Anthropic logo. /Courtesy of Yonhap News

Anthropic disclosed indications that Chinese artificial intelligence (AI) corporations used thousands of fake accounts and overseas broker networks to mass-collect answers from its AI model Claude and tried to use them to develop their own models.

According to a threat intelligence report Anthropic released on the 10th (local time), Chinese AI corporations including Moonshot AI and DeepSeek accessed Claude at scale using so-called "transfer stations."

Transfer stations are overseas brokerage services that relay requests and responses between Chinese AI corporations and U.S. AI models. Operated outside China, these firms created large numbers of U.S. AI service accounts using fake identities, stolen or forged credit cards, and hijacked API keys, then input questions sent by Chinese AI corporations into Claude and returned the answers.

This method is a type of "distillation" technique that boosts a company's model performance by training on a competitor's responses, and U.S. authorities have likened it to theft on an industrial scale.

According to Anthropic, one user asked Moonshot's "Kimi" service to analyze surveillance data on a person collected from hundreds of closed-circuit (CC) TV cameras in Chengdu, China. Moonshot then passed this data to Claude through an intermediary network.

Moonshot also mobilized thousands of fake accounts to exchange more than 23 million messages with Claude from May to July. DeepSeek transmitted sensitive customer information to Claude in a similar way. A total of seven China-based research institutes attempted such distillation over the past seven months.

Jacob Klein, Anthropic's head of threat intelligence, told The Wall Street Journal (WSJ), "Users had no way to know their Kimi usage history was being passed to Claude," adding, "If corporations like Anthropic had done this, it would have been a big scandal."

Anthropic said in the report that it also found evidence Claude was used for hacking crimes and biological research. One user in China used Claude to try to modify the avian influenza virus to infect mammals. Klein said, "If previously we worried about this type of misuse as a hypothetical concern, now it has moved into reality."

WSJ also reported that OpenAI confirmed similar queries related to biological weapons and toxins.

A Chinese-speaking hacking group believed to be in Changsha, China, used Claude as an "exploit foundry." Comprising two local university undergraduates, the group split Claude into multiple subordinate AI agents to carry out information gathering and post-intrusion tasks simultaneously. It was designed to continuously remember target lists, stolen credentials, and task instructions.

In one operation targeting network equipment alone, it identified more than 10 zero-day vulnerability candidates in a month, and about 50 institutions were targeted using this approach, it was found.

In addition, the report said it confirmed cases including attacks by a Russian state-backed hacking group targeting Ukrainian government, military, and diplomatic institutions; a French hacker operating a doxxing site; and a Turkish corporations' manipulation of public opinion in Malaysia's elections.

※ This article has been translated by AI. Share your feedback here.