← BACK TO FEED
DeepSeekmodel distillationAI securityChinaNSA

NSA, CISA and FBI: China Is Systematically Looting US AI Models at Industrial Scale

U.S. agencies including the NSA, CISA, and FBI have accused multiple China-based AI companies — including DeepSeek, Alibaba, and Moonshot AI — of conducting large-scale "distillation attacks" to systematically extract capabilities from American frontier AI models such as Claude, GPT, Gemini, and Grok. The companies allegedly bypassed geographic restrictions and terms of service using VPNs, obfuscated accounts, proxy networks, and third-party aggregators to harvest billions of tokens, significantly shortcutting their own AI development timelines and costs. U.S. agencies have recommended that AI companies implement stronger detection measures and coordinate across platforms to counter these distributed campaigns.

The NSA, CISA, and FBI have jointly accused multiple Chinese AI companies of running coordinated, large-scale distillation campaigns against US frontier AI models. The target list reads like a who's who of American AI: Anthropic's Claude, OpenAI's GPT, Google's Gemini, and xAI's Grok.

Distillation, for those unfamiliar, is a legitimate technique where a smaller model learns from a larger one. The problem isn't the method. It's the scale, the intent, and the fact that it's being done without authorisation, in violation of terms of service, and almost certainly with Chinese government backing.

The joint advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as the principal offenders. According to the agencies, these firms have collectively extracted billions of tokens across millions of requests since at least late 2024, using the distilled outputs to accelerate their own model development at a fraction of what legitimate training would cost.

The allegations get specific. DeepSeek apparently ran organised campaigns through mid-2025 targeting reasoning capabilities to build its R1 and V3 models. Moonshot AI reportedly extracted Claude Fable 5 data for Kimi-K3 and GPT-4o data for Kimi-K2. Alibaba allegedly distilled multiple Claude and GPT-5 variants to sharpen its models' software engineering and customer service capabilities. MiniMax is accused of pulling chain-of-thought reasoning from Claude, Gemini 1, and Gemini 2.5 Pro to improve its M2 model. StepFun reportedly hit an impressive range of Claude and GPT-5 variants between late 2025 and early 2026, targeting coding and agentic functions for its Step 4 model. And Z.AI allegedly distilled billions of tokens from GPT-5.5 and Claude Opus 4.8 to develop reasoning capabilities as recently as mid-2026.

US frontier models are officially unavailable in China, which means Chinese developers have had to get creative. The advisory describes a grey market of proxy services, obfuscated accounts, VPNs, and third-party API aggregators that relay requests through servers outside mainland China. Some of these services have reportedly been sold openly on Chinese marketplaces Taobao and Xianyu. Bold.

The operational approach is deliberately distributed. Companies spread requests across multiple platforms and providers to avoid triggering detection systems. They buy bulk premium subscriptions shared across developer teams to keep costs down and blend in with legitimate traffic. Advanced tactics include automated failover when one route gets blocked, chain-of-thought extraction, and quality evaluation frameworks designed to detect when a model is deploying countermeasures.

This isn't the first warning shot. Back in February, Anthropic publicly identified industrial-scale distillation campaigns by DeepSeek, Moonshot AI, and MiniMax targeting Claude. Google's Threat Intelligence Group chimed in this week, reporting a spike in distillation attacks against its own models, with some campaigns exceeding 100 million prompts and focusing on visual, audio, and video generation capabilities.

The agencies are now pushing US AI companies to implement better detection, subtly alter responses for suspected distillation attempts, and share intelligence across providers and platforms to expose distributed campaigns.

Arctic Wolf's Ismael Valenzuela framed it well: this is essentially distributed credential stuffing, but for model capabilities. The evasion tactics mirror what security teams already see in payment fraud and account abuse. The difference is the payload. Instead of stealing money, attackers are stealing the product itself, the reasoning, the fine-tuned behaviours, the proprietary optimisations that US companies have spent billions developing.

Valenzuela also flagged something businesses outside the frontier AI space might miss: if your organisation has API access to any of these models, your keys and service accounts are potential attack vectors. Abuse of that access looks identical to legitimate usage. That's not a frontier AI problem, that's everyone's problem.

READ NEXT
NSA, FBI and CISA Accuse Chinese AI Firms of Systematic Model Distillation at Industrial ScaleChina Claims US Firms Distil Its Models Too, As AI Trade War Rhetoric EscalatesAI Agents Are Eating Security Budgets — and CISOs Still Don't Have the Guardrails to Show for It