U.S. Agencies Accuse Six Chinese AI Firms of Siphoning Claude, GPT, Gemini and Grok
Set Trending Topics as a preferred source on Google.
The NSA, FBI and CISA say DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.ai extracted the capabilities of American frontier models at industrial scale. Beijing rejects the allegations.
The rise of China’s AI labs has caught a lot of people off guard. Models such as DeepSeek V4, Kimi K3 and Qwen sit close to the Silicon Valley frontier in benchmarks while costing a fraction to run. Washington now offers an explanation for that gap, one that recasts the Chinese catch-up as theft.
In a joint advisory (AA26-251A), the National Security Agency, the FBI and the Cybersecurity and Infrastructure Security Agency accuse six Chinese AI companies of systematically extracting capabilities from U.S. frontier models since at least late 2024 and folding them into their own systems. The named firms are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.ai. The targets: Claude from Anthropic, GPT from OpenAI, Gemini from Google and Grok from xAI. The campaigns were “aggressive, malicious and targeted,” according to the CISA advisory, and ran “likely with Chinese government awareness.” The agencies stop short of claiming direct state direction, and the wording looks carefully chosen.
What Each Company Is Accused Of
The advisory is unusually specific. DeepSeek allegedly harvested reasoning capabilities and domain knowledge for its R1 and V3 models. One aside deserves attention: the agencies note that the widely cited training budget of 5.6 million dollars leaves out the cost of the data acquired this way.
Moonshot AI is said to have pulled millions of interactions from Claude and GPT-4o for its Kimi models. Alibaba allegedly used Claude and GPT-5 output to sharpen software engineering and customer service capabilities in the Qwen family. MiniMax went after chain-of-thought and reinforcement learning data, and also attempted prompt injection against Claude Code. StepFun is accused of copying reasoning and coding capabilities, and Z.ai of extracting “billions of tokens” from GPT-5.5 and Claude Opus by the middle of this year.
Fake Accounts, Shared Subscriptions and Gray-Market Proxies
The technical picture the agencies paint is one of an organized supply chain. Requests were routed through bulk-created or purchased accounts, shared premium subscriptions, VPNs, cloud providers and so-called transfer stations, meaning API proxies that defeat geographic restrictions and usage limits. Some of that access is traded openly on Chinese marketplaces such as Taobao and Xianyu, the advisory says. Third-party aggregators stripped metadata to obscure where the traffic originated.
Through those accounts came “highly coordinated requests with identical or similar prompt texts,” in some cases running for days or months and reaching thousands to millions of requests per subject area. Operators added jailbreak prompts designed to make the models reveal their hidden reasoning chains, plus automated failover that switched to another route the moment one was blocked. According to the agencies, the attackers even ran their own evaluation frameworks to detect when a provider had quietly switched on countermeasures.
The Most Contentious Recommendation: Deliberately Worse Answers
For U.S. providers, the agencies recommend sharper behavioral and infrastructure-level detection: watch traffic more closely, throttle new accounts that immediately max out their limits, and correlate suspicious patterns across platforms.
The delicate part is what comes next. Rather than banning flagged accounts outright, the advisory suggests models should quietly modify their responses so the output becomes less accurate and more error-prone for suspected attackers. As Ars Technica points out, that carries an awkward cost: anyone misclassified as an attacker gets degraded answers with no way of knowing. For developers building production systems on these APIs, that is a hard risk to price in.
Beijing Pushes Back
The denial came quickly. Mao Ning, a spokesperson for the Chinese foreign ministry, said (via NBC News) that all parties should strengthen cooperation to ensure “an open, inclusive, beneficial and ethical development of AI for the good of humanity,” and that Washington should refrain from “groundless accusations.”
The timing is worth noting. The advisory lands alongside planned U.S.-China talks on AI security involving Treasury Secretary Scott Bessent, which gives the accusations the flavor of a negotiating position.
The Accusations Are Not New
The industry has been here before. Anthropic accused DeepSeek, Moonshot and MiniMax earlier this year of running more than 16 million queries against Claude through roughly 24,000 fraudulent accounts, and later leveled a similar charge at Alibaba’s Qwen involving 28.8 million interactions.
Judging the case is still tricky. Distillation is an ordinary machine learning method, and the usual condition is permission, as in Apple’s billion-dollar arrangement with Google. Meanwhile the models whose outputs now warrant protection were themselves trained on data nobody asked permission for. Even OpenAI CEO Sam Altman has waved the issue off recently, saying distillation does not crack his top ten list of worries.

