Anthropic Exposes Chinese AI Firms' Distillation Attacks on Claude

Anthropic has released a report detailing aggressive distillation attacks by Chinese AI firms, including Alibaba, Moonshot AI, and DeepSeek. These unauthorized campaigns aimed to extract internal reasoning data from Claude models to train their own systems. Alibaba executed the largest effort, running 151 million exchanges between May and July 2026 across 3,500 accounts. Moonshot AI routed nearly 300,000 requests over ten days, allegedly through a network linked to the Chinese military, targeting capabilities like coding and logical reasoning.

The same report finds that artificial intelligence has empowered small actors to perform complex cyber operations previously reserved for state teams. A Russian espionage campaign hit over 20 government and defense organizations in Ukraine and Europe. Additionally, Chinese undergraduates used AI to find more than a dozen zero-day vulnerabilities in a single month, while criminal groups dumped 2,100 cloud access tokens across 40 corporate tenants in just 34 hours.

Despite these security threats, companies struggle to implement AI messaging tools effectively. Experts warn that rushing adoption without addressing the human factor can erode trust in leadership. Meanwhile, Deloitte data shows only 49% of firms have a CISO, and just 21% feel their governance is ready, even as 80% of automation leaders plan to increase AI investment.

McKinsey research indicates that while AI coding tools speed up writing code, they often fail to deliver fast results in production due to missed business rules. Conversely, OpenAI recently announced that nearly 10,000 AI agents solved the Navier-Stokes case, demonstrating new capabilities in formal verification for smart contracts. However, security researchers from ESET discovered a GuardBreaker method where attackers use code comments to fool AI malware scanners, highlighting ongoing vulnerabilities.

Key Takeaways

  • Anthropic reports Alibaba ran 151 million exchanges to distill data from Claude models between May and July 2026.
  • Moonshot AI routed nearly 300,000 requests over ten days, allegedly via a network linked to the Chinese military.
  • AI enabled a Russian espionage campaign to hit over 20 government and defense organizations in Ukraine and Europe.
  • Chinese undergraduates used AI to find more than a dozen zero-day vulnerabilities in a single month.
  • Criminal groups dumped 2,100 cloud access tokens across 40 corporate tenants in just 34 hours using AI agents.
  • Only 49% of organizations currently have a Chief Information Security Officer according to a Deloitte survey.
  • Just 21% of companies feel their AI governance is ready despite 80% planning to increase investment.
  • McKinsey finds AI coding tools often fail in production due to missed business rules and security requirements.
  • OpenAI announced nearly 10,000 AI agents solved the Navier-Stokes case, advancing formal verification for smart contracts.
  • ESET researchers discovered the GuardBreaker attack method where code comments trick AI malware scanners.

Anthropic reports AI distillation attacks from Chinese firms

Anthropic released a report on Thursday detailing distillation attacks by Chinese AI companies including Alibaba, Moonshot AI, and DeepSeek. These unauthorized campaigns aimed to extract internal reasoning data from Claude models to train their own systems. Alibaba ran the largest effort with 151 million exchanges between May and July 2026 across 3,500 accounts. Moonshot AI routed nearly 300,000 requests over ten days, allegedly through a network linked to the Chinese military. The attacks targeted valuable capabilities like coding, data analysis, and logical reasoning within the models.

AI enables state hackers and criminals to launch complex attacks

A new Anthropic report finds that artificial intelligence has allowed small actors to perform cyber operations that once required skilled state teams. The report documents a Russian espionage campaign hitting over 20 government and defense organizations in Ukraine and Europe. It also describes Chinese undergraduates using AI to find more than a dozen zero-day vulnerabilities in a single month. Criminal groups like ShinyHunters used AI agents to dump 2,100 cloud access tokens across 40 corporate tenants in just 34 hours. One attacker stole over 300,000 national identity records from a North African government agency using AI tools.

Companies struggle to implement AI messaging tools effectively

Experts warn that companies rushing to adopt AI-powered messaging tools may ignore the human factor in their organizations. Selling an AI transformation that does not feel real to employees can deepen skepticism and erode trust in leadership. This issue highlights a gap between the hype of new technology and its practical application in daily work. The concern suggests that successful implementation requires more than just deploying new software.

Coxon warns AI builders fear technology could kill everyone

A video report features Coxon stating that some AI builders believe their technology could kill everyone. The warning highlights serious concerns about the potential risks associated with advanced artificial intelligence systems. This perspective suggests that the rapid development of AI brings significant dangers that creators are aware of.

HousingAI hires new sales head and researcher to expand team

HousingAI appointed Ben Yexley as Head of Sales and Chris Galley as Researcher to grow its social housing knowledge platform. Yexley will lead sales growth while working with housing associations and local authorities on AI adoption. Galley will oversee sector monitoring and manage the review processes for the platform's content. The company launched earlier this year to provide regulated guidance on housing laws and practices using curated data. These hires reflect a growing focus on evidence and source validation in regulated markets using generative AI.

Deloitte finds only 49% of firms have a CISO

A new Deloitte survey shows that only 49% of organizations currently have a Chief Information Security Officer. While 80% of automation leaders plan to increase AI investment, only 21% feel their governance is ready. The report highlights a gap where companies hire a CISO for the title but fail to fund the legal and compliance teams needed to manage real risks. Experts suggest merging cyber, compliance, and vendor risk into one process with clear owners to fix this issue.

McKinsey warns of productivity illusion in AI coding

McKinsey research shows that while AI coding tools speed up writing code, they often fail to deliver fast results in production. AI models frequently miss important business rules and security requirements, leading to more rework and hidden costs later. A property and casualty insurer successfully used AI to migrate legacy systems only because they provided full context about their architecture. Experts recommend embedding governance policies and ensuring reliable context from enterprise systems before using AI for code generation.

OpenAI math breakthrough exposes new crypto security risks

OpenAI recently announced that nearly 10,000 AI agents solved a complex math problem known as the Navier-Stokes case. This achievement demonstrates how AI can now handle formal verification, a process used to prove smart contracts are secure. The ability to automate these proofs could lower costs for DeFi protocols but shifts the security challenge to creating accurate specifications. Experts warn that the next test is whether these systems can produce proofs that humans can easily inspect.

Experts discuss growing fears about artificial intelligence

Tech experts Anthony Mongeluzo, Alex Holley, and Mike Jerrick discussed recent concerns about artificial intelligence on a Fox 29 broadcast. The conversation included a report where a researcher quit his job because he believes AI could kill humans within 10 years. The segment highlighted the intense debate surrounding the safety and future impact of advanced AI systems.

Hackers use code comments to fool AI malware scanners

Security researchers from ESET discovered a new attack method called GuardBreaker that tricks AI-based code scanners. Attackers from the group UAC-0099 added specific comments to malware code that force AI models to refuse analysis. These comments do not change how the malware works but successfully derail automated security tools. Experts advise that no single AI engine should decide if code is safe and recommend using multi-layered checks instead.

Sources

NOTE:

This news brief was generated using AI technology (including, but not limited to, Google Gemini API, Llama, Grok, and Mistral) from aggregated news articles, with minimal to no human editing/review. It is provided for informational purposes only and may contain inaccuracies or biases. This is not financial, investment, or professional advice. If you have any questions or concerns, please verify all information with the linked original articles in the Sources section below.

AI Distillation Attacks Chinese AI Companies Unauthorized Data Extraction Alibaba Moonshot AI DeepSeek AI Enabled Cyber Attacks Russian Espionage Campaign AI Vulnerability Discovery Criminal AI Activity AI Messaging Tools Implementation Employee Skepticism AI Transformation AI Risks AI Builders Concerns HousingAI Expansion AI Adoption in Social Housing CISO Role in Organizations AI Coding Tools AI Math Breakthrough Formal Verification AI Security Risks AI Debate AI Malware Detection GuardBreaker Attack

Comments

Loading...