• Home
  • Alibaba, DeepSeek, Moonshot used Claude…

Alibaba, DeepSeek, Moonshot used Claude to train AI models – Anthropic

Anthropic said it had detected and disrupted large-scale efforts by China-based AI companies, including Alibaba, Moonshot and DeepSeek, to train their models using Claude.

The United States AI company said in a threat intelligence report released on Thursday that the firms engaged in what it called “illicit distillation”.

The process involves using outputs from a more advanced AI model to train another system and replicate some of its capabilities without authorisation.

“Some of these exchanges included sensitive information, including from individual users, major multinational companies, and state-affiliated actors … These practices are likely inconsistent with privacy laws and the labs’ own terms of service,” according to the report.

Anthropic said operators linked to Alibaba used outputs from Claude to help train its Qwen models, while Moonshot redirected some Kimi user requests to Claude and used some of the resulting interactions to train its own AI models.

The Alibaba operation was the largest model-distillation campaign Anthropic said it had recorded, involving more than 151 million exchanges with Claude between May and July.

The activity peaked at nearly three million exchanges a day across more than 3,500 fraudulent accounts, according to the report. Anthropic said Alibaba also used Claude for broader AI research, including reinforcement learning and model architecture.

Anthropic also reported activity involving Moonshot AI, the Beijing-based developer of the Kimi family of AI models.

According to the report, Moonshot secretly routed some customer requests submitted to Kimi to Claude and displayed Claude’s responses to users, who were unaware that they were interacting with Anthropic’s model rather than a Kimi system.

During one 10-day period, Moonshot forwarded nearly 300,000 customer requests to Anthropic, with the vast majority directed to Claude Opus models. Anthropic said the requests were channelled through a network of 5,380 accounts it identified as fraudulent, most of which appeared to be based in Singapore and Japan.

The report said Moonshot retained at least some of the exchanges and extracted Claude’s reasoning transcripts for use as training data for its own models.

Anthropic attributed more than 23 million exchanges to Moonshot between May and July.

Anthropic said it was unclear whether Moonshot had informed its customers that their requests were being sent to Anthropic.

The company said DeepSeek, which gained prominence last year for its AI capabilities and relatively low costs, also used tactics similar to those employed by Moonshot by transferring user exchanges to Claude without notifying customers.

Anthropic said it detected more than 12 million distillation attacks linked to DeepSeek over a 14-day period in July 2026.

The report, which identified several other major Chinese AI companies, covered activity that Anthropic said it disrupted between December 2025 and August 2026. The activities spanned seven areas, including cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and AI model distillation.