AI
Published 2026-09-09
Verified 2026-09-19

NSA/CISA/FBI: China AI firms distilled billions of tokens from Claude/GPT/Gemini/Grok

SecurityWeek (9 September 2026) summarises a joint NSA, CISA, and FBI warning that China-based AI companies — named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI — extracted billions of tokens across millions of exchanges from US frontier models (Claude, GPT, Gemini, Grok variants) since at least late 2024, described as systematic distillation with likely Chinese government awareness. Coverage maps TTPs to MITRE ATLAS and notes additional techniques outside that framework. iTnews and BleepingComputer carried the same agency warning the same day. This is official AI guidance / strategic warning, not a product CVE. UPDATE 11–12 September 2026 (Anthropic September 2026 TI, illicit distillation section): Anthropic says that since its February disclosure it identified and disrupted additional industrial-scale illicit distillation attacks against Claude from seven labs based in China, targeting generally available models (not Mythos-class). Distillation itself is a legitimate teacher/student training method; illicit distillation here means covert, fraud-enabled capability extraction (fake accounts, stolen cards/API keys). Aligns with the US agency warning’s China-lab theme; still not a product CVE. Primary remains the agency warning; Anthropic TI is confirmatory vendor telemetry.

Exploited in Australia?
unknown

Primary: SecurityWeek — US agencies frontier AI distillation (9 Sep 2026) · iTnews (9 Sep 2026); also BleepingComputer / THN

ai