Find notable cyber news and cases, enriched with sources, timelines, and signals.

China-based AI companies' knowledge-distillation campaign against U.S. frontier AI models

Campaign
First reported
Last updated
Happening score
H score 23
3 unique sources, 4 articles

Summary

Hide ▲

Anthropic said it disrupted industrial-scale illicit distillation against Claude by seven China-based labs, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), MiniMax, Xiaomi, and SenseTime. The campaign used proxy services, fake or stolen credit cards, login credentials, and API keys to harvest model outputs and reuse them as training data, including Claude Opus 4.6 and 4.7 reasoning and tool-use traces. Anthropic said it has detected six illicit distillation campaigns since February 2026 and is responding with summarized internal reasoning and Fable 5.1 preserved thinking. The broader Happening remains a China-based AI companies' knowledge-distillation campaign against U.S. frontier AI models that has been described by CISA, NSA, and FBI as extracting billions of tokens across millions of exchanges and requests since at least late 2024.

Related Happenings

China-based AI labs illicit Claude distillation campaign

Campaign
H score27 First: 11.09.2026 19:15 Last: 11.09.2026 19:15 Sources 1

How related: Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax.

About this happening: A coordinated industrial-scale distillation campaign against Claude is extracting reasoning and tool-use outputs to train competing models, increasing the risk of unauthor...

UNC6780 open-source software supply chain campaign targeting AI environments

Campaign
H score45 First: 08.09.2026 15:02 Last: 08.09.2026 15:02 Sources 1

About this happening: UNC6780 is running a large-scale open-source supply-chain campaign that targets AI-assisted coding tools and software dependencies across PyPI, npm, and Docker Hub...

U.S. frontier AI companies knowledge distillation mitigation advisory

Advisory/Mitigation
H score31 First: 08.09.2026 15:00 Last: 08.09.2026 15:00 Sources 1

How related: The advisory recommends that AI companies improve behavioral and infrastructure-level detection, modify responses when distillation operations are suspected, and share intelligence about these campaigns with all stakeholders.

About this happening: CISA, NSA, and FBI issued a joint advisory for U.S. frontier AI companies, warning that knowledge distillation campaigns can strip proprietary model capabiliti...

CISA, NSA, and FBI joint advisory on AI model distillation

Public Sector Action
H score25 First: 08.09.2026 15:00 Last: 08.09.2026 15:00 Sources 1

How related: a bulletin released by the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI).

About this happening: CISA, NSA, and FBI released a joint cybersecurity advisory warning U.S. AI companies about knowledge distillation campaigns targeting frontier models. The advi...

Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure

Campaign
H score17 First: 19.08.2026 20:50 Last: 19.08.2026 20:50 Sources 1

About this happening: The U.S. government warned of an active threat using AI-generated exploit scripts against Siemens S7 Series PLCs in U.S. critical infrastructure. The campaign...

Timeline

  1. 08.09.2026 15:00 5 articles · 13d ago

    CISA, NSA, and FBI warn of China-based AI companies extracting U.S. frontier AI model outputs

    Initial Disclosure

    CISA, NSA, and FBI released a joint cybersecurity advisory warning that China-based AI companies including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have used knowledge distillation against U.S. frontier AI models such as Claude, GPT, Gemini, and Grok, with activity described as extracting billions of tokens across millions of exchanges and requests since at least late 2024.

    Show sources