From Three Labs to Seven
In February 2026, Anthropic named three Chinese AI companies — DeepSeek, Moonshot AI, and MiniMax — running "industrial-scale" distillation campaigns against Claude, totaling roughly 16 million exchanges through about 24,000 fraudulent accounts (Labs' coverage at the time). In its September 10, 2026 threat intelligence report, Anthropic said the picture has grown considerably: seven China-based labs — the original three plus Alibaba, Zhipu (Z.ai), Xiaomi, and SenseTime — have now been tied to illicit distillation activity, spanning campaigns tracked as GTG-16001 through GTG-16012 and totaling more than 190 million unauthorized exchanges with Claude.
Knowledge distillation — training a smaller "student" model to mimic a larger "teacher" model's outputs — is a legitimate and widely used machine learning technique on its own. What makes these campaigns illicit, according to Anthropic, is how the exchanges were obtained: through fraudulent accounts, stolen credentials, and infrastructure built specifically to evade detection and access limits rather than through licensed API use.
How the Campaigns Operated
- Thousands of fake accounts created using stolen payment methods and stolen or fraudulently obtained API keys
- Traffic rerouted through proxy services to mask the true origin of requests and harvest Claude's responses at scale for use as training data
- A secondary market for conversations — some operators reportedly purchased user conversation transcripts from third-party resellers rather than querying Claude directly, meaning exposure extended beyond Anthropic's own systems to any transcripts already leaked or resold elsewhere
Anthropic's Response
Anthropic said it has:
- Banned reseller accounts that were feeding the secondary transcript market
- Changed how Claude's reasoning is summarized in its outputs
- Rolled out encrypted reasoning designed to prevent prompt manipulation aimed at extracting raw chain-of-thought content
Why This Matters
The jump from three labs and 16 million exchanges to seven labs and 190 million reframes distillation from an isolated incident involving a handful of aggressive competitors into what looks like a broader pattern across China's frontier AI ecosystem. For an industry already navigating export-control debates and IP-theft accusations between the US and China, naming Alibaba, Zhipu, Xiaomi, and SenseTime alongside the previously identified DeepSeek, Moonshot AI, and MiniMax gives policymakers a much larger body of evidence to point to.
It's also a reminder that model providers' own API access controls are only part of the exposure surface — a resold-transcript market means capability extraction can continue even after direct API abuse from a given account is shut down, which is likely why Anthropic is now targeting resellers directly rather than only banning source accounts.