Anthropic said on Thursday that accounts linked to Alibaba conducted more than 151 million exchanges with its Claude models between May and July 2026, marking what the company describes as its largest identified distillation campaign.
The activity was detailed in Anthropic's Threat Intelligence Report for September 2026, which documented efforts the company said it identified and terminated between December 2025 and August 2026. Anthropic described distillation as a practice of extracting a model's capabilities and recreating them without consent, typically using fake accounts and compromised credentials.
Campaign Structure and Methods
The traffic traced to Alibaba was distributed across 3,500 accounts and peaked at approximately three million exchanges in a single day. Anthropic said it linked the accounts because each used the same fixed prompt designed to extract reasoning from Claude, which the company viewed as a unified effort to generate training data for Alibaba's Qwen family of models.
One attacker method involved camouflaging requests as translation tasks, instructing Claude to translate what was presented as "previous working memory" into Japanese. Anthropic typically obscures the reasoning behind its model's responses by showing users summarized thinking blocks instead of raw traces.
Earlier Campaign and Market Impact
This represents a significant escalation from Anthropic's earlier allegations. In June, the company stated that Alibaba used 25,000 fake accounts across 28.8 million exchanges from April 22 to June 5, targeting Claude's reasoning, coding, and multi-step task abilities. Following the latest allegations, Alibaba's US-listed shares fell approximately 2.7% to a 52-week low.
Broader Distillation Efforts
Anthropic identified five separate distillation campaigns linked to China-based AI firms. The report also detailed a campaign attributed to Moonshot AI, which the company said "silently forwarded" approximately 300,000 customer requests to Claude over a 10-day period through 5,380 fraudulent accounts, primarily routing traffic to its Opus model instead of processing them through Moonshot's Kimi service.
The September report cited distillation attempts from Alibaba, Moonshot AI, DeepSeek, Z.ai, Xiaomi, SenseTime, and MiniMax. In February, Anthropic publicly accused DeepSeek, Moonshot AI, and MiniMax of creating more than 24,000 fake accounts and sending over 16 million prompts to Claude.


