What Anthropic counted

Operators affiliated with Alibaba sent 151 million exchanges to Claude between May and July 2026 to produce training material for the Qwen family of models, Anthropic says, in what it calls the largest distillation campaign it has measured. The figure comes from Anthropic’s September 2026 threat intelligence report, published on 10 September, which covers December 2025 to August 2026 across seven categories of harm.

In total Anthropic observed nearly 200 million exchanges linked to distillation, attributed to five separate campaigns, TechCrunch reported. According to CyberScoop, the report ties the activity to seven labs based in China, including Alibaba, DeepSeek, Moonshot AI, Xiaomi and Zhipu.

Distillation means training one model on the outputs of another. With permission it is routine. What Anthropic describes is the unlicensed version: harvesting a competitor’s outputs through fraudulent accounts, against its terms of service, to build a rival model at a fraction of the cost.

How the Alibaba campaign was traced

The Alibaba-linked traffic peaked at nearly three million exchanges a day and was spread across more than 3,500 accounts that Anthropic describes as fraudulent. Spread that widely, the accounts could pass as unrelated users. What tied them together, according to TechCrunch, was a single fixed prompt designed to extract Claude’s chain of thought, the step-by-step working a model produces before it answers. One variant framed the request as a translation task, asking the model to translate its previous working memory.

That is why Anthropic attributes the traffic to one effort rather than to thousands of separate customers: the same prompt, repeated at that volume, works as a fingerprint.

Rows of computer monitors in an open-plan office
Anthropic says the Alibaba-linked traffic ran across more than 3,500 accounts it describes as fraudulent. Mikhail Nilov · pexels · Pexels License

Customers’ requests, passed on

The report describes a different pattern at two other labs. Moonshot and DeepSeek silently forwarded their own customers’ requests to Claude and returned its answers as their own, CyberScoop reported. If that is accurate, some users of those companies’ products were getting answers from Claude without being told.

Coverage of the report gives differing per-company figures for Moonshot and DeepSeek, so Aivio has left them out. None of the reporting we reviewed included a response from Alibaba, DeepSeek, Moonshot AI, Xiaomi or Zhipu.

This is not Anthropic’s first accounting. In February it said DeepSeek, Moonshot and MiniMax had generated more than 16 million interactions with Claude through about 24,000 fake accounts, NBC News reported. On 8 September the NSA, CISA and FBI issued a joint advisory accusing six China-based companies of industrial-scale distillation against US models. The new report puts a figure on a single company that is several times the February total.

The rest of the report

Distillation is one of seven categories. The others describe operations in which Claude was misused and which Anthropic says it disrupted.

  • A Yemen-linked group used Claude “in place of human software engineers” to write missile-guidance and flight-control software for a guided rocket and a long-range ballistic missile, Al Jazeera reported. The operators appeared to have conducted an unsuccessful test-fire, and Anthropic said it has no evidence the group fielded a working weapon.
  • A Russian-aligned espionage campaign bearing the hallmarks of Midnight Blizzard hit more than 20 government and defence organisations and stole more than 300,000 national identity records from a North African government agency.
  • Two Chinese undergraduates in Hunan province ran an automated exploit foundry that produced more than a dozen possible zero-day vulnerabilities in a single month.
  • Affiliates of the ShinyHunters crime collective dumped 2,100 cloud access tokens across 40 corporate tenants in 34 hours, according to CyberScoop.

Anthropic says it banned the accounts and organisations it identified, built automated detection for the behaviour it found and shared indicators with authorities and industry partners.

Exterior of a government office building
The same report describes espionage against more than 20 government and defence organisations. Nikolay Demirev · pexels · Pexels License

What to watch

The immediate question is whether Alibaba disputes the Qwen attribution, and whether the other companies named publish their own account of the traffic. The US advisory covered GPT, Gemini and Grok as well as Claude; comparable figures from OpenAI, Google or xAI would show whether 151 million is unusual or typical.