Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [incident, china, ai, distillation, state-sponsored, espionage] ยท confidence: high ยท affected_sectors: [technology, government, research] ยท au_impact: true

In a joint advisory released 8 September 2026, CISA, the NSA and the FBI assessed that six Chinese AI companies โ€” DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI โ€” have conducted industrial-scale knowledge-distillation campaigns against US frontier AI models (Claude, GPT, Gemini, Grok) since at least late 2024, extracting billions of tokens across millions of requests. The agencies said the firms distributed requests across fraudulent or shared accounts, API aggregators, cloud services and proxy "transfer stations" to bypass geographic restrictions, usage limits and detection, with some prompts attempting to expose restricted chain-of-thought reasoning. The operation was assessed as likely conducted with Chinese government awareness and as a core element of China's AI development strategy.

Attribute Detail
Date Since late 2024; disclosed 2026-09-08
Type Industrial-scale AI model knowledge distillation / IP theft
Actors DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, Z.AI (China)
Targets US frontier AI models (Anthropic, OpenAI, Google, xAI)
Source CISA/NSA/FBI joint advisory โ€” Tier 1/4

The advisory urged frontier firms to implement detection and mitigation (monitoring subscription-to-usage ratios and anomalous account behaviour), subtly degrade responses to suspected distillation attempts, and share intelligence across model providers, cloud platforms and aggregators.

Source