{"schema":"postcutoff/event@1","as_of":"2026-10-10T23:43:00+02:00","url":"https://postcutoff.com/e/2026-09-08-nsa-cisa-fbi-advisory-chinese-ai-distillation/","md":"https://postcutoff.com/e/2026-09-08-nsa-cisa-fbi-advisory-chinese-ai-distillation/index.md","disclosure":{"written_by":"AI agents (Claude Opus 5.5 in Claude Code)","editor":"Adam Bicz","policy":"https://postcutoff.com/about/"},"license":null,"id":"2026-09-08-nsa-cisa-fbi-advisory-chinese-ai-distillation","date":"2026-09-08","date_precision":"day","short_title":"NSA, CISA and FBI advisory AA26-251A","deck":"Six Chinese AI firms run 'industrial-scale' distillation of Claude, GPT, Gemini and Grok","takeaway":"On Sept 8, 2026 the NSA, CISA and FBI issued a joint cybersecurity advisory (AA26-251A), \"China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies\".","category":"policy-safety","category_label":"Policy & safety","importance":4,"confidence":"high","status":{"key":"confirmed","labels":["Confirmed"]},"sources":[{"n":1,"title":"CISA: Cybersecurity Advisory AA26-251A","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a","type":"official","group":"primary","domain":"cisa.gov"},{"n":2,"title":"Advisory PDF (media.defense.gov)","url":"https://media.defense.gov/2026/Sep/08/2003992823/-1/-1/1/CSA_CHINA_BASED_AI_COMPANIES_MALICIOUS_DISTILLATION_AGAINST_US.PDF","type":"official","group":"primary","domain":"media.defense.gov"},{"n":3,"title":"CyberScoop: US accuses Chinese AI companies of distillation","url":"https://cyberscoop.com/us-accuses-chinese-ai-companies-distillation/","type":"press","group":"press","domain":"cyberscoop.com"},{"n":4,"title":"The Next Web: US intelligence advisory names six Chinese AI firms and lists the US models each one targeted","url":"https://thenextweb.com/news/nsa-fbi-cisa-advisory-chinese-ai-distillation","type":"press","group":"press","domain":"thenextweb.com"},{"n":5,"title":"TechRadar: FBI, NSA warn Chinese AI companies like DeepSeek and Alibaba are carrying out industrial-scale distillation","url":"https://www.techradar.com/pro/security/fbi-nsa-warn-chinese-ai-companies-like-deepseek-and-alibaba-are-reportedly-carrying-out-industrial-scale-distillation-campaigns-to-boost-their-models","type":"press","group":"press","domain":"techradar.com"},{"n":6,"title":"Interesting Engineering (Oct 10): Anthropic accuses Chinese AI firms of secretly using Claude to train their AI models","url":"https://interestingengineering.com/ai-robotics/anthropic-accuses-chinese-ai-firms","type":"press","group":"press","domain":"interestingengineering.com"}],"official":2,"filed":"2026-10-10","updated":"2026-10-10","orgs":["NSA","CISA","FBI","DeepSeek","Moonshot AI","Alibaba","MiniMax","StepFun","Z.AI"],"title":"NSA, CISA and FBI advisory AA26-251A: six Chinese AI firms run 'industrial-scale' distillation of Claude, GPT, Gemini and Grok","summary":"On Sept 8, 2026 the NSA, CISA and FBI issued a joint cybersecurity advisory (AA26-251A), \"China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies\". It names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI and says that since late 2024 they extracted billions of tokens across millions of requests from variants of Claude, GPT, Gemini and Grok. It calls distillation \"the core—not merely a supplement—of their AI development strategy\" and gives labs detection and mitigation advice. It was the first formal US government attribution of model distillation to named Chinese companies, two days before Anthropic's own threat report on the same campaigns.","key_facts":["Alert code AA26-251A, released Sept 8, 2026; co-authored by NSA, CISA and FBI (PDF hosted on media.defense.gov)","Firms named: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, Z.AI. Targets: variants of Claude, GPT, Gemini and Grok; activity since at least late 2024","Key line: Chinese AI companies conduct 'systematic extraction of proprietary functionalities and capabilities of U.S. AI companies' models through industrial-scale knowledge distillation campaigns'","Says DeepSeek's publicly cited $5.6M training cost is misleading because it leaves out the cost of the illicitly acquired data","Per-firm detail (The Next Web, CyberScoop): Moonshot distilled 18 different US models for Kimi versions; MiniMax targeted Claude Code (chain-of-thought and RL data); Z.AI used GPT-5.5 and Claude Opus (billions of tokens by mid-2026); DeepSeek used distilled outputs as synthetic training data","Techniques: fraudulent accounts, single accounts spread over many addresses, cloud and aggregator routing that strips metadata, grey-market API proxies ('transfer stations'), jailbreak prompts to extract hidden chain of thought","Mitigations: monitor subscription-to-usage ratios and new accounts that hit maximum usage at once; subtly alter outputs for suspected distillers; share intelligence across companies","Attribution: the campaigns ran 'likely with Chinese government awareness' (hedged wording, per The Next Web). The Chinese Embassy's Liu Chang called the allegations a 'deliberate attack on China's development in AI' (via Bloomberg)","Followed by Anthropic's Sept 10 threat intelligence report (seven firms; press tallied nearly 200M exchanges) and OpenAI's Sept 30 report on a Moonshot campaign. Interesting Engineering re-reported the accusations on Oct 10, quoting investment manager Wang Zebin that Anthropic's report 'does not provide enough concrete examples to independently verify' them"],"key_numbers":[],"tags":["distillation","china","us-government","cybersecurity-advisory","model-theft","deepseek","moonshot","alibaba","minimax","stepfun","zhipu"],"science":null,"body_md":"## What happened\n\nThree US security agencies published a joint advisory that treats model distillation by Chinese AI labs as a security threat\nto the US AI industry. It names six companies and the US model families they targeted, describes how they evaded detection, and\ntells US labs how to detect and blunt it. Anthropic published its own figures two days later, and China's cyberspace regulator later\nopened a data-security probe into DeepSeek and Moonshot from the opposite angle.\n\n## Why it matters\n\nDistillation moved from company terms-of-service complaints to a formal US government attribution. That supports export-control and\npolicy action against Chinese labs and supports the argument that China's low-cost frontier models depend on US model outputs. The\nadvisory's attribution to the Chinese government is hedged (\"likely with ... awareness\").","disputed":[],"related":[{"id":"2026-09-30-openai-moonshot-distillation-campaign","url":"https://postcutoff.com/e/2026-09-30-openai-moonshot-distillation-campaign/","date":"2026-09-30","date_precision":"day","short_title":"OpenAI says Moonshot AI-linked individuals ran a coordinated campaign to extract its models' hidden reasoning","deck":null,"takeaway":"Hidden chains of thought are a main competitive asset and a safety-monitoring surface.","category":"policy-safety","category_label":"Policy & safety","importance":3,"confidence":"high","status":{"key":"confirmed","labels":["Confirmed"]},"sources":11,"official":2,"filed":"2026-09-30","updated":"2026-10-04","orgs":["OpenAI","Moonshot AI"]},{"id":"2026-09-22-china-cac-probes-deepseek-moonshot-claude-leaks","url":"https://postcutoff.com/e/2026-09-22-china-cac-probes-deepseek-moonshot-claude-leaks/","date":"2026-09-22","date_precision":"day","short_title":"China's cyberspace regulator probes DeepSeek and Moonshot over possible data leaks to Anthropic via Claude","deck":null,"takeaway":"Distillation from US frontier models, long treated in the US as IP theft and an export-control issue, now carries regulatory risk inside China too.","category":"policy-safety","category_label":"Policy & safety","importance":3,"confidence":"medium","status":{"key":"partly","labels":["Partly confirmed"]},"sources":4,"official":0,"filed":"2026-09-29","updated":"2026-09-29","orgs":["Cyberspace Administration of China","DeepSeek","Moonshot AI","Anthropic"]},{"id":"2026-09-10-anthropic-threat-intelligence-report-sept-2026","url":"https://postcutoff.com/e/2026-09-10-anthropic-threat-intelligence-report-sept-2026/","date":"2026-09-10","date_precision":"day","short_title":"Anthropic report details AI-orchestrated cyberattacks and distillation by Chinese labs","deck":null,"takeaway":"It documents the move from AI-assisted to AI-orchestrated attacks, and it treats distillation of frontier models as a security threat on a par with cyber misuse.","category":"policy-safety","category_label":"Policy & safety","importance":3,"confidence":"medium","status":{"key":"partly","labels":["Partly confirmed"]},"sources":10,"official":2,"filed":"2026-09-29","updated":"2026-10-09","orgs":["Anthropic"]},{"id":"2026-06-24-anthropic-accuses-alibaba-qwen-distillation","url":"https://postcutoff.com/e/2026-06-24-anthropic-accuses-alibaba-qwen-distillation/","date":"2026-06-24","date_precision":"day","short_title":"Anthropic tells US senators and the White House that Alibaba's Qwen lab ran the largest known distillation campaign on Claude (28.8M exchanges)","deck":null,"takeaway":"It moved the distillation dispute from blog posts to Congress and put Alibaba, China's biggest open-weights lab, at its centre.","category":"policy-safety","category_label":"Policy & safety","importance":3,"confidence":"medium","status":{"key":"partly","labels":["Partly confirmed"]},"sources":10,"official":0,"filed":"2026-10-04","updated":"2026-10-04","orgs":["Anthropic","Alibaba"]},{"id":"2026-02-23-anthropic-distillation-attacks-report","url":"https://postcutoff.com/e/2026-02-23-anthropic-distillation-attacks-report/","date":"2026-02-23","date_precision":"day","short_title":"Anthropic accuses DeepSeek, Moonshot and MiniMax of 'distillation attacks'","deck":"16M+ Claude exchanges via ~24,000 fraudulent accounts","takeaway":"\"Distillation attacks\" became a named security and policy issue in 2026.","category":"policy-safety","category_label":"Policy & safety","importance":3,"confidence":"high","status":{"key":"confirmed","labels":["Confirmed"]},"sources":3,"official":1,"filed":"2026-10-04","updated":"2026-10-04","orgs":["Anthropic","DeepSeek","Moonshot AI","MiniMax"]}],"people":[],"posts":[],"videos":[],"models":[],"changes":[{"date":"2026-10-10","type":"filed","text":"Created (missed on Sept 8) from the CISA page, CyberScoop and The Next Web"}],"provenance":{"agents":[{"model":"Claude Opus 5.5","maker":"Anthropic","tool":"Claude Code"}],"filed":"2026-10-10","run":null,"sources_read":null,"updated":"2026-10-10","human_review":null,"version":null},"gaps":[{"model_id":"gpt-6-astra","name":"GPT-6 Astra","cutoff":"2026-04","days_after":131,"in_training_data":false},{"model_id":"claude-opus-5-5","name":"Claude Opus 5.5","cutoff":"2026-06","days_after":70,"in_training_data":false},{"model_id":"gemini-3-8-flash","name":"Gemini 3.8 Flash","cutoff":"2026-03","days_after":161,"in_training_data":false},{"model_id":"grok-4-7","name":"Grok 4.7","cutoff":"2026-05","days_after":100,"in_training_data":false}],"short_url":"https://postcutoff.com/s/nsa-cisa-fbi-advisory"}