The Hacker News

Top story

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to

Sep 9, 2026, 9:32 AMBy info@thehackernews.com (The Hacker News)4 min readcybersecurity
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

U. S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks.

The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to a bulletin released by the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI).

"While 'distillation' is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U. S.

frontier AI models," the authoring agencies said . The joint advisory noted that Chinese AI firms like DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z. AI have extracted billions of tokens across millions of exchanges/requests from U. S.

frontier AI models, including variants of Anthropic Claude, OpenAI GPT, Google Gemini, and SpaceXAI Grok, since at least late 2024, likely with the blessing of the Chinese government. "China-based AI companies achieve cost savings for their industrial-scale distillation campaigns through bulk procurement of the U. S.

AI companies' premium subscriptions shared across teams of developers," the agencies said.

"Advanced industrial-scale distillation tactics include chain-of-thought (CoT) reasoning extraction, automated failover between pathways during blocking attempts, and sophisticated quality evaluation frameworks to detect defensive countermeasures.

China-based AI companies that conduct industrial-scale distillation against U. S. AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model."

Some of the specific allegations laid out by the NSA, CISA, and FBI are as follows - These distillation requests are routed through various methods to gain unauthorized access to the U. S. models, violating their .

These include application programming interfaces (APIs), remote cloud providers, and third-party aggregators that obfuscate user metadata to avoid detection. It's worth noting that U. S. frontier models are officially restricted and not offered in China.

This has forced Chinese developers to rely on domestic systems or alternative access methods like virtual private networks, obfuscated accounts, and automated agents to bypass these geographic controls.

The efforts are complemented by a gray market of proxies that serve as relay or transfer stations to obtain illicit access through servers hosted outside mainland China. Such services have been marketed on Chinese online marketplaces Taobao and Xianyu.

Furthermore, the China-based AI companies deliberately take steps to distribute these operations across multiple providers and platforms to fly under the radar, focusing on distilling the best capabilities and proprietary features of each U. S. frontier model to train their own models.

This is not the first time Chinese firms have been called out for engaging in illegal distillation attacks. Earlier this February, Anthropic said it identified industrial-scale campaigns conducted by DeepSeek, Moonshot AI, and MiniMax to illicitly extract Claude's capabilities to improve their own models.

As recently as this week, Google Threat Intelligence Group (GTIG) said it has observed a spike in distillation campaigns targeting Google's AI models, some of which have exceeded 100 million prompts and focused on visual and audio understanding, image generation, and video generation.

"Attackers deploy proxy infrastructure to orchestrate large-scale automated attacks, rotating queries across thousands of compromised credentials and fraudulent accounts across different product channels to obscure their origin and bypass standard security controls," GTIG said.

Ismael Valenzuela, vice president of Labs, Threat Research, and Intelligence at Arctic Wolf, said the security bulletin needs to be interpreted as an abuse of legitimate access, while stressing the need for a coordinated response against sophisticated, well-resourced adversaries.

"While distillation is nothing out of the ordinary in a research setting, the warning states that the offending companies are deliberately distributing operations across the vast global AI ecosystem, similar to the evasion tactics security teams have seen from adversaries engaging in distributed credential stuffing or payment fraud," Valenzuela said.

"When adversaries can replicate the advanced reasoning and agent behaviors of models from U. S. AI companies without heeding the laws and regulations binding those U. S.

AI companies, defenders will struggle to distinguish their activity from legitimate platforms, leaving the door open for offensive cyber operations, influence campaigns, or autonomous tooling that can go undetected."

"Businesses not directly associated with frontier AI models may be tempted to disregard these campaigns as irrelevant due to them being a national security issue, but the exposure of model access to customers or partners makes API keys and service accounts valuable targets, with abuse of access to those models appearing as legitimate," Valenzuela added.

See how to test new CVEs against your environment, confirm what attackers can actually exploit, and fix the exposures that pose the greatest risk. Learn how to identify exploitable risk faster, prioritize what matters most, and reduce exposure before AI-powered attacks accelerate the threat.

Continue with the publisher

Read the original source after the immersive in-app article experience.

Read on source site
Loading...