Anthropic announced that it had identified “industrial-scale” campaigns aimed at illegally capabilities Claude. According to the company, three Chinese artificial intelligence labs are behind these operations: DeepSeek, Moonshot AI, and MiniMax.

Anthropic claims that these “distillation attacks” led to more than 16 million interactions with its LLM, via approximately 24,000 fraudulent accounts. These actions violated both its terms of service and geographical access restrictions , as the company’s services are not available in China due to legal and regulatory risks.
What is distillation and when does it become illegal?
Model distillation is a well-established practice in AI: a smaller or less complex model is trained on the responses of a more powerful one, in order to achieve comparable performance at a lower cost. It is a legitimate technique when applied internally by a company to its own models.
See also: Russian group exploits weak Fortinet firewalls via AI
However, when a competitor systematically leverages the outputs of a foreign model to “copy” its capabilities, without permission, the practice becomes a violation of intellectual and contractual rights. As Anthropic points out, models resulting from illegal distillation often do not maintain the same safeguards, increasing the risk of abuse.
National security and geopolitical implications
The company warns that removing or weakening security mechanisms can allow the development of systems that facilitate malicious activities: from aggressive cyber operations to disinformation campaigns and mass surveillance tools. In an environment of growing technological competition between the US and China, such allegations heighten concerns about the military and repressive exploitation of advanced AI models.
The discussion is not limited to commercial espionage. It touches on the core of technological dominance and the regulation of frontier models, which incorporate reasoning capabilities, agentic action, and automated decision-making.

How the capability export business was set up
According to Anthropic, the campaigns relied on extensive use of proxy services that resell access to advanced models. These infrastructures, described as “hydra clusters,” operated vast networks of fake accounts, distributing API traffic to avoid detection.
The company claims to have been able to attribute each campaign to a specific organization through analysis of request metadata, IP correlations, and infrastructure metrics. In one case, a single proxy network was handling over 20,000 fraudulent accounts simultaneously, mixing malicious and legitimate traffic.
See also: AI agents: The next big threat or the ultimate defense tool?
Claude's most advanced capabilities in the spotlight
DeepSeek reportedly focused on reasoning skills and generating answers to politically sensitive questions , conducting over 150,000 exchanges. Moonshot AI sought access to agentic reasoning, tooling, coding, and computer vision , exceeding 3.4 million requests. MiniMax reportedly recorded over 13 million interactions, with a focus on agentic coding .
According to the company, the volume and structure of the prompts did not indicate typical use, but rather systematic extraction of know-how.
The industry's response and countermeasures
To mitigate the threat, Anthropic has deployed specialized classifiers and behavioral fingerprinting to identify suspicious patterns in API traffic. It has also strengthened verification processes for educational accounts, security research programs, and start-ups, and implemented enhanced safeguards to reduce the effectiveness of model outputs for illicit distillation.
See also: Deepfake attacks and biometric spoofing
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The case comes shortly after a similar disclosure by Google Threat Intelligence Group, which said it had disrupted attacks targeting the Gemini. Google had clarified that such attacks do not directly affect end users, but rather the model providers and developers themselves.
The incident highlights a new reality: as AI models become more powerful, they become a strategic target. Protecting them is no longer just a technical issue, but a matter of business survival and national strategy.
