Anthropic Accuses Chinese AI Labs Of Data Theft
Anthropic alleges Chinese AI labs routed user data through fake accounts, exposing sensitive information. Chinese labs accused of illicit distillation.

Anthropic, a leading AI company, has accused several Chinese AI laboratories of secretly routing customer prompts to its Claude models through networks of fraudulent accounts.
The allegations, detailed in Anthropic's latest threat intelligence report, mark an escalation in the company's ongoing dispute with Chinese AI developers over what it calls 'illicit distillation'.
According to the report, Moonshot AI, a Beijing-based maker of the Kimi chatbot, covertly diverted thousands of user requests to Claude and passed off the responses as its own, without informing users that their queries were being redirected.
Since Anthropic does not permit access to its technology from within China, Moonshot relied on 5,380 fraudulent accounts, most of which appeared to be based in Singapore and Japan, to circumvent the restriction.
In one 10-day stretch alone, Anthropic said Moonshot relayed nearly 300,000 customer requests, the vast majority of which were routed to Claude's Opus models.
Anthropic said the diverted exchanges were then used to train Moonshot's own software, with the company extracting Claude's reasoning transcripts specifically to serve as training data — a technique known in the industry as distillation.
DeepSeek was accused of a similar tactic, according to the report, routing live customer conversations through Claude rather than processing them through its own systems.
Reports also named Xiaomi as having engaged in comparable behaviour.
The alleged scheme has exposed sensitive information, including a user's query about an individual tracked across hundreds of CCTV cameras in Chengdu, and live credentials for a Russian government database.
Anthropic also said relayed traffic included material from a Chinese police case-management system.
Beyond Moonshot, DeepSeek and Alibaba, Anthropic's report named several other Chinese firms, including Zhipu, developer of the GLM models, and SenseTime, which were accused of similar extraction practices.
MiniMax was separately accused of operating a proxy service through an undisclosed shell company.
The allegations highlight the ongoing tensions between Anthropic and Chinese AI developers, and raise concerns about the security and integrity of AI systems.
The incident also underscores the need for greater transparency and accountability in the development and use of AI technology.
In the context of the rapidly evolving AI landscape, the allegations against Chinese AI labs are significant, as they suggest a willingness to engage in illicit activities to gain a competitive advantage.
The incident is likely to have implications for the development of AI policy and regulation, both in China and globally.
The allegations also raise questions about the potential consequences of illicit distillation, including the potential for AI systems to be compromised or manipulated.
As the use of AI technology becomes increasingly widespread, the need for robust security measures and transparent development practices will become increasingly important.
Frequently asked questions
What is illicit distillation in AI?
Illicit distillation refers to the practice of using a rival's more powerful model to train and improve a competitor's own product, often without permission or disclosure.
Which Chinese AI labs were accused of data theft?
Moonshot AI, DeepSeek, Alibaba, Zhipu, and SenseTime were named in Anthropic's report as having engaged in illicit distillation practices.