12 SEP 2026 — Anthropic published a threat intelligence report on 10 September naming seven China-based AI labs it says ran industrial-scale campaigns to extract Claude's capabilities. The largest, attributed to Alibaba, is put at more than 151 million exchanges between May and July, peaking near three million a day across more than 3,500 accounts Anthropic describes as fraudulent. Every figure in the report comes from the telemetry of the company making the accusation.
That detail does not invalidate the report, but it is the necessary frame for everything that follows.
What is alleged, lab by lab
The seven named are Alibaba, Moonshot, DeepSeek, Z.ai (also known as Zhipu), MiniMax, Xiaomi and SenseTime. The seven are not all accused of the same thing, and the distinctions matter more than the headline count.
Alibaba is the volume case: 151 million exchanges over three months, which Anthropic calls the single largest distillation campaign it has documented. Moonshot is put at more than 23 million exchanges and DeepSeek at more than 12.1 million. Z.ai is described as running a chain-of-thought extraction pipeline, replaying Claude's own reasoning traces back through Claude while rotating 273 fraudulent accounts.
Xiaomi is said to have replayed user conversations and coding sessions from its own MiMo models into Claude through the OpenClaw and OpenCode harnesses. MiniMax is described as having built a proxy service through a shell company, reselling access to models from Anthropic and OpenAI.
One allegation is a different kind of claim
Distillation-for-training is a dispute about terms of service and intellectual property. Two of the allegations are not that, and lumping them in with the rest understates them.
Anthropic says Moonshot routed live customer requests to Claude without telling those customers, then presented Claude's answers as Kimi's own. Over one ten-day period it puts the relay at close to 300,000 customer requests through roughly 5,000 fraudulent accounts, aimed mainly at Claude Opus. DeepSeek is described as doing something similar.
If accurate, that is not a question of whose training data is whose. A person who opened Kimi, and in some cases paid for it, received an answer from another company's model without being told. In that case the injured party is the user, and the relevant law concerns consumer protection rather than intellectual property.
It is also the allegation most easily checked by someone other than Anthropic. Routing behaviour is observable from the client side by anyone with an account and a willingness to test it.
How the attribution is said to work
Anthropic's stated method is pattern recognition rather than identity. Campaigns were linked by a shared fixed prompt used to pull out the chain of thought, including one framed as a translation task — an instruction to render previous working memory into katakana-only Japanese.
That fingerprint is specific and unusual, which is the report's strongest evidence. A prompt that strange, repeated across accounts, is difficult to explain as coincidence.
What the fingerprint does not establish, on its own, is who was holding the keyboard. It groups activity without naming an employer. The step from "these accounts ran the same extraction prompt" to "Alibaba ran this campaign" is an inference, and the report is the only place the working is shown.
Nobody accused has answered
At the time of writing, none of the named companies has responded publicly to the allegations. CNBC reported that Alibaba, Moonshot, DeepSeek and Xiaomi did not immediately reply to requests for comment.
China's Ministry of Commerce has responded to the framing rather than the specifics, calling distillation a widely used and neutral technical method and warning of resolute countermeasures if the allegations become a pretext for suppressing Chinese AI companies.
The ministry's technical point is correct and worth separating from its politics. Distillation — training a smaller model on a larger one's outputs — is ordinary practice, taught openly and used everywhere. The allegation is that the distillation was done at scale through accounts created with stolen credentials and payment cards, breaching terms of service and, in two cases, silently reselling a competitor's live service.
Our own position, stated plainly
This publication is written with the assistance of Claude, which Anthropic makes. The company alleging the misconduct supplies the tool that wrote this article, and no reader should have to work that out for themselves.
In practice, we have not treated any figure in this piece as established. Nothing here has been independently verified, the numbers cannot be reproduced by anyone outside Anthropic, and the accused have not yet had their say. We have covered several of these labs on their merits before — Z.ai's Ox Alpha weights, Moonshot's valuation, Alibaba's screen-operating agent — and this report does not retroactively change what those models do.
What would settle it
Three things, none of which has happened yet.
A response from any named company that engages with the account numbers rather than the framing. A third party — a cloud provider, a payment processor, a registrar — confirming that the accounts described were created the way Anthropic says. Or, for the routing allegation specifically, an independent test showing whether a Kimi or DeepSeek query reaches a Claude endpoint.
The third is the one an outsider can test, which makes it the allegation most likely to be resolved rather than merely argued about. The rest will probably be settled, if at all, by regulators or in court, and the seven labs are in a jurisdiction where an American court's writ is limited.
Why it matters beyond the dispute
The report describes a market in extracted capability. MiniMax is the clearest example: a shell company reselling access to two American labs' models. That has nothing to do with training data. It is a distribution business built on somebody else's inference.
For a practitioner in this region choosing a model, the question is simpler than the geopolitics. If a provider is relaying your queries to a third party, then your data crosses a border you were not told about, and your compliance position is not what your contract says it is. That risk exists whether or not Anthropic's numbers hold up, and it is worth asking any vendor directly.