Anthropic Attributes Its Largest Measured Distillation Campaign to Alibaba

September 11, 2026
Anthropic says Alibaba used more than 151 million Claude exchanges to train Qwen models, while Moonshot AI routed Kimi customer requests to Claude and saved some responses for training.
Anthropic Attributes Its Largest Measured Distillation Campaign to Alibaba

Anthropic says in a threat intelligence report that it has detected and disrupted unauthorised distillation campaigns since February 2026, attributed with high confidence to specific PRC based labs targeting its Opus class models.

The largest it has measured is attributed to operators affiliated with Alibaba Group: over 151 million exchanges observed between May and July 2026, peaking at nearly 3 million exchanges a day from more than 3,500 fraudulent accounts. Anthropic says the campaign targeted the chain of thought reasoning transcripts of Opus 4.6 and 4.7, forcing Claude to write out its reasoning inside inline tags before answering, and that the harvested transcripts were used to distil Claude's capabilities into Qwen 3.5, 3.6 and 3.7. It says Claude was also used to help build Alibaba's reinforcement learning environments and advance its model architecture research.

Moonshot AI is described doing something different. Anthropic says Moonshot silently forwarded customer requests to Claude rather than processing them with Kimi, and showed Claude's responses to those users: almost 300,000 customer requests over a ten day period, the vast majority routed to Opus, through 5,380 fraudulent accounts mostly appearing to be in Singapore and Japan. People who thought they were using Kimi were being answered by Claude.

The privacy finding is the one least likely to travel and it deserves to. Anthropic says DeepSeek, Xiaomi and Moonshot fed conversations between their own models and their users into Claude, then trained on Claude's responses. Many of those exchanges were relayed from third party model routing services commonly used in the United States and Europe, and contained names, email addresses, company data and other sensitive data belonging to hundreds of end users in at least a dozen languages. Anthropic says these practices are likely inconsistent with privacy laws and with the labs' own terms of service.

One finding from Anthropic's own research sits underneath all of it: a model distilled from a frontier model can acquire dangerous capabilities, including in biological and cyber domains, even when the harvested exchanges contain little about those subjects, because the safeguards that stop Claude being misused do not transfer when the model is distilled by an unauthorised lab.

We hope you enjoyed this article.

Consider subscribing to one of our newsletters like Cybersecurity AI Weekly or Daily AI Brief.

Also, consider following us on social media:

Subscribe to Cybersecurity AI Weekly

Weekly newsletter about AI in Cybersecurity.

Market report

2025 Generative AI in Professional Services Report

Thomson Reuters

This report by Thomson Reuters explores the integration and impact of generative AI technologies, such as ChatGPT and Microsoft Copilot, within the professional services sector. It highlights the growing adoption of GenAI tools across industries like legal, tax, accounting, and government, and discusses the challenges and opportunities these technologies present. The report also examines professionals' perceptions of GenAI and the need for strategic integration to maximize its value.

Read more