{"slug": "anthropic-says-china-based-operators-used-claude-to-copy-its-ai-track-dissidents", "title": "Anthropic says China-based operators used Claude to copy its AI, track dissidents and run dating scams", "summary": "Anthropic said on Thursday it disrupted China-based operators that used its Claude AI models for unauthorized model copying, surveillance, cyber intrusions, weapons-related research and fraud, according to a threat report covering December 2025 to August 2026. The company accused seven China-based labs of \"illicit distillation,\" including operators linked to Alibaba Group Holding Ltd that it said ran the largest campaign it has measured, targeting Opus 4.6 and 4.7 to train Qwen 3.5, 3.6 and 3.7, peaking at nearly 3 million exchanges a day from more than 3,500 fraudulent accounts and totaling more than 151 million exchanges from May to July. Anthropic said it banned the accounts involved, tightened safety controls and shared information with other firms and governments, and noted Claude is not generally available in China.", "body_md": "[Back to News](https://ministryofcyberaffairs.com/)\n\n# Anthropic says China-based operators used Claude to copy its AI, track dissidents and run dating scams\n\nAnthropic said its threat intelligence team spotted the activity by watching how accounts behaved, not by reading every chat. Investigators grouped related users into internal clusters, then matched language, time zones, shared proxy servers, fake identities, virtual cards and stolen API keys. Sudden spikes in traffic — in some cases millions of exchanges a day — and the reuse of the same account pools after bans pointed to organised campaigns rather than isolated users. The company said it then\n\nSAN FRANCISCO, Sept 10 - Anthropic said on Thursday it had disrupted Chinese companies, security units and other operators that used its Claude AI models for unauthorized copying, surveillance, cyber intrusions, weapons-related research and fraud.\n\nThe findings were published in a threat report covering activity from December 2025 to August 2026.\n\nAnthropic said it banned the accounts involved, tightened safety controls and, where the harm went beyond its platform, shared information with other firms and with governments.\n\nClaude is not generally available in China.\n\nAnthropic said the operators reached the models through unofficial proxy services that created accounts with false identities, disposable email addresses, virtual payment cards and stolen API keys.\n\nThe company said the cases involved its Haiku, Sonnet and Opus models.\n\nIt said it had not seen the same pattern on its Fable or Mythos systems, except in one copying case.\n\n## Distillation campaigns\n\nAnthropic accused seven China-based labs of **“illicit distillation”**, using large volumes of Claude output, including hidden reasoning text, to train other models without authorization.\n\nIt said operators linked to Alibaba Group Holding Ltd (9988.HK) ran the largest such campaign it had measured, targeting Opus 4.6 and 4.7 and using the material to train Qwen 3.5, 3.6 and 3.7.\n\nThe activity peaked at nearly 3 million exchanges a day from more than 3,500 accounts Anthropic described as fraudulent.\n\nFrom May to July it attributed more than 151 million exchanges to that campaign.\n\nWhen Anthropic banned a pool of almost 5,000 accounts, the traffic shifted to another pool, the report said.\n\nSome of those accounts also carried traffic for DeepSeek and Xiaomi, it added.\n\nAlibaba did not immediately respond to a request for comment on the report.\n\nAnthropic said Moonshot AI, maker of the Kimi assistant, forwarded customer prompts to Claude and showed users Claude’s replies while they believed they were using Kimi.\n\nIn one 10-day period it counted almost 300,000 such requests through more than 5,000 accounts that appeared to be in Singapore and Japan.\n\nFrom May to July it attributed more than 23 million exchanges to Moonshot.\n\nDeepSeek used a similar method and sent selected coding-tool traffic to Opus, Anthropic said.\n\nIt attributed more than 12.1 million exchanges to DeepSeek over 14 days in July.\n\nIt also attributed smaller campaigns to Zhipu, which operates abroad as Z.ai, and to Xiaomi.\n\nSenseTime bought logs of Claude chats from third-party vendors, the report said.\n\nMiniMax set up a shell company that sold access only to U.S. models, which Anthropic said was a way to harvest training data.\n\nSome forwarded chats contained internal company documents and live passwords, the report said.\n\nAnthropic argued that safety limits built into Claude do not carry over when another lab trains on stolen transcripts.\n\n## Surveillance\n\nSeparately, Anthropic said China-based operators linked to the state or to government contractors used Claude to profile dissidents, religious groups and diaspora communities.\n\nOne operator with no Arabic used the model to draft recruitment messages in Syrian dialect aimed at Uyghurs in Syria, translate replies and check the wording, the report said.\n\nThe same operator pulled traffic from more than 100 WhatsApp groups and flagged people who still had family in Xinjiang.\n\nAnthropic said it had low confidence that this was a contractor rather than an official acting directly.\n\nOther accounts produced dossiers on Catholic leaders in Asia, Taiwan church officials, Tibetan exile groups and Falun Gong media, it said.\n\nOne user identified themselves as a Chinese state information-security officer.\n\nAnthropic also described a municipal cyber-police unit running a daily sentiment monitor, a police academy student who obtained a list of 10 private citizens marked for “control,” and a local bureau, possibly in Zhejiang, that wrote a staff manual telling officers to treat Claude as a state intelligence analyst.\n\nOverseas tasking included protest locations in Vancouver, Turkey and Oslo, the report said.\n\nA further operation scored foreign news for political sensitivity and rewrote it in official language, the company said.\n\nIts filters did not always hold.\n\nIn one session Claude refused a request and then complied when asked again.\n\n## Cyber operations\n\nAnthropic said a group of Chinese-speaking operators, probably in Changsha, used Claude to scan networks, hunt software flaws and write malware.\n\nTwo were undergraduates.\n\nOne had interned at security firm Sangfor and was applying to QiAnXin.\n\nThe group’s target list covered about 50 organisations, the report said.\n\nIt described theft of student records from an education firm, access to a retailer’s production systems and the taking of citizen data from a Southeast Asian government agency.\n\nAn automated effort to reverse-engineer appliance firmware produced more than a dozen possible previously unknown flaws in a month, tested in the operators’ own lab, Anthropic said.\n\nWhen the group broke into systems directly, it focused on victims inside China.\n\n## Weapons-related work\n\nThree China-based cases appear in a section on conventional weapons.\n\nAnthropic bars the use of Claude to design weapons and said it banned the accounts.\n\nOne actor, presenting as a U.S. defence contractor, used Claude to draft a Chinese specification and a proposal of more than 200 pages for an anti-torpedo system intended for the PLA Navy, the report said.\n\nA second actor, with account signals Anthropic linked to the PLA Academy of Military Sciences, built about 16 programs for electronic warfare and air-defence suppression.\n\nMidway through the project the default exercise was changed to 12 targets in Taiwan, including air bases and Patriot batteries, it said.\n\nA third described themselves as a defence writer and used Claude to gather public information on directed-energy weapons and draft restricted briefings, the report said.\n\nAnthropic did not say any of the software had been deployed.\n\n## Fraud\n\nAnthropic also said a China-based studio used Claude to power more than 20 dating apps advertised as human-run.\n\nIn two weeks in April it counted more than 4,700 AI personas in contact with at least 25,000 people.\n\nPaid gig workers were mixed into the same feed so some users could still join a video call.\n\n## Response\n\nAnthropic said it now tries to attribute proxy networks to organisations rather than banning accounts one by one, blocks requests it believes are designed to steal model reasoning, and can require identity checks when traffic appears to come from countries it does not support, including China.\n\nThe report is based on Anthropic’s own logs and attributions.\n\nThe named companies have not publicly accepted the allegations.\n\nReporting based on Anthropic’s report, “Detecting and countering misuse of AI: September 2026,” published Sept. 10, 2026. [https://www.anthropic.com/threat-intelligence-report-september-2026](https://www.anthropic.com/threat-intelligence-report-september-2026)", "url": "https://wpnews.pro/news/anthropic-says-china-based-operators-used-claude-to-copy-its-ai-track-dissidents", "canonical_source": "https://ministryofcyberaffairs.com/news/anthropic-says-china-based-operators-used-claude-to-copy-its-ai-track-dissidents-and-run-dating-scams-c2e8d61e-c64f-41c5-916e-5d1fc587625b?utm_source=rss&utm_medium=feed", "published_at": "2026-09-11 02:02:41+00:00", "updated_at": "2026-09-15 23:35:54.189965+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "large-language-models", "artificial-intelligence"], "entities": ["Anthropic", "Claude", "Alibaba Group Holding Ltd", "Qwen", "DeepSeek", "Moonshot AI", "Kimi", "SenseTime"], "alternates": {"html": "https://wpnews.pro/news/anthropic-says-china-based-operators-used-claude-to-copy-its-ai-track-dissidents", "markdown": "https://wpnews.pro/news/anthropic-says-china-based-operators-used-claude-to-copy-its-ai-track-dissidents.md", "text": "https://wpnews.pro/news/anthropic-says-china-based-operators-used-claude-to-copy-its-ai-track-dissidents.txt", "jsonld": "https://wpnews.pro/news/anthropic-says-china-based-operators-used-claude-to-copy-its-ai-track-dissidents.jsonld"}}