FEDERAL security agencies in the United States warned on 9 September 2026 of a coordinated foreign campaign targeting American frontier AI models. The joint advisory from CISA, NSA and the FBI states that China-based firms including DeepSeek, Moonshot AI, Alibaba Group, MiniMax, StepFun and Z[.]AI are conducting large-scale knowledge distillation, API scraping and model capability extraction from U.S. developers’ systems.
The activity aims to steal proprietary capabilities by querying major commercial APIs at scale, using transfer stations to bypass rate limits and resell access, and concealing traffic via bulk subscription purchases and metadata scrubbing. Targeted models cited include versions of Claude, GPT, Gemini and Grok, with billions of tokens extracted across millions of API sessions.
The report details how attackers inject prompts to elicit hidden reasoning traces from frontier models, training rival student models at minimal cost. It also notes that the operation could undermine fair technological competition and accelerate development cycles for the adversaries, with substantial claimed savings in training costs that authorities say are misleading once the data theft is considered.
In response, the agencies urge providers to implement rigorous behavioural monitoring, track subscription-to-usage ratios, and deploy defensive measures such as response degradation to suspected scraping, cross-ecosystem information sharing and differential privacy on API outputs. The advisory emphasises collaborative threat intelligence to detect and mitigate distributed scraping operations across cloud services and model platforms.