Anthropic names Chinese labs in AI distillation report
Anthropic's September 2026 threat report says DeepSeek and Moonshot routed live customer requests through Claude. Know who actually serves your tokens.
Anthropic published its threat intelligence report on September 10, and one finding should change how you buy inference. Two Chinese labs, the report says, quietly forwarded their own customers' requests to Claude and handed back Claude's answers as their own. If you were a customer of those labs, your prompts went to a vendor you never signed a contract with. That is the AI distillation story worth your attention, and it is a supply-chain problem, not a geopolitics problem.
What actually happened
The report covers activity Anthropic disrupted between December 2025 and August 2026 across seven harm categories, including a category Anthropic calls illicit distillation: harvesting a frontier model's outputs to train a competitor.
Per CyberScoop's coverage, seven China-based labs ran distillation campaigns starting in February. Operators linked to Alibaba ran the largest, peaking at nearly 3 million exchanges per day from more than 3,500 fraudulent accounts. DeepSeek and Moonshot AI went further: the report says they silently forwarded customer requests to Claude and returned its responses, behavior Anthropic describes as likely inconsistent with privacy laws and with those labs' own terms of service.
The same report documents how fast credential theft now moves. CyberScoop cites ShinyHunters affiliates dumping 2,100 cloud access tokens across 40 corporate tenants in 34 hours, and one intrusion going from a single stolen developer token to full control of a cloud environment in roughly three hours, with AI agents doing nearly all the work.
Why your token supply chain matters for your business
Most small teams pick a model provider on price per million tokens. That number tells you nothing about who runs the GPU. A reseller, a proxy, or a "compatible endpoint" can sit between you and the model, and the cheapest tier is exactly where that happens. When it does, your customer data crossed a border and a contract boundary that nobody in your vendor chain will admit to.
Ask your provider one question in writing: do you serve this model on your own infrastructure, or do you route it? Get the answer in the contract, next to data residency and retention. If a vendor will not answer, that is the answer.
Then treat API keys like the cash they are. Scope each key to one service, rotate on a schedule, keep them out of repos and images, and alert on billing anomalies — a key that starts costing money at 3 a.m. is the cheapest breach signal you will ever get. Three hours from stolen token to owned cloud means your detection window is a shift, not a quarter.
Key takeaways
- Anthropic's September 10 threat report names seven China-based labs running distillation campaigns since February
- Alibaba-linked operators peaked at nearly 3 million exchanges per day from 3,500+ fraudulent accounts
- DeepSeek and Moonshot AI allegedly forwarded live customer requests to Claude and returned its responses
- Cheap inference tiers are where routing and reselling hide - ask who runs the hardware, in writing
- The same report shows one stolen developer token reaching full cloud control in about three hours
- Scope keys per service, rotate them, keep them out of repos, and alert on spend anomalies
We build AI systems where you know what every call touches. Model routing behind an interface you control, keys scoped per service, spend and egress you can actually see. See how we build AI automation, or send us your current vendor stack and we will tell you what leaves the building.
Sources: Anthropic: Countering misuse of AI, September 2026, CyberScoop.
- #anthropic
- #vendor-risk
- #ai-security
- #api-keys
- #model-distillation
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
California's Adam Raine Act: chatbot rules you must build
SB 1119 makes minor time limits, crisis resources, self-harm alerts and safety plans product requirements for any chatbot California kids can reach.
Read itZscaler Agentic SOC: the agent now pulls the trigger
Zscaler's Agentic SOC uses Anthropic and OpenAI models to triage, investigate, and contain threats automatically. The line that moved is autonomous remediation.
Read it