
The U.S. National Security Agency, Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency have accused six China-based artificial intelligence companies of conducting industrial-scale campaigns to extract capabilities from U.S. frontier AI models.
In a joint cybersecurity advisory released on September 8, 2026, the agencies said the campaigns involve billions of tokens and millions of exchanges with U.S. AI systems. They said the activity is intended to reproduce restricted capabilities while avoiding some of the research, computing and electricity costs required to develop frontier models independently.
The companies named are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The agencies said the activity has targeted models associated with Anthropic, OpenAI, Google and xAI.
The alleged campaigns use large numbers of accounts, proxy services, third-party access providers and distributed infrastructure to obtain model outputs at scale. Requests can be routed across multiple providers, making it harder for any one company to identify the full operation.
The agencies said operators can concentrate their queries on particular capabilities, including reasoning, coding, software engineering, agentic functions, tool use and specialized knowledge, rather than attempting to reproduce an entire model.
The full NSA, FBI and CISA advisory provides the agencies’ technical assessment and recommended defenses.
DeepSeek is described as one of the earliest companies identified in the activity, with alleged operations dating to at least late 2024. The agencies said its campaigns were used to generate training data for models including DeepSeek-R1 and DeepSeek-V3.
The advisory says DeepSeek targeted multiple Claude, Gemini, GPT and Grok models. It also says the company used prompts designed to elicit detailed reasoning from frontier systems.
The agencies said DeepSeek’s reported $5.6 million training cost for DeepSeek-V3 did not account for the alleged cost of data obtained through extensive distillation activity.
Moonshot AI is accused of beginning its campaign at least in mid-2025. The advisory says the company extracted data from Anthropic’s Claude Fable 5 for Kimi K3 and used GPT-4o data in developing Kimi K2.
Moonshot had previously denied U.S. allegations concerning its use of Anthropic’s models.
Reuters’ reporting on Moonshot AI provides additional context on the company and the earlier allegations.
Alibaba is accused of using the technique to improve its Qwen models in late 2025. The agencies identified Claude 4, Claude Sonnet and GPT-5 among the systems allegedly targeted.
The allegation follows an investigation disclosed by Anthropic in June. The company said Alibaba-linked operators had generated more than 28.8 million exchanges through almost 25,000 fraudulent accounts between April 22 and June 5, 2026.
Anthropic’s investigation into model-distillation attacks describes the company’s earlier findings.
MiniMax is accused of using extracted data to improve its M2 model. The advisory identifies Claude Code, Claude Sonnet 4, Claude Opus 4.5, Gemini 1, Gemini 2.5 Pro, Gemini 3 Pro and GPT-5 among the alleged targets.
The agencies also allege that MiniMax used prompt injection against Claude Code to make the system believe it was a MiniMax product.
StepFun is accused of conducting extraction activity between late 2025 and early 2026. The advisory lists several Claude and GPT models among its alleged targets and says the activity was aimed at improving coding and agentic functions in Step 4.
Z.AI is accused of extracting billions of tokens from GPT-5.5 and Claude Opus 4.8 by mid-2026. The agencies said the alleged objective was to develop chain-of-thought reasoning capabilities.
Across the operations, the advisory describes infrastructure capable of creating and managing large numbers of accounts, distributing requests among providers and concealing identifying information.
The agencies said some networks use intermediary services that they call “transfer stations.” These services allegedly resell access to frontier models and can help users bypass geographic restrictions, obscure their identities and avoid provider safeguards.
Anthropic previously described some large account networks as “hydra clusters” because blocked accounts could be replaced with others. The company said some proxy networks operated more than 20,000 fraudulent accounts simultaneously.
The campaigns can use highly repetitive and coordinated prompts. The advisory says operators can automatically assess model responses and adjust their activity when providers change or restrict access.
In one example, the agencies said MiniMax redirected traffic to a newly released Claude model within 24 hours of its launch.
The advisory identifies four techniques as novel tactics: regional restriction and subscription exploitation, centralized request routing, automated metadata sanitization, and systematic quota and cost optimization.
The agencies recommend stronger identity verification, API rate limiting, progressive throttling, production-access controls and improved monitoring of account and network behavior.
They also recommend that providers consider reducing the value of responses delivered to users identified with high confidence as conducting malicious distillation. Possible measures include reducing reasoning depth, changing reasoning approaches or using a less capable model.
The agencies caution that providers should avoid revealing such defensive changes to suspected operators because doing so could expose detection methods.
They are also calling for greater information sharing among AI companies, cloud providers, API aggregators and infrastructure companies. Indicators such as IP addresses, domains, proxy information, account behavior and query patterns can help providers connect activity that might otherwise appear unrelated.
The U.S. advisory follows a series of disclosures from major AI companies.
In February, Anthropic said DeepSeek, Moonshot AI and MiniMax had generated more than 16 million exchanges with Claude through approximately 24,000 fraudulent accounts.
OpenAI separately told Congress that it had observed activity consistent with DeepSeek attempting to distill frontier models through increasingly obfuscated methods.
OpenAI’s submission to Congress provides its account of the earlier activity.
Google has also reported model-extraction campaigns. Its threat-intelligence team has described attackers using legitimate API access to systematically probe advanced models and transfer knowledge into other systems.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.



