Alibaba (BABA) ran 151 million Claude exchanges on fake accounts, Anthropic says

Chart of exchanges Anthropic attributes to seven Chinese AI labs, led by Alibaba at 151 million

Key points

  • Anthropic names seven China-based AI labs
  • Anthropic attributes 151 million Claude exchanges to Alibaba
  • Anthropic says Moonshot and DeepSeek rerouted customer requests
  • US agencies issued a distillation advisory Tuesday

Anthropic said operators affiliated with Alibaba (BABA) ran the largest model-copying campaign it has ever measured against its Claude models. The company observed more than 151 million exchanges between May and July, according to a threat intelligence report published Thursday. Six other labs based in China are named alongside it.

The practice is called distillation. One lab feeds another model's outputs into its own training pipeline, which is an ordinary training method when the model's owner agrees to it. Anthropic defines the illicit version as "an industrial-scale, covert campaign to extract a model's capabilities and replicate them in another model without authorization." The report covers activity the company says it detected and disrupted between December 2025 and August 2026.

Anthropic describes a network of proxy services and resold training data behind the campaigns. The labs routed requests through services the report calls transfer stations, which open thousands of accounts using false identities, fake or stolen credit cards, and stolen API keys. Some of those proxy operators also save the exchanges and resell them. SenseTime's pipeline included Claude transcripts bought from third-party data vendors, and MiniMax built its own proxy service through a shell company that sells access to Anthropic and OpenAI models and to no Chinese models at all, including its own.

What Anthropic says each lab did

LabWhat the report describesScale Anthropic measured
Alibaba (BABA)Forced Claude to write out its reasoning, trained Qwen on the transcripts151M+ exchanges, May to July
Moonshot AIServed Claude's answers to Kimi customers and saved the exchanges23M+ exchanges, May to July
DeepSeekRelayed coding-tool users' requests to Claude Opus without telling them12.1M+ exchanges, 14 days in July
ZhipuRotated 273 fraudulent accounts to pull and clean reasoning traces3.4M+ exchanges, 17 days in June and July
XiaomiReplayed sessions from its own MiMo models through Claude400,000+ exchanges, 20 days in March and April
SenseTimeBought Claude transcripts from third-party data vendorsNot disclosed
MiniMaxRan a proxy network through an undisclosed shell companyNot disclosed

Alibaba's pipeline injected a fixed prompt into each request to force Claude to write out its chain of thought before giving a final answer, the report says, and those transcripts became supervised fine-tuning data. Traffic peaked at nearly 3 million exchanges a day from more than 3,500 fraudulent accounts. Anthropic banned a first pool of nearly 5,000 accounts, and the traffic moved to a second pool, some of whose accounts were also carrying requests from DeepSeek and Xiaomi. Alibaba used Claude for its own research as well, building reinforcement learning environments and working on model architecture. Alibaba is also an investor in Moonshot, one of the other labs the report names. Its annual report filed in May 2026 discloses an approximately 36% equity interest bought for about $800 million during the fiscal year ended March 31, 2024.

Customer data traveled with the requests

Moonshot AI, which makes the Kimi chatbot, forwarded customer requests to Claude and showed users the answers it returned. Over one 10-day stretch the company relayed almost 300,000 requests through 5,380 accounts, most of which appeared to be in Singapore and Japan. Anthropic says it does not know whether Moonshot told those customers. DeepSeek ran a similar setup, checking inbound traffic for the signatures of coding tools such as Claude Code and OpenCode, then forwarding those users' requests to Claude Opus.

Those relayed sessions carried real data. The requests contained names, email addresses, company data and other sensitive information from hundreds of end users in at least a dozen languages. The report says the practices are "likely inconsistent with privacy laws and the labs' own terms of service." Anthropic's examples include an engineer at a large Chinese state-owned enterprise who exposed internal code and live credentials through Kimi, and an IT operator handling data for an agency tied to Russia's defense ministry whose requests DeepSeek passed to Claude.

China's foreign ministry said it was not aware of the report and opposes distortion of facts and smears against the country, Reuters reported. Alibaba, Moonshot, DeepSeek and Xiaomi did not immediately respond to requests for comment from CNBC.

The findings land while Washington is already moving on the issue. On Tuesday, the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI released an advisory warning that China-based AI companies are distilling US models. It names DeepSeek, Moonshot, Alibaba, MiniMax, StepFun and Z.ai. One of its recommendations is that US labs make targeted changes to the responses they return to high-confidence distillation requests, such as answering with a less sophisticated model. Those changes should vary from request to request, so the degradation is hard to evaluate. The advisory also says not to tell a suspected account that it has been switched to a downgraded model.

Not everyone wants a crackdown. Y Combinator chief executive Garry Tan told CNBC he would "do nothing" about distillation. "We could argue that there should be an American distillation regime," he said, adding that regulators should focus on keeping a balance between open-weight and frontier models.

Alibaba's US-listed shares traded at $109.45 shortly before noon ET on Friday, up about 0.8% from Thursday's close of $108.56. The stock is about 43% below its 52-week high of $192.67, set on October 2, 2025.

Frequently asked questions

What did Anthropic accuse Alibaba (BABA) of doing?

In a threat intelligence report published on September 10, 2026, Anthropic said operators affiliated with Alibaba ran the largest distillation attack it has ever measured against its Claude models, observing more than 151 million exchanges between May and July 2026. The report says a fixed prompt forced Claude to write out its reasoning, and those transcripts were turned into fine-tuning data used to train Qwen 3.5, 3.6 and 3.7. Alibaba did not immediately respond to requests for comment from CNBC.

What is illicit distillation?

Distillation trains one AI model on the outputs of another, and it is an ordinary training method when the model's owner agrees to it. Anthropic defines the illicit version as an industrial-scale, covert campaign to extract a model's capabilities and replicate them in another model without authorization, typically enabled by networks of fake accounts created with stolen credit cards, login credentials and API keys.

Which AI labs did Anthropic name in the report?

Seven labs based in China: Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax. The report covers activity Anthropic says it detected and disrupted between December 2025 and August 2026. Separately, the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI issued a joint advisory on September 8, 2026 naming DeepSeek, Moonshot, Alibaba, MiniMax, StepFun and Z.ai.

Did Moonshot and DeepSeek send their customers' data to Claude?

Anthropic says both companies relayed their own users' requests to Claude without telling them. Moonshot passed almost 300,000 customer requests through 5,380 accounts over one 10-day stretch, and DeepSeek relayed more than 12.1 million exchanges over 14 days in July 2026. According to the report those sessions contained names, email addresses and company data from hundreds of end users in at least a dozen languages, and Anthropic said the practices are likely inconsistent with privacy laws and the labs' own terms of service.

More coverage

Dennis Singleton
Dennis Singleton

Dennis Singleton has spent years following the markets, but what keeps his attention is how AI is built. He writes about the companies behind the technology, from semiconductor designers and advanced packaging to photonics, memory, networking, and the hardware powering modern AI. His approach starts with filings, earnings, and industry research, then translates the important details into clear, straightforward analysis without unnecessary hype.