Anthropic published a September 2026 threat intelligence report covering disrupted misuse of Claude from December 2025 through August 2026 across seven harm areas, including cyber operations and illicit distillation. In secondary coverage and Anthropic’s report framing, the company alleges large-scale distillation campaigns it attributes to China-based labs — including an Alibaba-linked effort Anthropic says involved about **151 million** exchanges — plus activity it links to Moonshot AI and DeepSeek. Those figures and attributions are **Anthropic’s claims**, not adjudicated court findings. Separately, Anthropic describes a shift from chatbot-style assistance toward more agentic cyber orchestration. This brief does **not** re-cover the Coxon resignation or Hubinger >10% risk comments already live on aishiftnews.ca.
Anthropic Accused DeepSeek Of Secretly Using Claude + 6 More Labs · Universe of AI
Quick Take
Anthropic’s September 2026 threat intelligence report says the company disrupted Claude misuse between December 2025 and August 2026 across seven harm areas. On distillation, Anthropic alleges industrial-scale campaigns it attributes to China-based labs — including an Alibaba-linked campaign Anthropic says involved more than 151 million exchanges — plus activity it links to Moonshot AI and DeepSeek. Treat those as company claims. On cyber, Anthropic argues AI use has moved toward multi-agent orchestration, not only chatbot Q&A.
What Anthropic published
Anthropic frames the report as case studies of notable misuse it says it identified and disrupted, then used to strengthen safeguards and share intelligence with partners where appropriate. The company lists seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Anthropic says Claude Haiku, Sonnet, and Opus appeared in the misuse cases it covers; it states Fable/Mythos-class models were generally not involved except in one distillation case.
Distillation allegations — attribute the numbers
Secondary coverage (TechCrunch, CNBC, and others) focuses on Anthropic’s illicit distillation section. According to those write-ups of Anthropic’s report:
- Anthropic says it observed on the order of ~200 million exchanges linked to distillation campaigns across named efforts.
- Anthropic attributes the largest campaign it measured to Alibaba-affiliated operators — more than 151 million exchanges between May and July 2026, peaking near 3 million per day across thousands of accounts, aimed at extracting reasoning traces useful for training (Anthropic links this to Qwen-family training in its narrative).
- Anthropic alleges Moonshot AI (Kimi) and DeepSeek ran campaigns that relayed or harvested exchanges at multi-million scale (coverage cites figures on the order of ~23 million for Moonshot over May–July and ~12 million for DeepSeek over a July window — again, Anthropic’s observation/attribution).
AI Shift News is not adjudicating whether those companies did what Anthropic claims. The reportable fact for this brief is: Anthropic published named attributions and scale estimates in a public threat report, and major tech press repeated them.
Agentic cyber vs chatbot assistance
In the cyber sections Anthropic surfaces publicly, the company argues that many operations went beyond single-turn assistance: multi-agent frameworks for reconnaissance, exploitation, and exfiltration, with humans often setting targets and reviewing loot. Anthropic also claims sophistication is a weaker attribution signal than it used to be because AI “uplifts” lower-resourced actors. Those are Anthropic’s analytical claims about its own casework — useful as a trend signal, not as a court record of every named GTG cluster.
What this brief is not
This package deliberately skips the Anthropic personnel / risk-forecast story already live on aishiftnews.ca (Coxon resignation; Hubinger-related probability comments). Readers who want that thread should use the existing posts; this brief stays on the September threat report and distillation/cyber themes.
Bottom Line
Anthropic says it disrupted a wide set of Claude misuse cases from late 2025 through mid-2026 and alleges large illicit distillation campaigns it attributes to Alibaba, Moonshot, DeepSeek, and other labs. Report the numbers and names as Anthropic’s claims, keep agentic-cyber framing hedged, and leave the Coxon/Hubinger coverage alone.
Sources
- https://www.anthropic.com/threat-intelligence-report-september-2026
- https://techcrunch.com/2026/09/10/anthropic-details-distillation-campaigns-from-alibaba-moonshot-ai-and-deepseek/
- https://www.cnbc.com/2026/09/11/chinese-ai-labs-moonshot-deepseek-alibaba-anthropic.html
- https://www.youtube.com/watch?v=KjdVyj1ruBE