# Anthropic Ties 151 Million Claude Exchanges to an Alleged Alibaba Distillation Campaign

The September threat report names DeepSeek, Moonshot AI and MiniMax in smaller efforts, and puts model extraction alongside cyber operations and weapons research as a named harm category.

- Published: 2026-09-11T06:22:22.078Z
- Canonical: https://polylog.news/ai/2026-09-11/anthropic-ties-151-million-claude-exchanges-to-an-alleged-al
- Publisher: Polylog (AI desk)
- Section: geopolitics
- Sources: [Anthropic News](https://www.anthropic.com/threat-intelligence-report-september-2026), [TechCrunch](https://techcrunch.com/2026/09/10/anthropic-details-distillation-campaigns-from-alibaba-moonshot-ai-and-deepseek/), [CNBC](https://www.cnbc.com/2026/09/11/chinese-ai-labs-moonshot-deepseek-alibaba-anthropic.html), [CyberScoop](https://cyberscoop.com/anthropic-report-ai-enabled-cyber-attacks/)

Anthropic released its [September 2026 threat intelligence report](https://www.anthropic.com/threat-intelligence-report-september-2026) on Wednesday, covering misuse it says it detected and disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation.

The largest single case involves distillation. Anthropic says accounts it links to Alibaba conducted more than 151 million exchanges with Claude models between May and July 2026, spread across roughly 3,500 accounts that all used one fixed prompt designed to extract the model's chain of thought. Because the prompt was identical across accounts, Anthropic attributes the traffic to a single coordinated effort to build training data for the Qwen model family. [TechCrunch reports](https://techcrunch.com/2026/09/10/anthropic-details-distillation-campaigns-from-alibaba-moonshot-ai-and-deepseek/) that the Alibaba case was the largest of five campaigns Anthropic attributes to China-based AI companies, with smaller volumes tied to DeepSeek, Moonshot AI and MiniMax. [CNBC notes](https://www.cnbc.com/2026/09/11/chinese-ai-labs-moonshot-deepseek-alibaba-anthropic.html) that this follows a June accusation from Anthropic against Alibaba over a separate, earlier extraction effort.

What is confirmed here is limited. Anthropic controls the logs, the account data and the attribution method, and it is also the commercial party harmed if Qwen closes the capability gap using Claude's outputs. The companies Anthropic names have not, by its own account, admitted to the activity. A shared prompt appearing across thousands of accounts is reasonable evidence of coordination, but tying those accounts to a specific corporate owner is a judgment call that no outside party has yet reproduced. The exchange counts should be read as Anthropic's own measurement of its own service, not as an independently confirmed finding.

The report also describes a broader shift in who can carry out advanced operations. Anthropic argues that model assistance across reconnaissance, tooling, data processing, exploitation and exfiltration lets less skilled operators achieve results that previously required experienced teams, a framing [CyberScoop summarizes](https://cyberscoop.com/anthropic-report-ai-enabled-cyber-attacks/) as small actors running state-level campaigns. Anthropic also describes a new category of actors building software for firearms, missiles, armed drones and munitions, and says it blocked attempts at research relevant to biological weapons.

## What this means

Distillation is now a named security category rather than a licensing dispute, and that changes what frontier vendors do at the API layer. Expect tighter identity verification, limits on how much chain-of-thought output any account can extract, and refusal to serve regions or resellers a vendor cannot vet. That adds cost and delay for every legitimate high-volume API customer, and it gives US policymakers a concrete case for extending export controls from chips to model access itself. Alibaba carries the direct reputational exposure, and buyers evaluating Qwen's model weights now face a provenance question they cannot resolve on their own. Two outcomes matter most: either Alibaba or the other named labs produce a rebuttal that survives scrutiny, or the accusation becomes the accepted factual basis for US rules on who may access a frontier model.

## What to watch

- Whether Alibaba, DeepSeek, Moonshot AI or MiniMax publicly dispute the attribution, and whether any independent researcher can reproduce the account-clustering method Anthropic used.
- Whether US agencies cite the report in new restrictions on foreign access to American model APIs, which would extend export control from hardware to inference itself.
- Whether other frontier vendors publish comparable distillation telemetry, which would show this is an industry-wide pattern rather than one company's dispute.
