NSA, CISA and FBI advisory AA26-251A
Six Chinese AI firms run ‘industrial-scale’ distillation of Claude, GPT, Gemini and Grok
Confirmed
Importance: major (4 of 5)The takeaway
On Sept 8, 2026 the NSA, CISA and FBI issued a joint cybersecurity advisory (AA26-251A), “China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies”.
Status
- Claim
Confirmed
- Our reporting
- High confidence
- Importance
- Major (4 of 5)
- Last verified
- 10 October 2026
Your AI and this story
- GPT-6 Astra131 days after its cutoff
- Claude Opus 5.570 days after its cutoff
- Gemini 3.8 Flash161 days after its cutoff
- Grok 4.7100 days after its cutoff
None of these four assistants can know about it. The closest, Claude Opus 5.5, stops 70 days before it.
Key facts
- Alert code AA26-251A, released Sept 8, 2026; co-authored by NSA, CISA and FBI (PDF hosted on media.defense.gov)
- Firms named: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, Z.AI. Targets: variants of Claude, GPT, Gemini and Grok; activity since at least late 2024
- Key line: Chinese AI companies conduct ‘systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns’
- Says DeepSeek’s publicly cited $5.6M training cost is misleading because it leaves out the cost of the illicitly acquired data
- Per-firm detail (The Next Web, CyberScoop): Moonshot distilled 18 different US models for Kimi versions; MiniMax targeted Claude Code (chain-of-thought and RL data); Z.AI used GPT-5.5 and Claude Opus (billions of tokens by mid-2026); DeepSeek used distilled outputs as synthetic training data
- Techniques: fraudulent accounts, single accounts spread over many addresses, cloud and aggregator routing that strips metadata, grey-market API proxies (‘transfer stations’), jailbreak prompts to extract hidden chain of thought
- Mitigations: monitor subscription-to-usage ratios and new accounts that hit maximum usage at once; subtly alter outputs for suspected distillers; share intelligence across companies
- Attribution: the campaigns ran ‘likely with Chinese government awareness’ (hedged wording, per The Next Web). The Chinese Embassy’s Liu Chang called the allegations a ‘deliberate attack on China’s development in AI’ (via Bloomberg)
Show 1 more
- Followed by Anthropic’s Sept 10 threat intelligence report (seven firms; press tallied nearly 200M exchanges) and OpenAI’s Sept 30 report on a Moonshot campaign. Interesting Engineering re-reported the accusations on Oct 10, quoting investment manager Wang Zebin that Anthropic’s report ‘does not provide enough concrete examples to independently verify’ them
What happened
Three US security agencies published a joint advisory that treats model distillation by Chinese AI labs as a security threat to the US AI industry. It names six companies and the US model families they targeted, describes how they evaded detection, and tells US labs how to detect and blunt it. Anthropic published its own figures two days later, and China’s cyberspace regulator later opened a data-security probe into DeepSeek and Moonshot from the opposite angle.
Why it matters
Distillation moved from company terms-of-service complaints to a formal US government attribution. That supports export-control and policy action against Chinese labs and supports the argument that China’s low-cost frontier models depend on US model outputs. The advisory’s attribution to the Chinese government is hedged (“likely with ... awareness”).
Sources
6 sources from 6 sites. Numbers match the chips in the text.
6 sources: 2 primary, 4 press
Primary
- CISA: Cybersecurity Advisory AA26-251Acisa.gov, official
- Advisory PDF (media.defense.gov)media.defense.gov, official
Press
- CyberScoop: US accuses Chinese AI companies of distillationcyberscoop.com, press
- The Next Web: US intelligence advisory names six Chinese AI firms and lists the US models each one targetedthenextweb.com, press
- TechRadar: FBI, NSA warn Chinese AI companies like DeepSeek and Alibaba are carrying out industrial-scale distillationtechradar.com, press
- Interesting Engineering (Oct 10): Anthropic accuses Chinese AI firms of secretly using Claude to train their AI modelsinterestingengineering.com, press
Changes
- Filed (missed on Sept 8) from the CISA page, CyberScoop and The Next Web