Anthropic Says Seven China-Based Labs Ran Industrial-Scale Claude Distillation

Anthropic’s September 2026 multi-lab threat report details illicit Claude distillation it says it disrupted across seven China-based labs — a broader peg than Writeble’s June 28 Alibaba-only piece — with TechCrunch and The Hacker News relaying Anthropic-reported volumes and caveats.

Anthropic September 2026 threat report illicit distillation
Anthropic September 2026 threat report illicit distillation

Anthropic’s September 2026 multi-lab threat intelligence report — distinct from Writeble’s June 28 Alibaba-only distillation brief — covers misuse Anthropic says it disrupted between December 2025 and August 2026 across seven harm areas, including illicit distillation. TechCrunch (September 10) and The Hacker News (September 11) focus on that distillation chapter, relaying Anthropic’s claim that seven China-based labs ran industrial-scale campaigns to extract Claude capabilities for training.

According to The Hacker News’ summary of the report, Anthropic named seven China-based labs in the distillation narrative, including clusters linked to Alibaba, Moonshot, DeepSeek, Z.ai/Zhipu, Xiaomi, SenseTime, and MiniMax. The coverage cites enormous exchange volumes Anthropic attributes to fraudulent account fleets—for example Alibaba-linked GTG-16005 at about 151 million exchanges from May to July 2026, Moonshot-linked GTG-16002 at about 23 million plus roughly 300,000 customer requests relayed in 10 days, and DeepSeek-linked GTG-16001 above 12.1 million exchanges over 14 days in July. TechCrunch similarly frames about 200 million exchanges across five campaigns and describes chain-of-thought elicitation tricks used to pull richer training signal.

Privacy and mitigations

Secondary coverage also reports Anthropic’s allegation that some Moonshot and DeepSeek activity silently forwarded customer requests into Claude and reused exchanges for training—an angle that goes beyond terms-of-service scraping into end-user privacy. Anthropic says it disrupted the activity, banned accounts, and tightened safeguards such as summarized or protected thinking outputs. Treat all volume and attribution figures as Anthropic-reported claims relayed by approved secondaries; this brief does not reproduce exploit methods.

Primary sources are Anthropic’s September 2026 threat intelligence report, TechCrunch’s September 10 distillation story, and The Hacker News’ September 11 summary.

Topics
  • #Cyber Security
  • #AI Agents
  • #Products
Raj M

Author

Raj M

Contributor

AI Systems Architect is a seasoned technology leader with over 15 years of experience in the IT industry working with Fortune 500 companies. With a solid foundation in multi-agent systems, open-source LLM infrastructure, and enterprise deployment, he excels at building scalable production-grade AI platforms.