They Thought They Were Writing to a Chinese Model. Claude Replied.
Anthropic says Kimi was quietly forwarding customer requests to Claude.

Someone asked for help tidying up a budget model before Thursday's review. The figures for four industrial sites were in it: Ho Chi Minh City, Kuala Lumpur, Bangkok, Ljubljana. Someone else pasted in the config for a broken notification bot, Telegram token and two live API keys included.
Both messages now sit, numbers and keys blacked out, in a public report Anthropic published on September 10. Neither person ever wrote to Anthropic. They were talking to a Chinese assistant.
Seven named labs, and numbers that belong to the accuser
The report, "Detecting and countering misuse of AI," covers December 2025 through August 2026 and accuses, in its own words, "seven labs based in China" of running distillation campaigns against Claude. In plain terms: running the American model at scale to harvest its answers and train their own on top of them.
The seven are Alibaba, Moonshot AI, DeepSeek, Zhipu (branded Z.ai outside China), Xiaomi, SenseTime, and MiniMax. Anthropic attributes to Alibaba a peak of nearly 3 million exchanges a day from more than 3,500 fraudulent accounts, and over 151 million exchanges between May and July alone.
One thing needs saying up front, because it shapes everything that follows. These numbers come from Anthropic's own internal logs. No outside party has audited them, the report doesn't mention referring anything to a regulator, and none of the seven companies is described as having been contacted for its side of the story. This is the meter reading supplied by the party that says it got robbed.
Two labs served up Claude without saying so
The scale of the harvesting isn't the most interesting part. The route the data took to get there is. Three of the seven labs fed Claude their own customers' conversations, and not in the same way.
Moonshot, the company behind Kimi, allegedly "silently forwarded customer requests to Claude, instead of processing them using Kimi," then displayed Claude's answers back to those same users. The report counts almost 300,000 customer requests relayed over ten days, routed through 5,380 fake accounts based mostly in Singapore and Japan.
DeepSeek reportedly did much the same, with a filter attached: it scanned incoming requests for specific strings to identify developers working from third-party coding tools, then rerouted those particular queries to Claude Opus. Anthropic counted more than 12.1 million exchanges over fourteen days in July.
Xiaomi didn't do that, and the distinction matters. Anthropic's investigation "did not indicate that Xiaomi used Claude's responses to serve its users." Instead, the phone maker recorded its own customers' conversations with its MiMo models, then replayed them through Claude afterward, purely to manufacture training data. More than 400,000 requests over twenty days.
A live login to a Russian government database, a municipal police file
What these relays dropped in Anthropic's lap goes well past a budget spreadsheet. On the DeepSeek side, the report describes requests from an IT worker at an agency tied to Russia's defense ministry that exposed live credentials for a government database. Elsewhere, engineers were building a tool for a Chinese municipal public-security bureau that cross-checked a person's movements against police records, indexed by national ID number.
On the Moonshot side, a user Anthropic assesses was "likely affiliated with the PLA" had Kimi analyze surveillance footage from hundreds of cameras across Chengdu. An engineer at a large Chinese state-owned company handed over internal code and live credentials while doing it. Anthropic's own line on that one: "The user had no way of knowing that their use of Kimi was being forwarded to Claude."
In total, Anthropic says it saw "names, email addresses, company data, and other sensitive data of hundreds of end users in at least a dozen languages" pass through this pipeline. Much of that traffic arrived via third-party routing services, the kind US and European developers use to hop between models. One more junction in a chain where, by this point, nobody is quite sure who's talking to whom.
Six names on September 8, seven on September 10
Two days before this report, the NSA, CISA, and the FBI put out a joint advisory on the same subject. It named six companies: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
The two lists don't match. Five names appear on both. StepFun, which the agencies name, is absent from Anthropic's report. Xiaomi and SenseTime, which Anthropic names, are absent from the agencies' advisory. Nobody seems to have flagged the gap.
The gap says something about who plays which role here. The agencies' advisory is specific about which models got copied, but it gives no volumes, no account counts, and never says where its information comes from. The document that actually shows its receipts belongs to the company claiming to be the victim. The regulator accuses without showing its work; the vendor shows its work, because it's the one holding the meter.
We went and read the terms of service
That leaves the question the report never asks: could these users have known? Anthropic writes that these practices are "likely inconsistent with privacy laws and the labs' own terms of service." So we checked.
DeepSeek's privacy policy from the period lists its recipients exhaustively: technical vendors, its own corporate group, business transactions, authorities. The only user-input sharing it describes involves keywords sent to a search engine. Nothing about routing a conversation to a foreign model provider.
Kimi's is even more explicit. Its current policy states that personal data is stored in China and won't leave the country without separate consent. Its official list of third-party recipients runs to roughly twenty entities: Tencent, Huawei, OPPO, vivo, China's telecom carriers, and on the Western side Google, Apple, and AppsFlyer.
Every one of them is listed for login, payment, or ad measurement. No model vendor appears anywhere, no clause anticipates a conversation being routed somewhere else. Two caveats apply: the policy we reviewed is dated late August 2026, after the period described here, and we couldn't locate terms specific to Xiaomi's MiMo API.
Who was supposed to tell them?
The report answers half the question. On Moonshot, Anthropic writes: "We do not know if Moonshot notified their customers that their requests were being rerouted to Anthropic and exposed to a third party." On its own conduct, it says nothing at all. Nowhere does the document state whether the people whose messages got reproduced were informed, or how their content came to be read in the first place.
Anthropic still draws a conclusion from the episode that reaches well past it: AI providers, it writes, will keep gaining visibility into real-world use "that even governments and intergovernmental organizations" don't have. It's written as an argument. It reads like a plain observation.
Topics covered:
Frequently asked questions
What is a distillation campaign against an AI model?
Were Kimi users' requests actually sent to Claude?
Did these labs' terms of service allow for that kind of transfer?
Why do the US agencies' list and Anthropic's list disagree?
Were the affected users ever told?

Katja Liersch
Co-founder & Journalist
Katja is a journalist and TV producer. With decades of experience in mainstream media, she brings to Declic Media the perspective of those discovering AI: curious, demanding and pragmatic. She ensures every piece of content truly speaks to everyone.
All articles by Katja →