Anthropic alleges 151-million-query distillation attack on Claude
It names seven China-based labs and a Russia-linked group that allegedly built malware which rewrote itself whenever defences caught it.

Anthropic says it recorded more than 151 million exchanges it attributes to Alibaba over three months — peaking at nearly three million a day from more than 3,500 accounts it describes as fraudulent — in what it calls the largest illicit distillation attack it has seen.
The allegation sits in the company's latest threat intelligence report, which says it disrupted attacks from seven China-based labs over eight months and separately shut down a suspected Russia-linked espionage campaign run against Ukrainian government, military and diplomatic targets.
What distillation is, and why it is worth 151 million queries
Distillation means training a smaller, cheaper model using the output of a larger, more expensive one. Done with permission it is ordinary engineering. Done without, it is a way of acquiring the expensive part of a competitor's product — the trained behaviour — without paying to train it.
Anthropic alleges that operators it links to Alibaba ran bulk queries against Claude between May and July 2026 with the aim of extracting its capabilities and using them to improve Alibaba's Qwen models.
The scale is the striking part. Three million exchanges a day is not a researcher probing a rival's system; it is an industrial pipeline.
Anthropic named Alibaba, Moonshot, DeepSeek and Xiaomi among the seven labs.
A different method, and a sharper problem
Two of those companies are accused of something other than bulk querying, and it raises a question that goes beyond commercial rivalry.
Rather than running mass queries, Moonshot — which makes the Kimi chatbot — and DeepSeek allegedly routed live customer conversations through Claude and used its responses as training data, according to Anthropic. Those conversations sometimes included sensitive information.
If that is accurate, the people affected are not the AI companies. They are the users of those chatbots, whose conversations were allegedly passed to a third-party model without any indication that this was happening.
These are allegations made by a competitor about named companies, published in that competitor's own report. Anthropic has not published the underlying evidence, and the firms it names have not responded publicly.
The Russian operation
The espionage findings are separate and more conventional in shape, if not in method.
A hacking group whose tradecraft Anthropic says is consistent with the Russia-based actor Midnight Blizzard allegedly ran phishing, hotel Wi-Fi hijacking and WhatsApp account-takeover operations against Ukrainian government, military and diplomatic targets — using AI at nearly every stage.
The most technically notable element is a system the group allegedly built to defeat security software automatically: it detected when its malware had been flagged by defences, then rewrote the code until it evaded detection again.
That is a feedback loop with no human in it. Malware that rewrites itself in response to being caught changes the economics of defence, because the defender's success becomes the input that produces the next variant.
The claim underneath all of it
Anthropic's broader argument is about how these operations were run, not just what they targeted.
Cybercriminals and state-backed hackers are increasingly using AI not merely to assist with tasks but to orchestrate and execute large parts of attacks, the company said, with humans often acting as overseers rather than hands-on operators.
"A majority of the operations ... were enabled by AI via direct execution or orchestration," Anthropic said. "The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing" tasks.
Multi-agent frameworks mean several model instances working together, passing results between them, with a person setting the objective rather than performing the steps. It is the same architecture legitimate companies are deploying for legitimate automation — which is precisely why it is available to everyone else.
What this does not settle
A vendor report is a partial view by construction. Anthropic can describe what it detected on its own systems; it cannot describe what it missed, and it has a commercial interest in how these findings are read.
The distillation allegations in particular are a competitor's account of rivals' conduct. Attribution in this field rests on behavioural patterns and account activity rather than on confessions, and Anthropic has described its confidence in terms of consistency with known actors rather than certainty.
What is not in dispute is the direction. The company says it has shared intelligence with authorities and industry partners where appropriate, and has folded the findings into its own detection systems. The activity it describes — bulk extraction of model capabilities, and state-linked operations where the AI does the work — was happening at scale for eight months before anyone outside the company knew.



