Kimi and DeepSeek users got Claude answers, Anthropic says
2026-09-11 · 4 min read
On September 10, Anthropic published what it called on X "our most detailed threat intelligence report to date," in a post from @AnthropicAI that ran through cyberattacks, influence operations, surveillance, biology, and weapons. Most of the coverage went to the drone swarms and the bioweapons attempts. The section that matters if you buy AI from a vendor is the one on distillation, and it is not really about model training.
The headline numbers are large. Anthropic says seven China-based labs ran campaigns to extract Claude's capabilities and feed them into competing models. Alibaba is the biggest: more than 151 million exchanges between May and July of this year, peaking near 3 million a day, spread across more than 3,500 accounts Anthropic calls fraudulent, with the harvested transcripts used to train Qwen. These are Anthropic's findings from Anthropic's own investigation. No court or regulator has tested them, and the named companies have said nothing publicly.
Two apps, one borrowed brain
Anthropic's sharper claim is that Moonshot AI, which makes Kimi, and DeepSeek did more than query Claude in bulk. It says they took their own users' live conversations, routed them to Claude, and displayed Claude's answers inside their own products as if their own models had written them.
The scale, per the report: Moonshot relayed close to 300,000 customer requests over a ten-day stretch, most of it to Opus, through a network of 5,380 accounts registered mostly in Singapore and Japan. DeepSeek was more selective, flipping flagged sessions over to Opus, which Anthropic ties to 12.1 million exchanges in a fourteen-day window in July.
Set the geopolitics aside and picture the person typing. Someone opened a Chinese AI app, pasted in internal source code or a customer record, and read a good answer with that app's name on it. The prompt had taken a round trip through a US company's servers. Anthropic says the material swept up this way included corporate source code, government credentials, and surveillance footage analysis.
Nobody misled those users about quality. The answers were good, they just came from a model the customer never chose and a company the customer never agreed to send anything to.
Why the number jumped
Anthropic has said a version of this before. An earlier post from the same account announced "industrial-scale distillation attacks on our models by DeepSeek, Moonshot AI, and MiniMax," counting 24,000 fraudulent accounts and over 16 million exchanges (@AnthropicAI). This report totals close to 200 million.
Some of that jump is real growth and some of it is better detection. Anthropic has also changed the product in response: Claude now summarizes its internal reasoning instead of handing it over raw, and it encrypts preserved thinking so a caller cannot rewrite the context behind a reply. Both changes make Claude harder to strip-mine. They also leave everyone else with less visibility into how it reached a given answer, and that cost lands on ordinary customers rather than on the labs doing the copying.
The question this puts on your desk
Almost no small business buys a model. You buy software with a model inside it: a scheduler with an AI assistant, a CRM that drafts follow-ups, an answering service, an intake bot somebody built for you. In nearly every one of those, the vendor picks which model answers, and can change that pick on a Tuesday without telling you.
That arrangement is normal, and most of the time it causes nobody any trouble. It is also the arrangement this report describes going wrong. Four questions are worth putting to whoever sells you AI, in writing:
- Which model handles our data, and who is the provider of record behind it?
- Where does it run, what is retained, and for how long?
- Do you notify customers when you swap models or add a subprocessor?
- Does anything we promise our own clients depend on an answer you cannot give?
A vendor with a clean answer will produce it in a day. If nobody there can tell you which model is answering, then nobody there knows where your data goes either, and the marketing page does not change that.
None of this is a reason to stay off AI tools. The security story here is about labs stealing from labs, and the users caught in the middle were collateral. It is a reason to know what is under the hood of the software you already pay for, especially the pieces that touch client records.
If you want a straight read on where AI actually belongs in your operation before you sign anything, New Face Design runs a free process audit: we walk your real workflow, put hours and dollars against each handoff, and tell you which pieces are worth automating and which should be left alone.