Federal cybersecurity and intelligence agencies on Tuesday accused six China-based artificial intelligence companies of running industrial-scale campaigns to extract proprietary features from leading U.S. models.
DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI were all named in the joint advisory. Officials alleged the companies, “likely with Chinese government awareness,” pulled billions of tokens across millions of requests from U.S. AI systems. The list included variants of Claude, GPT, Gemini, and Grok. The activity dates back to at least late 2024.
Cybersecurity and Infrastructure Security Agency (CISA) Acting Director Nick Andersen said that CISA is committed to promoting the secure use of AI.
“We strongly urge AI companies to take immediate steps to safeguard their platforms against knowledge distillation campaigns that threaten to close the gap in advancements made by American companies,” Andersen said.
Knowledge distillation is a standard research method where a smaller model learns from the outputs of a larger one. The three agencies—CISA, the National Security Agency, and the FBI—differentiated legitimate research from “aggressive, malicious, and targeted distillation activities at an industrial scale.”
The advisory
saidthe firms routed traffic through native application programming interfaces (API), remote cloud providers, and third-party aggregators that strip user metadata. A gray market of proxies, referred to as “transfer stations,” helped them dodge geographic blocks, break terms of use, and muddy the trail. Bulk premium subscriptions, shared across developer teams, kept the bills down.
DeepSeek, formally Hangzhou DeepSeek Artificial Intelligence Basic Technology Research Co. Ltd., has run an organized campaign since at least late 2024, according to the agency, to feed synthetic training data into its R1 and V3 models.
Targets included Claude 3.7, Claude Sonnet 4 and 4.5, Claude Opus 4.1, Gemini 2.5 Pro and Flash previews, GPT-4, GPT-4o, GPT-5, and Grok 4. Officials called DeepSeek’s widely cited $5.6 million training figure misleading, saying it leaves out the cost of data taken through distillation.
Moonshot AI, or Beijing Moonshot Technology Co. Ltd., was accused of a broad campaign since at least mid-2025. The advisory said the firm pulled substantial Claude Fable 5 data for its Kimi-K3 model and GPT-4o data for Kimi-K2.
The new advisory recommends three steps for U.S. model providers, including hunting anomalous prompts, accounts, and usage spikes; quietly degrading answers when a distillation campaign is suspected; and sharing intelligence across companies, clouds, and API aggregators.
In July, Office of Science and Technology Policy Director Michael Kratsios said his office had
reason to believeMoonshot AI “distilled Anthropic’s Fable for the development of its K3 model.”
“Large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable,” Kratsios said.
Alibaba, the agencies contended, distilled Claude-4, Claude Opus, Claude Sonnet, and GPT-5 in late 2025 to hasten software engineering, customer-service dialogue, and image creation for its Qwen family of models. MiniMax, or Shanghai MiniMax Co. Ltd., used Claude Code, Claude Sonnet 4, Claude Opus, and several Gemini versions to improve its M2 model. Officials said MiniMax even attempted prompt injections to convince Claude Code it was actually a MiniMax product.
StepFun distilled a string of Claude and GPT-5 variants between late 2025 and early 2026 for its Step 4 model. By mid-2026, Z.AI had taken billions of tokens of GPT-5.5 and Claude Opus 4.8 data for chain-of-thought reasoning, the advisory said.
On April 23, a White House memo
warnedof “industrial-scale campaigns” employing “tens of thousands of proxy accounts” and jailbreaking tricks.
“There is nothing innovative about systematically extracting and copying the innovations of American industry,” Kratsios wrote at the time. “And there is nothing open about supposedly open models that are derived from acts of malicious exploitation.”
The memo also said the campaigns “allow those actors to deliberately strip away security protocols from the resulting models and undo mechanisms that ensure those AI models are ideologically neutral and truth-seeking.”
Anthropic, the maker of Claude, said in
Februarythat DeepSeek, Moonshot AI, and MiniMax created about 24,000 fraudulent accounts and sent more than 16 million prompts to Claude. MiniMax accounted for more than 13 million, Moonshot AI more than 3.4 million, and DeepSeek about 150,000, according to the company.
Treasury Secretary Scott Bessent said he is open to sanctioning Chinese AI developers over alleged model theft.
“This administration supports open-source models, but what we do not support is IP theft,” Bessent said in July. “If we see, especially, that overseas models are stealing from our great companies, we have the ability to sanction them because of this theft.”
“There’s a very technical AI word for it called distillation, but you and I would call it theft.”
CISA, the National Security Agency, and the FBI said the effort sits at the center of those firms’ development plans.









