cd /news/ai-safety/anthropic-says-china-based-operators… · home topics ai-safety article
[ARTICLE · art-130842] src=ministryofcyberaffairs.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Anthropic says China-based operators used Claude to copy its AI, track dissidents and run dating scams

Anthropic said on Thursday it disrupted China-based operators that used its Claude AI models for unauthorized model copying, surveillance, cyber intrusions, weapons-related research and fraud, according to a threat report covering December 2025 to August 2026. The company accused seven China-based labs of "illicit distillation," including operators linked to Alibaba Group Holding Ltd that it said ran the largest campaign it has measured, targeting Opus 4.6 and 4.7 to train Qwen 3.5, 3.6 and 3.7, peaking at nearly 3 million exchanges a day from more than 3,500 fraudulent accounts and totaling more than 151 million exchanges from May to July. Anthropic said it banned the accounts involved, tightened safety controls and shared information with other firms and governments, and noted Claude is not generally available in China.

by read6 min views28 publishedSep 11, 2026
Anthropic says China-based operators used Claude to copy its AI, track dissidents and run dating scams
Image: Ministryofcyberaffairs (auto-discovered)

Back to News Anthropic said its threat intelligence team spotted the activity by watching how accounts behaved, not by reading every chat. Investigators grouped related users into internal clusters, then matched language, time zones, shared proxy servers, fake identities, virtual cards and stolen API keys. Sudden spikes in traffic — in some cases millions of exchanges a day — and the reuse of the same account pools after bans pointed to organised campaigns rather than isolated users. The company said it then

SAN FRANCISCO, Sept 10 - Anthropic said on Thursday it had disrupted Chinese companies, security units and other operators that used its Claude AI models for unauthorized copying, surveillance, cyber intrusions, weapons-related research and fraud.

The findings were published in a threat report covering activity from December 2025 to August 2026.

Anthropic said it banned the accounts involved, tightened safety controls and, where the harm went beyond its platform, shared information with other firms and with governments.

Claude is not generally available in China.

Anthropic said the operators reached the models through unofficial proxy services that created accounts with false identities, disposable email addresses, virtual payment cards and stolen API keys.

The company said the cases involved its Haiku, Sonnet and Opus models.

It said it had not seen the same pattern on its Fable or Mythos systems, except in one copying case.

Distillation campaigns #

Anthropic accused seven China-based labs of “illicit distillation”, using large volumes of Claude output, including hidden reasoning text, to train other models without authorization.

It said operators linked to Alibaba Group Holding Ltd (9988.HK) ran the largest such campaign it had measured, targeting Opus 4.6 and 4.7 and using the material to train Qwen 3.5, 3.6 and 3.7.

The activity peaked at nearly 3 million exchanges a day from more than 3,500 accounts Anthropic described as fraudulent.

From May to July it attributed more than 151 million exchanges to that campaign. When Anthropic banned a pool of almost 5,000 accounts, the traffic shifted to another pool, the report said.

Some of those accounts also carried traffic for DeepSeek and Xiaomi, it added.

Alibaba did not immediately respond to a request for comment on the report.

Anthropic said Moonshot AI, maker of the Kimi assistant, forwarded customer prompts to Claude and showed users Claude’s replies while they believed they were using Kimi.

In one 10-day period it counted almost 300,000 such requests through more than 5,000 accounts that appeared to be in Singapore and Japan.

From May to July it attributed more than 23 million exchanges to Moonshot. DeepSeek used a similar method and sent selected coding-tool traffic to Opus, Anthropic said.

It attributed more than 12.1 million exchanges to DeepSeek over 14 days in July.

It also attributed smaller campaigns to Zhipu, which operates abroad as Z.ai, and to Xiaomi.

SenseTime bought logs of Claude chats from third-party vendors, the report said.

MiniMax set up a shell company that sold access only to U.S. models, which Anthropic said was a way to harvest training data.

Some forwarded chats contained internal company documents and live passwords, the report said.

Anthropic argued that safety limits built into Claude do not carry over when another lab trains on stolen transcripts.

Surveillance #

Separately, Anthropic said China-based operators linked to the state or to government contractors used Claude to profile dissidents, religious groups and diaspora communities.

One operator with no Arabic used the model to draft recruitment messages in Syrian dialect aimed at Uyghurs in Syria, translate replies and check the wording, the report said.

The same operator pulled traffic from more than 100 WhatsApp groups and flagged people who still had family in Xinjiang.

Anthropic said it had low confidence that this was a contractor rather than an official acting directly.

Other accounts produced dossiers on Catholic leaders in Asia, Taiwan church officials, Tibetan exile groups and Falun Gong media, it said.

One user identified themselves as a Chinese state information-security officer.

Anthropic also described a municipal cyber-police unit running a daily sentiment monitor, a police academy student who obtained a list of 10 private citizens marked for “control,” and a local bureau, possibly in Zhejiang, that wrote a staff manual telling officers to treat Claude as a state intelligence analyst.

Overseas tasking included protest locations in Vancouver, Turkey and Oslo, the report said.

A further operation scored foreign news for political sensitivity and rewrote it in official language, the company said.

Its filters did not always hold.

In one session Claude refused a request and then complied when asked again.

Cyber operations #

Anthropic said a group of Chinese-speaking operators, probably in Changsha, used Claude to scan networks, hunt software flaws and write malware.

Two were undergraduates.

One had interned at security firm Sangfor and was applying to QiAnXin.

The group’s target list covered about 50 organisations, the report said.

It described theft of student records from an education firm, access to a retailer’s production systems and the taking of citizen data from a Southeast Asian government agency.

An automated effort to reverse-engineer appliance firmware produced more than a dozen possible previously unknown flaws in a month, tested in the operators’ own lab, Anthropic said.

When the group broke into systems directly, it focused on victims inside China.

Three China-based cases appear in a section on conventional weapons.

Anthropic bars the use of Claude to design weapons and said it banned the accounts.

One actor, presenting as a U.S. defence contractor, used Claude to draft a Chinese specification and a proposal of more than 200 pages for an anti-torpedo system intended for the PLA Navy, the report said.

A second actor, with account signals Anthropic linked to the PLA Academy of Military Sciences, built about 16 programs for electronic warfare and air-defence suppression.

Midway through the project the default exercise was changed to 12 targets in Taiwan, including air bases and Patriot batteries, it said.

A third described themselves as a defence writer and used Claude to gather public information on directed-energy weapons and draft restricted briefings, the report said.

Anthropic did not say any of the software had been deployed.

Fraud #

Anthropic also said a China-based studio used Claude to power more than 20 dating apps advertised as human-run.

In two weeks in April it counted more than 4,700 AI personas in contact with at least 25,000 people.

Paid gig workers were mixed into the same feed so some users could still join a video call.

Response #

Anthropic said it now tries to attribute proxy networks to organisations rather than banning accounts one by one, blocks requests it believes are designed to steal model reasoning, and can require identity checks when traffic appears to come from countries it does not support, including China.

The report is based on Anthropic’s own logs and attributions.

The named companies have not publicly accepted the allegations.

Reporting based on Anthropic’s report, “Detecting and countering misuse of AI: September 2026,” published Sept. 10, 2026. https://www.anthropic.com/threat-intelligence-report-september-2026

── more in #ai-safety 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/anthropic-says-china…] indexed:0 read:6min 2026-09-11 ·