A new wave of accusations
Anthropic released a 154-page threat report covering the misuse of its models from December 2025 through August 2026. Part of the document concerns not isolated use, but industrial-scale copying: according to the company, Chinese labs massively collected Claude’s responses to train their own systems on them. For the first time, a more specific accusation was made: user requests were not merely collected, but quietly forwarded to Claude.
The list names seven companies: Alibaba, DeepSeek, Moonshot AI, Xiaomi, Zhipu (Z.ai), SenseTime, and MiniMax. Previously, the FBI, NSA, and CISA had spoken out about similar schemes involving Chinese developers.
How the forwarding works
The scheme bypasses ordinary access restrictions. A company creates a network of fake accounts and pays for it through proxies, and in some cases with stolen payment details or API keys. A user sends a request to its own model, but some requests are sent to Claude, and the response is returned to the user as the result of its own system’s work. From the client’s perspective, there is no difference, although in fact their data is processed by an American lab.
They also copy reasoning chains: these are saved and used as ready-made material for additional training. This transfer of capabilities can improve the quality of a company’s own model without the cost of training it from scratch.
Scale: the three leaders by volume
The figures in the report vary by orders of magnitude, showing how different the tactics were.
| Company | Volume | Distinguishing feature |
|---|---|---|
| Alibaba | more than 151 million requests from May through July, up to 3 million per day | The largest campaign: from 3 to 500 fake accounts, collecting Opus 4.6 and 4.7 reasoning chains, and training Qwen |
| Moonshot AI | about 300 000 requests over 10 days | Forwarding Kimi requests through 5 380 accounts, primarily from Singapore and Japan |
| DeepSeek | more than 12,1 million exchanges over 14 days in July | Quietly forwarding some requests without notifying users |
The report gives another figure for Moonshot: from May through July, it is credited with more than 23 million exchanges with Claude. The company says it saved some sessions and extracted the model’s reasoning for training its own systems.
What ended up in the hands of others
The content of some of the forwarded messages is a separate cause for concern. They included internal documents from a Chinese technology company, credentials linked to a Russian government registry, and information used by engineers of a police-surveillance system. Anthropic emphasizes that it is unknown whether users knew their data was being sent to a third party.
Another layer of the problem is privacy. Forwarding meant that requests from Chinese users were effectively processed by an American company. The very fact of this routing raises the question of how well users understood where their messages were being stored.
The parties’ reactions
Beijing rejected the accusations. Official representatives called them a means of pressuring China’s AI industry and threatened retaliatory measures. Chinese labs provided no detailed public explanations. For its part, Anthropic said it had implemented classifiers to detect attempts at mass data extraction, moved from blocking individual accounts to organization-wide bans, and introduced identity verification for accounts showing signs of abuse or originating from unsupported countries. According to the company, it was not possible to successfully attack the Mythos-class models, which are not publicly available.
What this means for users and teams
- Find out who processes the request. If a service claims to use its own model, that does not mean the response was generated by that model.
- Do not send sensitive data to other people’s chats. Internal documents, keys, and personal information reached third parties even without a direct breach.
- Read the provider’s policies. Disclaimers about data use and subcontractors matter more than marketing claims about sovereignty.
- Take regulatory risk into account. For companies operating across multiple markets, data transfers between jurisdictions can result in claims from both sides at once.
Compare models before you start
The service sets its plans, limits and model catalog. If they differ from this article, contact us so we can update it and record a new review date.
Browse modelsAffiliate link: your price stays the same and the project earns a commission.