On 10 September 2026, Anthropic published Detecting and countering misuse of AI: September 2026. The report covers activity they say they disrupted between December 2025 and August 2026, across seven harm areas. One of those areas is illicit distillation. This note restates that section. The counts and the company names are Anthropic's.

Opening of Anthropic's September 2026 threat report, titled Detecting and countering misuse of AI.
From Anthropic's report page. The distillation cases sit further down, behind a Read more control.

Distillation itself, they write, is a legitimate training method: a larger teacher generates answers, a smaller student is trained on those exchanges. They define illicit distillation as an industrial-scale, covert campaign to extract a model's capabilities and replicate them without authorization. Since a February 2026 disclosure, they write, they identified and disrupted additional distillation attacks against Claude from seven labs based in China.

Operators affiliated with Alibaba, they write, ran the largest distillation attack they have measured. A fixed prompt forced Claude to write out chain-of-thought traces from Opus 4.6 and 4.7. Those traces were saved for supervised fine-tuning of Qwen 3.5, 3.6, and 3.7. Between May and July 2026 they counted over 151 million exchanges, peaking at nearly 3 million a day from more than 3,500 fraudulent accounts.

Moonshot AI, they write, silently forwarded Kimi customer requests to Claude and showed Claude's replies as Kimi's. In one ten-day window they counted almost 300,000 such requests, mostly to Opus, through 5,380 fraudulent accounts that looked as if they sat in Singapore and Japan. Between May and July they attribute over 23 million exchanges to Moonshot. They say some of the forwarded traffic included sensitive customer data, and that they do not know whether Moonshot told those customers.

DeepSeek used a similar silent relay, they write, and the same cross-session method for extracting reasoning traces. They say it tagged users coming through Claude Code, the Claude Agent SDK, or OpenCode, and sent selected requests to Opus. Over 14 days in July they counted over 12.1 million exchanges.

Zhipu, branded outside China as Z.ai, they write, ran a chain-of-thought cleaner against Claude for its GLM models. Over 17 days in June and July they attribute over 3.4 million exchanges. They say Zhipu first tried to distill cyber capabilities from Fable, then switched to Opus 4.6 and another US lab's model after Fable's safeguards held. The report's opening states that none of the misuse cases involved Fable or Mythos except that one illicit distillation case.

They attribute a Xiaomi campaign that saved MiMo user conversations and coding sessions and replayed them through Claude for supervised fine-tuning and reinforcement-learning data. They did not find Xiaomi serving Claude's replies back to those users. Over 20 days in March and April they counted more than 400,000 requests across more than 1,500 accounts. They suggest a MiMo-V2-Pro free trial, later extended, may have been timed to collect that traffic.

SenseTime's pipeline, they write, included Claude transcripts bought from third-party vendors who had logged users of proxies and routing services. MiniMax, they write, ran a proxy through a shell company with no obvious link to MiniMax. That service offered only Anthropic and OpenAI models, not MiniMax's own. They treat that as evidence the proxy existed to harvest US frontier exchanges. They do not attach a public exchange count to SenseTime or MiniMax the way they do for the other five.

They also write that the same proxy networks were shared. Some Alibaba-linked accounts, they say, were funneling requests from DeepSeek and Xiaomi. The named labs have not admitted these campaigns in the report. The document is Anthropic's clustering of their own logs.