over the last year, raising new risks.

Massive Distillation Attacks by Chinese AI Firms
Operators linked to Alibaba ran what Anthropic called the largest “illicit distillation” attack, allegedly aimed at extracting capabilities of Claude models and using them to improve the Chinese tech firm’s Qwen models, the company said. Anthropic said it observed more than 151 million exchanges it attributed to Alibaba between May and July 2026, peaking at nearly 3 million per day from more than 3,500 accounts it described as fraudulent. Alibaba did not immediately respond to a request for comment.

Distillation refers to the process of training smaller AI models using output from larger, more expensive models in a bid to lower the costs of training a new AI tool. However, the methods employed by Moonshot AI and DeepSeek allegedly went beyond bulk queries. Rather than running bulk queries, Kimi chatbot creator Moonshot and DeepSeek allegedly routed live customer conversations, which sometimes included sensitive information, through Claude and used its responses as training data, Anthropic alleged.
Anthropic named Moonshot AI, which it said silently forwarded customer requests to Claude and displayed the responses as though they came from its own Kimi model. Over one ten-day period, Anthropic said, Moonshot relayed almost 300,000 requests through a network of 5,380 fraudulent accounts. It attributed more than 23 million exchanges to Moonshot between May and July. The company made similar allegations against DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax.

In one case involving DeepSeek, the company used the same replay technique and relayed users’ requests to Claude Opus without their knowledge, logging over 12.1 million exchanges in 14 days in July 2026; Anthropic reported that the relayed traffic exposed sensitive material including live credentials.
Weapons Development and Military Applications
Anthropic identified what it called “new categories of threat actors” misusing Claude, including those using the platform to “develop software for conventional weapons, including firearms, missiles, armed drones, bombs, and other munitions, as well as the targeting and control systems that operate them.” The report detailed incidents of operators using Claude to develop software for weapons design and development, or to support intelligence gathering and procurement related to weapons programs, in China, Russia, and Yemen.
The most striking disclosure in the September 2026 report involves a China-based threat actor that used Claude to advance an anti-torpedo weapons system intended for the People’s Liberation Army Navy. The report detailed six cases, three in China, two in Russia and one in Yemen. In the Yemen case, the company said a cell in the north of the country ran three weapons programmes.
One case involved likely freelance Russia-based actors that used Claude Code to build an autonomous FPV kamikaze drone swarm whose onboard model could select targets, including a “person” class, and issue detonation commands without a human in the loop, training a vision classifier on scraped Ukrainian combat footage.
Russian Cyber Espionage Operations
A Russian espionage cluster the report tracks as GTG-20006 ran AI-assisted operations against Ukrainian, European and diplomatic targets. Anthropic writes that its investigation “identified more than 20 distinct organizations targeted in the actor’s operational planning, reconnaissance, and live operations.” One Russian-speaking actor hit around 30 AI companies in four days via a vendor sandbox breach.
The company said that it detected and disrupted activity linked to affiliates of the ShinyHunters cybercrime collective, one of the most prolific cybercrime enterprises in recent months linked to attacks on major corporations around the world.
Influence Operations and Surveillance
Nine influence operations spanned six continents. The report also documented surveillance and intelligence gathering activities by state-linked actors across multiple regions. A Russian cluster tagged GTG-20006 targeted more than 20 organizations, while a Chinese-speaking group in Changsha, Hunan hit roughly fifty across sectors.
AI Leveling the Playing Field for Threat Actors
Running through the report is a leveling finding: “AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators.” This observation suggests that advanced AI models are democratizing capabilities that were once the exclusive domain of sophisticated state actors, making it easier for smaller groups and individuals to execute complex operations.
Anthropic noted that “sophistication has stopped being a reliable signal,” which breaks the attribution playbooks most security teams still rely on. This represents a fundamental shift in how security professionals must approach threat detection and attribution.
Key Facts
- Timeline: Report covers activity disrupted between December 2025 and August 2026
- Alibaba distillation: More than 151 million exchanges observed between May and July 2026, peaking at nearly 3 million per day
- Moonshot AI: Nearly 300,000 requests relayed in one ten-day period through 5,380 fraudulent accounts; 23 million total exchanges attributed between May and July
- DeepSeek: Over 12.1 million exchanges logged in 14 days in July 2026, exposing sensitive material including live credentials
- Cyber espionage: Russian cluster GTG-20006 targeted more than 20 organizations; Chinese group hit roughly 50 organizations
- Weapons cases: Six conventional weapons development cases documented across China (3), Russia (2), and Yemen (1)
- Cybercrime: Activity linked to ShinyHunters affiliates detected and disrupted
Sources
- Livemint: Anthropic disrupts Russian, Chinese AI campaigns targeting its Claude models
- Rappler: Anthropic disrupts Russian, Chinese AI campaigns targeting its Claude models
- The Next Web: Anthropic details how Claude was misused for surveillance and weapons
- AI Weekly: Anthropic Details Russian, Chinese AI-Uplifted Ops on Claude
Sources
- Anthropic disrupts Russian, Chinese AI campaigns targeting Claude – Nikkei Asia
- Anthropic Details Russian, Chinese AI-Uplifted Ops on Claude | AI Weekly
- Anthropic disrupts Russian, Chinese AI campaigns targeting Claude models | FMT
- Anthropic disrupts Russian, Chinese AI campaigns targeting its Claude models
- Anthropic details how Claude was misused for surveillance and weapons
- Anthropic Details Disrupted Claude Misuse Across Seven Harm Areas – Unite.AI
- Streamlinefeed