thehackernews.com 11 Sept 2026, 16:15 UTC

Anthropic Exposes Chinese AI Labs Harvesting Claude Training Data

CyberSIXT Evidence Panel Source marked as original reporting

ANTHROPIC has disclosed that it identified and disrupted industrial-scale illicit distillation attacks on Claude, originating from seven China-based labs including Alibaba, Moonshot, DeepSeek, Zhipu (Z[.]ai), and MiniMax. Knowledge distillation is a legitimate training method, but illicit distillation involves harvesting a model’s capabilities and reusing them to train replacement models without authorisation.

Anthropic reports that attackers used proxy services to route requests through networks of thousands of fake accounts, with stolen credentials and illegally obtained API keys, and in some cases exfiltrated user transcripts to train their own models.

Several campaigns are described as involving redirection of user exchanges to Claude to capture CoT (chain-of-thought) transcripts or to replay Claude’s reasoning for training purposes, with some exchanges reportedly including sensitive information from individuals, corporations, and state actors.

Anthropic lists seven campaigns with their scale and characteristics: GTG-16005, the largest to date, reportedly 151 million exchanges between May and July 2026 from over 3,500 fraudulent accounts targeting agentic tasks and software development; GTG-16002 (about 23 million exchanges) tied to Moonshot with roughly 300,000 customer requests relayed over 10 days via a proxy

network; GTG-16001 (over 12.1 million exchanges) linked to DeepSeek; GTG-16006 (over 3.4 million) tied to Zhipu via 273 fraudulent accounts; GTG-16008 (over 400,000) connected to Xiaomi; GTG-16012 involving third-party transcript purchases; and GTG-16003 linked to MiniMax establishing a proxy network to harvest exchanges for training.

Anthropic says the illicit market is fed by proxy networks that offer Claude access to users in unsupported regions and save transcripts for sale. In response, Anthropic has updated Claude to summarise internal reasoning before replying and introduced preserved thinking in Fable 5.1 to prevent prompts from altering system prompts or tools, alongside banning reseller accounts from unsupported regions. These measures accompany ongoing enforcement actions against abusing accounts and regions.

View full article

Article by CyberSIXT