ZeroHour
Story · 1 source · 1 articlefirst updated ()

CISA, NSA and FBI: Six Chinese AI Firms Ran Industrial-Scale Distillation of US Frontier Models

highAI safety & securityexploited in the wildimportance 84
What's new: First merged summary for this story: the joint CISA-NSA-FBI advisory published September 9, 2026 is new, publicly naming six Chinese AI firms for alleged government-aware, industrial-scale distillation of US frontier models since late 2024 and challenging DeepSeek's $5.6 million training-cost claim.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

A joint CISA, NSA and FBI advisory accuses DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI of extracting billions of tokens from US frontier models (Claude, GPT, Gemini, Grok) via API abuse since at least late 2024, likely with Chinese government…

A joint CISA, NSA and FBI advisory accuses six China-based AI firms — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI — of industrial-scale knowledge distillation campaigns that extracted billions of tokens from US frontier models, including Anthropic's Claude, OpenAI's GPT-4/GPT-5, Google's Gemini and xAI's Grok (Grok 4), via millions of API requests since at least late 2024. The agencies assess the campaigns likely had Chinese government knowledge, represent a core development strategy for the firms, and pose a strategic economic threat to US technological leadership. The distilled data aided DeepSeek's R1 and V3 and Moonshot's Kimi-K2/K3 models; DeepSeek reportedly ran an organized campaign against Claude, GPT and Gemini between late 2024 and mid-2025, and Z.AI distilled GPT-5.5 and Claude Opus 4.8 for chain-of-thought reasoning. Tactics included gray-market API proxy 'transfer stations,' fraudulently procured premium account pools, proxy routing, automated provider failover, request metadata sanitization, and prompt injection — including an alleged MiniMax injection that made Claude Code believe it was a MiniMax product. TTPs are mapped to MITRE ATLAS with additional novel techniques. The agencies challenge DeepSeek's reported $5.6 million training cost and recommend identity verification, behavioral and usage monitoring, differential privacy, response variation or silent degradation of responses to suspected distillers, targeted cost-imposing responses, and indicator sharing, while cautioning these mitigations could frustrate legitimate users.

  • Advisory issued jointly by CISA, NSA and FBI; reported September 9, 2026.
  • Six named China-based firms: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI.
  • Billions of tokens extracted across millions of API requests since at least late 2024.
  • Targeted US frontier models: Claude (Anthropic), GPT-4/GPT-5 (OpenAI), Gemini (Google) and Grok 4 (xAI).
  • Z.AI allegedly distilled data from GPT-5.5 and Claude Opus 4.8 for chain-of-thought reasoning.
  • Extracted data aided training of DeepSeek R1 and V3 and Moonshot Kimi-K2/K3.
  • DeepSeek allegedly ran an organized campaign against Claude, GPT and Gemini between late 2024 and mid-2025.
  • Moonshot allegedly redirected extraction to a newly launched Claude model within 24 hours of release.

Coverage timeline

  1. · 7d ago
    Help Net Security· 70
    Chinese AI firms are siphoning capabilities from American models, CISA warns

    CISA, NSA and FBI warn Chinese AI firms including DeepSeek and Moonshot AI extracted billions of tokens from US frontier models via distillation campaigns.