Anthropic says Moonshot and DeepSeek relayed live customer prompts to Claude — the distillation is the headline, the undisclosed subprocessor is your problem
TL;DR: Anthropic’s fourth threat intelligence report landed 10 September 2026, covering December 2025 to August 2026. The distillation section names seven China-based labs and totals close to 200 million Claude exchanges, led by 151 million tied to Alibaba between May and July across roughly 3,500 fraudulent accounts, driven by a single fixed prompt extracting reasoning traces for Qwen training data. 12.1 million are tied to DeepSeek in a two-week July window. That is the headline. The line that matters to anyone with a budget is quieter: Anthropic says Moonshot routed some Kimi customers’ requests to Claude without telling them and displayed the answers as Kimi’s, and that DeepSeek silently relayed exchanges the same way — roughly 300,000 relayed customer requests over ten days in the Moonshot case. Anthropic says some of those exchanges carried sensitive information from individuals, multinational companies and state-affiliated actors, and calls the practice likely inconsistent with privacy laws and the labs’ own terms of service. If true, buyers of those hosted products had an undisclosed subprocessor in the request path — and under GDPR that liability sits with the controller, which is you. Crucially: this is about hosted endpoints, not open weights. Running the weights yourself relays nothing. The report is vendor-authored and unreproducible; the named labs did not respond to press requests.
The theft is the story everyone wrote. It is not the story you can act on.
Two hundred million exchanges is an arresting number, and it did what arresting numbers do: it took the whole news cycle. Anthropic accusing Alibaba, DeepSeek and Moonshot of industrial-scale extraction of Claude’s reasoning is a geopolitical story, a trade-policy story and an intellectual-property story. It is not, for almost anyone reading this, a purchasing story. Whether Qwen 3.8 Max learned to reason partly from Claude transcripts changes nothing about what Qwen costs you on Tuesday.
Buried in the same section is a finding of an entirely different kind. Anthropic says that Moonshot routed some Kimi user requests to Claude without informing those customers, and displayed Claude’s responses as if they were Kimi’s own. It says DeepSeek did something structurally similar — silently relaying exchanges to Claude without notifying its customers. Press accounts of the Moonshot relay describe roughly 300,000 customer requests over a ten-day window, spread across about 5,000 accounts, aimed primarily at Claude Opus.
Read that as a buyer rather than as a spectator. A company paid a vendor for a hosted model. The vendor, on this account, forwarded some of that company’s prompts to a different vendor in a different jurisdiction, kept the responses as training material, and returned them under its own brand. Nobody told the customer. Nobody could have, because the customer would have said no.
Why an undisclosed relay is a compliance event and distillation is not
Distillation is a dispute between Anthropic and the labs. You are not a party to it.
Relaying is a fact about your data path, and European and UK data protection law is unambiguous about who carries it. When you use a hosted model API for business data, you are typically the controller and the vendor is the processor. A processor may not engage another processor without your authorisation, and the subprocessors have to be named. Anthropic’s own characterisation is that the conduct is likely inconsistent with privacy laws and the labs’ own terms of service — which, if it holds, means the vendor breached its contract with you.
That does not transfer the regulatory exposure to the vendor. Under GDPR Article 28 and Article 30, the obligation to know where your data goes, to record it, and to have authorised it, is the controller’s. The supervisory authority writes to the controller. This desk made the same point when Article 50 of the EU AI Act became applicable in August: the obligations land on deployers, and “the vendor did not tell us” is an explanation, not a defence.
There is a second, sharper edge on the Moonshot allegation. Anthropic states that one relayed request it assessed as coming from a user affiliated with the People’s Liberation Army asked Claude to analyse CCTV surveillance footage from hundreds of cameras in Chengdu. Set aside the geopolitics. The mechanism is what matters: if the relay was indiscriminate, then the set of things forwarded to a third party was decided by whoever was typing, not by any policy either vendor had published.
What the report says, with the numbers attached
| Named lab | Reported volume | Window | Character |
|---|---|---|---|
| Alibaba | 151M+ exchanges | May–Jul 2026 | ~3,500 fraudulent accounts, single fixed extraction prompt, attributed to Qwen training data |
| Moonshot | ~23M exchanges; ~300K relayed customer requests | Jul 2026 (10-day relay window) | Live Kimi customer traffic relayed to Claude Opus, answers presented as Kimi’s |
| DeepSeek | 12.1M+ exchanges | two weeks, Jul 2026 | Customer exchanges silently relayed without notification |
| Zhipu | 3M+ exchanges | — | Extraction campaign |
| Xiaomi | 400K+ requests | — | Extraction campaign |
| SenseTime, MiniMax | Named, volumes not detailed in reporting | — | Named among seven labs |
Anthropic’s response was to ban the associated accounts, strengthen classifiers and safeguards, and share indicators with industry partners and authorities. Worth noting for anyone tracking model tiers: the report says the misuse it observed ran on Haiku, Sonnet and Opus, with no Fable- or Mythos-class misuse except a single distillation case.
The rest of the report is not filler, and one finding belongs in your security review even if the distillation section does not. Anthropic describes an actor that compromised an AI vendor’s evaluation sandbox, extracted production credentials, and then used the same pattern against roughly thirty AI companies in about four days. Its framing is that stolen model API keys now serve three purposes at once — resale value, free compute to run the next attack, and attribution cover, because the traffic looks like yours. That is the same failure surface this desk flagged when an agent swarm reached data it should not have: the credential is the perimeter, and agent integrations hand it out casually.
The line that is now a procurement line item
The useful distinction coming out of this report is one the coverage keeps blurring: weights you run versus endpoints you call.
Open weights are untouched by the relay finding. If you pull Kimi K3 or a DeepSeek release and serve it on your own hardware, or through an inference provider whose subprocessor list you have read, there is no vendor in the request path with the opportunity to forward anything. That distinction is doing real work this week: Cognition launched SWE-2, post-trained on Kimi K3, on the same day this report named Moonshot — and because Cognition serves those weights itself, Devin’s data path is not implicated by anything here. What the buyer inherits there is a provenance and indemnity question, not a privacy one. The economics that made the open-weight price floor real are unchanged by a threat report. The residual question on self-hosted weights is provenance and indemnity — if a model’s reasoning was distilled in breach of another vendor’s terms, the commercial user inherits a dispute and an indemnity gap. That is worth a clause in your next renewal, not a migration.
Hosted first-party endpoints are where the exposure is, and the exposure is specifically that the request path may not match the documentation. This is the same structural hazard, in a new costume, that the site has now covered from several directions in a fortnight. DeepSeek’s own routing changes made capability downgrade a function of time of day. CISA’s distillation advisory described degraded models served with enough variation that evaluation cannot detect the substitution. Sakana’s Fugu orchestrator states outright that its routing is undisclosed by design. In every case the buyer’s evaluation harness cannot see the thing that changed. A silent relay to a competitor’s model is the most extreme version of that: your benchmark suite would have scored Claude and written down Kimi.
What this does not establish
The report is vendor-authored, and the limits are real rather than rhetorical.
Anthropic has telemetry on its own API, which is genuine evidence. It has not published account data, prompts, network indicators or enforcement records, so nobody outside the company can reproduce the attribution from a cluster of fraudulent accounts to a named corporate parent. Anthropic competes commercially with every lab it names. Alibaba, DeepSeek, Moonshot and MiniMax did not respond to requests for comment, and China’s Foreign Ministry said it was unaware of the report and opposes what it called distortion of facts and smears against the country. No substantive denial of the specific relay claim has been offered.
That combination — credible mechanism, serious allegation, no independent verification, no denial — does not support a ban. It supports a question. The question is cheap to ask and the answer is worth having in writing regardless of what this report turns out to be.
What to do with this
- Send the routing question, in writing, to every hosted model vendor you use. Does any request ever leave your infrastructure for a third-party model? Which subprocessors are named in our contract? A clear written answer converts a rumour into a document you can rely on; a vague one is itself informative.
- If you used first-party Kimi or DeepSeek hosted products for confidential work between roughly May and August 2026, record it as a potential undisclosed-subprocessor event in your Article 30 records now. Reconstructing that timeline under a regulator’s deadline is far more expensive than logging it today.
- Rotate and scope your model API keys, and set expiries. The report’s clearest operational finding is that AI credentials are now a primary target with three separate resale values. Short-lived, narrowly scoped keys reduce all three.
- Split hosted-endpoint risk from self-hosted-weight risk in your register. They are different exposures. Merging them leads either to banning cheap capacity you could safely run yourself, or to waving through a live data path because “we already approved that model”.
- Price the controls into the comparison. If a hosted Chinese endpoint won on price alone, the gap narrows by whatever the monitoring, contractual and record-keeping overhead now costs. If it won on capability per dollar, self-hosting the weights preserves the win without the request-path question.
- Do not treat vendor threat reports as neutral, or as noise. Read them the way you read a competitor’s security whitepaper: the mechanism is usually real, the attribution is usually a judgement, and the recommendations are usually sound for reasons unrelated to who is accused.
For the broader picture, the DeepSeek review and Qwen review track the hosted products named here, the Claude review covers the models on the receiving end, and best AI chatbots is where these vendors compete on the consumer side that the relay allegation most directly touches.
Frequently asked questions
What exactly does Anthropic's September 2026 threat report allege?
Anthropic published its fourth threat intelligence report, 'Countering misuse of AI', on 10 September 2026, covering activity it detected and disrupted between December 2025 and August 2026 across more than forty tracked threat groups and seven harm categories. The section that drew the coverage is illicit distillation: industrial-scale extraction of Claude's chain-of-thought reasoning through networks of fraudulent accounts, for use as training material. Reporting on the report puts the total at close to 200 million exchanges across the measured campaigns, and names seven China-based labs — Alibaba, DeepSeek, Moonshot, Zhipu, Xiaomi, SenseTime and MiniMax. The largest single campaign is attributed to Alibaba: more than 151 million exchanges between May and July 2026, peaking near three million a day, spread across roughly 3,500 accounts Anthropic flagged as fraudulent, and driven by a single fixed prompt designed to pull out reasoning traces. Anthropic says those transcripts were used to help train the Qwen family. Separately, Anthropic logged more than 12.1 million exchanges tied to DeepSeek over a two-week window in July 2026, and figures in the low tens of millions for Moonshot. Note the scope limit the report itself draws: distillation here means covert extraction through fake accounts, stolen cards and relayed traffic, not the ordinary practice of training on model outputs.
Why is the relaying finding more important to a buyer than the distillation total?
Because distillation is a dispute between two labs, and relaying is a fact about a product you may have paid for. Anthropic says Moonshot routed some Kimi user requests to Claude without informing customers and then displayed Claude's responses as if they were Kimi's, and that DeepSeek silently relayed exchanges to Claude without notifying its customers. Reported figures for the Moonshot relay describe roughly 300,000 customer requests routed over a ten-day window through about 5,000 accounts, aimed mainly at Claude Opus. If that is accurate, then a company that bought the hosted Kimi or DeepSeek product was sending its prompts to a third-party processor that appeared in no contract, no subprocessor list and no data-protection assessment. Anthropic states that some of the exchanges contained sensitive information from individual users, multinational companies and state-affiliated actors, and characterises the practice as likely inconsistent with privacy laws and with the labs' own terms of service. Under GDPR that is an Article 28 problem — a processor engaging a sub-processor without authorisation — and the controller on the hook is the customer, not the lab. The regulator writes to the deployer.
Does this mean open-weight Chinese models are unsafe to use?
No, and collapsing those two things is the most expensive mistake available here. The alleged conduct is about hosted endpoints — the first-party APIs and consumer apps operated by these labs — and about how the training data behind the models was obtained. Running Qwen, Kimi K3, DeepSeek or GLM weights on your own hardware or through a neutral inference provider relays nothing to anyone, because there is no vendor in the request path to relay it. The residual exposure on self-hosted weights is provenance, not privacy: if a model's reasoning ability was distilled from Claude in breach of Anthropic's terms, a downstream commercial user inherits a contractual dispute they were never party to and an indemnity gap their vendor agreement probably does not cover. That is a real risk to write into a procurement note, and it is a different risk from having your prompts silently forwarded. The practical split is clean — weights you run are a licensing question, endpoints you call are a data question.
How much of this is verified, and how much is one vendor's account?
It is one vendor's account, and that limit should be stated plainly rather than buried. Anthropic has direct telemetry on its own API, which is genuine evidence and better than inference. It has not published the underlying account data, prompts, network indicators or enforcement records, so outside researchers cannot reproduce the findings, and the attribution of a cluster of fraudulent accounts to a named corporate parent is a judgement call, not a receipt. Anthropic is also a direct commercial competitor to every lab it names, which does not make the report wrong but does mean it should not be read as neutral. On the other side of the ledger: Alibaba, DeepSeek, Moonshot and MiniMax did not respond to press requests for comment, and China's Foreign Ministry said it was unaware of the report while opposing what it called distortion of facts and smears. No named lab has offered a substantive denial of the specific relay claim. The responsible position for a buyer is neither dismissal nor acceptance — it is asking your own vendor, in writing, a question this report has made reasonable to ask.
What should a buyer actually do this week?
Five things, roughly in order of cost. First, send a written routing question to every hosted model vendor you use: does any request ever leave your infrastructure for a third-party model, and if so, which subprocessors are named in the contract? A vendor that answers confidently in writing has given you a document to rely on. Second, if you used first-party Kimi or DeepSeek hosted products for anything confidential in the May to August 2026 window, log it as a potential undisclosed-subprocessor event in your GDPR Article 30 records and decide whether it rises to an assessment — that decision is easier to defend made now than reconstructed later. Third, rotate and scope your model API keys; Anthropic's report describes stolen AI credentials being used as loot, as free compute, and as attribution cover, with one actor probing roughly thirty AI companies in about four days after compromising a single vendor sandbox. Fourth, separate your self-hosted open-weight usage from your hosted-endpoint usage in your own risk register, because the two carry different exposures and merging them will cause you to either over-restrict cheap capacity or under-restrict a live data path. Fifth, treat agent integrations as production credentials rather than developer conveniences, which is Anthropic's own stated recommendation and the cheapest item on this list.
Does this change the economics of the open-weight price floor?
Not directly, and anyone predicting a price correction from this report is guessing. The open-weight cost advantage that Qwen, Kimi and DeepSeek established this year rests on published weights and permissive licences, and nothing in a threat report revokes a licence that has already shipped. What changes is the due-diligence overhead on the hosted side of that market. A first-party endpoint priced below everyone else was already a bet that the vendor's operating practices matched its documentation, and this report is evidence — contested, vendor-authored evidence — that for at least two vendors the documentation may not have described the request path. If your reason for choosing a hosted Chinese endpoint over self-hosting was purely price, the gap just got narrower by the cost of the controls you now need to put around it. If your reason was capability at a price point, the answer is the same as it was before: run the weights yourself, or through a provider whose subprocessor list you have actually read.
Sources
- Anthropic — Countering misuse of AI: September 2026 (threat intelligence report, 10 September 2026)
- TechCrunch — Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek (10 September 2026)
- Quartz — Anthropic accuses Chinese AI labs of illicit distillation attacks (11 September 2026)
- CNBC — Chinese AI labs secretly used millions of Claude exchanges to train their models, Anthropic says (11 September 2026)
- Times of AI — Anthropic says Chinese labs routed user chats through Claude (11 September 2026)
- TechNode Global — Anthropic reports AI-orchestrated attacks and model theft (11 September 2026)
Related tool reviews
Questions or corrections? Email Pick Right. Want the full list? See all news.