Operators affiliated with Alibaba ran the biggest campaign of AI capability theft that Anthropic has recorded, peaking at almost 3 million exchanges a day from more than 3,500 fraudulent accounts.
The disclosure comes in Anthropic's September 2026 threat report, which names seven China-based laboratories caught extracting the reasoning of Claude models without authorisation.
Between May and July this year, Anthropic observed more than 151 million exchanges attributable to Alibaba.
The pipeline injected a fixed instruction into every request that forced Claude to write out its reasoning in inline text tags before answering.
Those transcripts were converted into supervised fine-tuning data and used to train the Qwen 3.5, 3.6 and 3.7 models.
Alibaba also used Claude to build reinforcement learning environments and to advance its own model architecture research.
Access came through roughly 5,000 fraudulent accounts using residential proxies, disposable email addresses and virtual card payments, with a second pool held in reserve for when the first was banned.
Kimi users were served Claude
Moonshot AI, which makes the Kimi family of models, silently forwarded customer requests to Claude and displayed Claude's answers as its own.
Over one ten-day window it relayed almost 300,000 customer requests, most of them to Opus, through a network of 5,380 fraudulent accounts registered largely in Singapore and Japan.
Total observed volume attributable to Moonshot between May and July was more than 23 million exchanges.
DeepSeek used the same technique, tagging users who arrived through coding harnesses such as Claude Code and OpenCode, then quietly rerouting them to Claude Opus.
Over fourteen days in July, DeepSeek accounted for more than 12.1 million exchanges.
Both firms defeated Anthropic's "thinking signature" control by saving the signature, opening a fresh session and coaxing the model into converting it back into a full reasoning trace.
Queries leaving the platform
The rerouted sessions swept up sensitive customer data from users who had no idea their queries were leaving the platform they had chosen.
One user assessed as affiliated with the People's Liberation Army fed CCTV archive footage of a single tracked individual, drawn from hundreds of cameras in Chengdu, into what they believed was Kimi.
DeepSeek relayed requests exposing live credentials for a Russian government database, and others from engineers building a case management system for a municipal Public Security Bureau in China.
Zhipu, branded outside China as Z.ai, rotated 273 accounts against Opus 4.8 and pushed 770,609 exchanges through a reasoning-cleaning pipeline in ten days.
It abandoned attempts to distil the cyber capabilities of Anthropic's Fable model after the safeguards degraded its attacks, switching to Opus 4.6 instead.
Xiaomi replayed its own users' coding sessions through Claude across more than 1,500 proxy accounts, while SenseTime bought harvested transcripts from third-party vendors and MiniMax built a proxy network through an undisclosed shell company.
Anthropic has responded with summarised reasoning, encrypted "preserved thinking" in Fable 5.1 and identity verification for suspect accounts.