News

Seven Chinese AI Labs Stole 190 Million Claude Exchanges. Here’s How They Did It.

Seven Chinese AI Labs Stole 190 Million Claude Exchanges. Here's How They Did It.

Between May and July 2026, accounts linked to Alibaba’s AI division generated more than three million conversations with Anthropic’s Claude every single day. Not to build better products for their customers. Not to run legitimate research. To steal the way Claude thinks.

By the time Anthropic shut the campaign down, those accounts had produced over 151 million unauthorized exchanges, training data that was then used to improve Alibaba’s Qwen 3.5, 3.6, and 3.7 models. Anthropic calls it “the largest distillation attack we have ever measured.”

And Alibaba wasn’t alone. On September 10, 2026, Anthropic published its most detailed threat intelligence report to date, naming seven China-based AI labs behind a combined total of roughly 190 million unauthorized Claude interactions since February 2026. Three days earlier, the US government had already moved: CISA, FBI, and the NSA issued a joint advisory formally accusing Chinese AI companies of running “industrial-scale” extraction campaigns against American frontier models.

The timing wasn’t a coincidence. Together, these two documents form something that matters well beyond the AI industry.

Quick answer: Anthropic’s September 2026 threat intelligence report identified and shut down seven illicit AI distillation campaigns run by China-based labs including Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime, and MiniMax. The campaigns generated approximately 190 million unauthorized exchanges with Claude using networks of fake accounts, stolen credit cards, and dark web markets for compromised credentials. Alibaba alone accounted for 151 million of those exchanges. US intelligence agencies issued a joint advisory three days before Anthropic’s report, coordinating what amounts to a public evidence record for future enforcement.

What Distillation Is And Why the Chain-of-Thought Data Is the Real Prize

Knowledge distillation is a legitimate and widely used AI training technique. It works like this: a large, powerful “teacher” model produces outputs, and a smaller “student” model trains on those outputs to develop similar capabilities without the full cost of original training. Every major AI lab uses some version of this internally.

The controversy isn’t the technique. It’s what these labs allegedly did to get the training data.

Specifically, they went after something more valuable than Claude’s final answers: its chain-of-thought reasoning. This is the step-by-step internal thinking process that advanced models like Claude Opus use before arriving at a conclusion. When you see Claude work through a problem methodically, explaining its logic at each step, that’s chain-of-thought.

Teaching a student model how to reason produces far better results than teaching it what conclusions to reach. A model trained on chain-of-thought transcripts doesn’t just learn answers. It learns thinking patterns, the same reasoning architecture that makes frontier models valuable for complex tasks.

Alibaba’s campaign specifically extracted CoT transcripts from Claude Opus 4.6 and 4.7 at industrial scale, using a fixed prompt injected into every request that forced Claude to write out its full internal reasoning before answering. The pipeline then stripped everything except those reasoning traces and fed them into fine-tuning data for Qwen. This is why Anthropic has since updated its models to summarize rather than fully expose their reasoning, a direct countermeasure against this exact extraction technique. The newest model, Fable 5.1, goes further, encrypting reasoning traces so that even if an attacker intercepts the chain-of-thought, it can’t be read.

The Dark Web Infrastructure Behind the Attacks

This is where the story connects to a pattern we’ve been tracking across multiple stories throughout 2026.

Anthropic’s head of threat intelligence, Jacob Klein, told CNBC that the illicit access ecosystem extends into dark web markets, specifically, markets for compromised AI platform accounts, stolen payment information, and purchased API keys. These aren’t sophisticated technical exploits. They’re purchasing problems. Someone needs a thousand accounts to run a distillation pipeline. Instead of registering them manually, they buy the credentials in bulk from an underground market that sells exactly this.

The same dark web economy that powers stolen credit card carding shops, where bulk stolen payment data is bought and sold as a commodity, also powers the fraudulent account creation behind these AI extraction campaigns. The credit cards fund the fake accounts. The fake accounts run the queries. The queries become training data.

Anthropic calls the resulting account networks “hydra clusters.” The name is deliberately mythological: cut off one account, two more appear. One documented proxy network controlled over 20,000 fraudulent accounts simultaneously. When Anthropic bans an account, the operator simply activates another from its pool, funded by a different stolen card, registered under a different stolen identity.

This is the whack-a-mole problem Klein described. It’s not a battle against a person or a fixed infrastructure. It’s a battle against an economy. The same secondary markets that sell stolen identity data are the supply chain for fake AI accounts. As long as bulk identity data is available on underground markets, the raw materials for this kind of access exist in essentially unlimited quantities.

The Seven Labs and What Each One Did

Anthropic tracks each campaign using internal GTG (Generative Threat Group) designators. Here’s what each one actually involved.

GTG-16005: Alibaba / Qwen: 151 million exchanges between May and July 2026, peaking at nearly 3 million per day across more than 3,500 fraudulent accounts. The campaign specifically extracted chain-of-thought reasoning from Claude Opus 4.6 and 4.7 to train Qwen 3.5, 3.6, and 3.7. Alibaba did not publicly deny the allegations. It subsequently prohibited its own employees from using Claude Code, an internal policy shift that, read alongside the report, functions as a quiet acknowledgment of the problem.

GTG-16002: Moonshot AI / Kimi: 23 million exchanges between May and July 2026. Moonshot did something different from simply generating new queries: it silently rerouted its own customers’ requests to Claude instead of processing them through Kimi. Moonshot’s paying users had no idea their questions were going to Claude. Their conversations, and Claude’s responses, were captured and saved as training data. Over a 10-day window, Moonshot relayed almost 300,000 customer requests to Claude through 5,380 fraudulent accounts.

One detail buried in this campaign deserves its own attention. Among the Moonshot users whose requests were secretly rerouted to Claude, Anthropic identified one that it assessed as likely affiliated with the Chinese military. That user was using the service to review closed-circuit surveillance footage and determine whether a tracked individual was “behaving abnormally.” The query went to Claude. Claude’s response became training data. A surveillance task potentially linked to military intelligence passed through an American AI company’s servers without Moonshot’s customers, Claude’s users, or Anthropic knowing it was happening in real time.

GTG-16001: DeepSeek: 12.1 million exchanges over 14 days in July 2026, using the same approach as Moonshot โ€” silently rerouting user requests to Claude without informing customers.

GTG-16006: Zhipu / Z.ai: 3.4 million exchanges between June and July 2026, running a reasoning extraction pipeline through 273 rotating fraudulent accounts.

GTG-16008: Xiaomi / MiMo: 400,000 exchanges between March and April 2026. Xiaomi replayed user conversations and coding sessions from its MiMo models to Claude through OpenClaw and OpenCode coding harnesses.

GTG-16012: SenseTime: Rather than running its own proxy infrastructure, SenseTime purchased transcripts of Claude user exchanges directly from third-party data resellers. Proxy services that record and sell conversations without users’ knowledge.

GTG-16003: MiniMax: Built its own proxy service through a shell company that offered access to Claude and OpenAI’s models, collecting exchanges to train its own models.

The breadth of tactics here matters. Some labs built fake account farms. Some rerouted their own users. Some bought transcripts on the open market. Some built shell companies with commercial fronts. These are not experiments or edge cases. They’re distinct, parallel approaches to the same goal, running simultaneously across seven separate organizations.

This mirrors what we’ve seen in other underground supply chains throughout 2026, as we covered in how the Sonora government portal credentials ended up on underground forums, the dark web economy has matured to the point where multiple actors run structurally similar operations with different tools against the same targets.

The User Privacy Betrayal Nobody Is Talking About Enough

Most coverage has focused on what Chinese labs extracted from Claude. But there’s a second victim population that’s getting less attention: the actual users of Moonshot and DeepSeek who had their conversations secretly sent to a different AI company entirely.

Those users paid for Kimi or DeepSeek. They typed questions, ran analysis, submitted work materials. They had no indication their interactions were being quietly rerouted to a competitor’s model and saved.

According to Anthropic’s report, some of those conversations included sensitive information from major multinational companies and state-affiliated actors. Real work product. Real confidential exchanges. All of it passed through unauthorized channels and captured as training data without consent.

This is the same structural problem that makes ValueFirst’s appearance in dark web monitoring concerning: the service you trust is silently routing your data somewhere you didn’t choose. The difference is scale. Moonshot’s rerouting reportedly reached 300,000 separate customer interactions in ten days.

SenseTime’s approach is perhaps most instructive about the scale of the secondary market. The company didn’t build any attack infrastructure at all. It simply bought conversation transcripts. That market exists, is functional, and is apparently accessible enough that a company chose to shop there rather than build its own access pipeline. Someone is collecting and selling user interactions with frontier AI models as a business, without the knowledge of the users who generated them. Understanding what to do when your data is circulating without your consent matters here, even if most affected users have no way to know they’re in this situation.

The Government’s Coordinated Timing

The sequencing of these announcements wasn’t accidental.

On September 8, 2026, CISA, the FBI, and the NSA published joint advisory AA26-251A, formally accusing six Chinese AI companies of conducting industrial-scale distillation against US frontier AI models. Three days later, on September 10, Anthropic published its September threat intelligence report, the evidentiary document that backs the government’s accusation with specific numbers, specific company names, specific campaign details, and specific technical methodology.

The advisory creates the governmental accusation. Anthropic’s report provides the evidence base. Together they establish a public record that can be cited in trade negotiations, Congressional hearings, export control proceedings, and legal action. This didn’t happen by coincidence. This is how a coordinated public legal strategy gets built.

The April 2026 White House NSTM-4 memorandum had already designated foreign AI distillation campaigns as a national security threat and directed federal agencies to share intelligence with US AI developers. The September report is the downstream product of that directive: agencies sharing intelligence with Anthropic, Anthropic incorporating it into a public threat intelligence report, and that report serving as the foundation for the government advisory.

Anthropic CEO Dario Amodei has publicly supported this framing while drawing distinctions. He’s argued against blanket bans on Chinese open-weight AI models while advocating for action specifically against industrial-scale covert extraction. That nuance matters because Chinese open-weight models like DeepSeek’s earlier releases are widely used by developers globally, and painting them all with the same brush creates policy overreach problems. The Alibaba, Moonshot, and DeepSeek incidents described in this report are about unauthorized access to a commercial product, not about the existence of Chinese AI models generally.

China’s Commerce Ministry rejected the allegations as having “no factual or legal basis” and warned that countermeasures could follow.

Why China’s National Intelligence Law Makes This Worse

Here’s the context that most coverage leaves out.

Every Chinese company, regardless of where it operates, what servers it uses, or what privacy policy it publishes, is subject to China’s National Intelligence Law. Article 7 of that law requires all organizations and citizens to “support, assist, and cooperate with national intelligence work.” There is no opt-out. There is no legal structure a Chinese company can establish that removes this obligation.

What that means for this story: any conversation transcripts, reasoning traces, or capability data that Chinese labs extracted from Claude, whether through Moonshot’s silent rerouting or SenseTime’s market purchases, are potentially accessible to Chinese intelligence agencies on demand. The 190 million exchanges didn’t just train Alibaba’s Qwen models. They represent a dataset that Chinese law requires those companies to hand over to the state if asked.

Some of those 190 million exchanges included enterprise data from multinational companies. Some included queries that Anthropic assessed as likely coming from Chinese military-affiliated users. The full population of what was captured is unknown.

What Anthropic Has Changed

The company’s response to this wave of attacks involves both detection and technical countermeasures.

On the detection side, Anthropic now bans accounts operating through proxy services and accounts from unsupported regions when identity verification fails. Reseller accounts, the commercial intermediaries that proxy operators use to distribute access, face higher scrutiny.

On the technical side, Claude’s behavior has been changed so it summarizes its internal reasoning rather than fully exposing it, making raw CoT extraction less useful as training data. The newer Fable 5.1 model goes further with what Anthropic calls “preserved thinking”: new API accounts can no longer alter the system prompt, tools, or messages that precede Claude’s reasoning in multi-turn conversations. The reasoning itself is now encrypted, so even if an attacker intercepts the CoT through a rerouting attack, it cannot be read in the form needed for fine-tuning.

Notably, none of the documented misuse cases in the September report involved the Fable 5.1 or Mythos-class models, with one limited exception. The campaigns ran on Claude Haiku, Sonnet, and Opus, the generally available models. The restricted-access higher tier appears so far to be holding its security posture.

What This Changes for Businesses Using AI

The story has a practical implication that extends beyond the AI industry itself.

If your company uses an AI service built on top of a third-party model, and many enterprise tools are, the question of where your queries actually go matters. The Moonshot and DeepSeek revelations show that a company can present one model to its customers while silently routing requests to another. Your data’s actual path may not match the interface you’re interacting with.

This is the same vendor risk principle we covered when looking at supply chain attacks and how third-party vendors create invisible exposure paths: trust is placed in the brand you interact with, not necessarily in the infrastructure underneath. Asking your AI vendor which models actually process your requests, and whether your conversations are stored, sold, or used for training โ€” is no longer a hypothetical security question. It’s a procurement one.

The dark web monitoring signal from ValueFirst’s India exposure earlier this year pointed to the same gap: communications infrastructure held sensitive enterprise data that the companies routing through it didn’t know was being collected. The AI distillation story is that pattern operating at geopolitical scale.

Frequently Asked Questions

What is illicit AI distillation?

Using the outputs of a frontier AI model like Claude to secretly train a competing model, without permission and at industrial scale, usually through fake accounts and proxy networks.

Which Chinese labs did Anthropic name?

Alibaba (Qwen team), Moonshot AI (Kimi), DeepSeek, Zhipu AI (Z.ai), Xiaomi (MiMo), SenseTime, and MiniMax. Seven labs in total, generating approximately 190 million unauthorized Claude exchanges since February 2026.

What is chain-of-thought, and why does it matter?

Chain-of-thought is the step-by-step reasoning process a model uses before reaching an answer. Training on CoT data teaches a student model how to reason, not just what to conclude, making it far more valuable for capability transfer than training on final answers alone.

Why did Moonshot’s attack affect users who didn’t know about it?

Moonshot silently rerouted its own customers’ queries to Claude instead of processing them through its Kimi models. Those users had no idea their conversations were going to Claude. Their data became training material without their knowledge or consent.

What is the dark web’s role in these attacks?

Dark web markets sell compromised AI platform accounts, stolen payment credentials, and harvested API keys in bulk. Attackers use these to create large pools of fraudulent accounts that replace each other when banned, making account-level blocking ineffective.

Why did the US government advisory come out three days before Anthropic’s report?

The timing was coordinated. CISA, FBI, and NSA published the government’s formal accusation on September 8; Anthropic published the supporting evidence on September 10. Together they establish a public legal and evidentiary record for potential enforcement proceedings.

Written by Muhammad Anas

Contributing writer at DarkWebDecoded.com covering dark web security, scam alerts, and privacy tools.

๐Ÿ“‹ Latest Articles

View all →
synthetic identity dark web
News

A Fake Person That Passes Bank Verification Costs $200. Here’s How They’re Built.

Somewhere on a dark web marketplace right now, you can buy a complete human identity for $200. It…

Sep 14, 2026
11 min read
Greenberg Traurig Data Breach
News

Greenberg Traurig Data Breach: One Law Firm Hit. Six in Three Weeks. Here’s the Real Story.

Greenberg Traurig confirmed a data breach to Vermont’s Attorney General on September 8, 2026. A ransomware group called…

Sep 12, 2026
10 min read
Operation Alice dark web
News

Operation Alice: One Person Was Running 373,000 Dark Web Sites. Every Customer Is Now a Suspect.

Between March 9 and March 19, 2026, law enforcement agencies from 23 countries quietly dismantled one of the…

Sep 10, 2026
10 min read
Bank of Baroda Data Breach
News

Bank of Baroda Data Breach: Why TripleX Released 1TB for Free And Why That’s the Whole Story

When a ransomware group steals data, the usual move is to demand payment. Hand over the money, or…

Sep 10, 2026
10 min read
Infostealer logs illustration showing a glowing ZIP archive leaking stolen passwords, browser cookies, credit cards, and crypto wallet data from a laptop
Guides

Infostealer Logs – The Breach That Rarely Gets Reported

Infostealer logs: In the first half of 2025, over 1.8 billion credentials containing saved passwords, usernames, phone numbers,…

Sep 10, 2026
12 min read
Wireframe chat marketplace stamped "SEIZED" beside frozen crypto wallets, illustrating the Xinbi Guarantee takedown and $52.8M freeze.
News

Xinbi Guarantee Seized – Inside the $24B Telegram Scam Marketplace

If you ask the average person where the largest criminal marketplaces on the internet are located, they’ll say…

Sep 10, 2026
10 min read
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted