Anthropic Threat Report Names Seven Chinese Labs Distilling Claude via Fake Accounts

Anthropic's September threat intelligence report, covering December 2025 through August 2026, is the company's most pointed public accounting of Claude misuse to date. It documents abuse across seven harm categories and, most controversially, names seven Chinese AI labs — Alibaba, DeepSeek, Moonshot, Xiaomi, Zhipu, SenseTime, and MiniMax — as having created thousands of fake accounts to harvest Claude outputs for model distillation, with roughly 151 million Claude exchanges attributed to Alibaba alone. Distillation, the practice of training a cheaper 'student' model on a stronger model's outputs, sits at the center of an escalating IP and data-privacy fight between US and Chinese labs.
Beyond distillation, the report catalogs harder-edged misuse: Claude was reportedly enlisted in Yemeni missile-guidance work and in a romance-scam operation spanning 4,700 fake profiles and 2.36 million messages. The recurring theme, echoed by developers, is that 'sophisticated attacks no longer require sophisticated attackers' — capable models lower the barrier to entry for fraud and weapons-adjacent work.
The report lands amid a charged geopolitical backdrop. China's state press blasted Anthropic's calls to slow AI as 'cold war tactics,' and the naming of specific labs drew both praise and accusations of politicizing safety research. It also arrives the same week a DeepSeek kernel engineer publicly compared letting Anthropic control AI to 'Hitler obtaining atomic bomb technology before the Allies,' underscoring how personal the lab rivalry has become.
What readers should watch: whether the named labs respond substantively or dismiss the findings, and whether regulators cite the report in distillation-related enforcement. Anthropic frames the disclosure as transparency; critics see selective attribution aimed at competitors. Either way, it hardens the narrative that frontier-model outputs are now a contested strategic resource.