Anthropic's threat report: 189.9m distilled exchanges, and two Chinese labs that relayed their own users to Claude
The September 10 report names seven China-based labs, a Russian espionage actor whose agents rebuilt malware until it went undetected, and customer data that reached Anthropic by accident.

Anthropic published its threat report on September 10 and put a figure on being copied: 189.9 million exchanges of illicit distillation across five measured campaigns, 151 million of them attributed to Alibaba's Qwen team between May and July, peaking near three million a day from more than 3,500 fraudulent accounts. Seven China-based labs are named since February. The report also describes a Russian espionage actor whose AI agents rebuilt its malware, unsupervised, until the security products stopped flagging it.
That total is the number the wires led with.
It is probably the least interesting thing in the document.
Here is what almost nobody pulled out. Anthropic says Moonshot and DeepSeek were not merely harvesting Claude — they were quietly serving Claude to their own paying customers, who believed they were talking to Kimi and to DeepSeek. Over one ten-day stretch Moonshot relayed almost 300,000 customer requests to Anthropic through 5,380 fraudulent accounts (mostly, on the account metadata, in Singapore and Japan).
So what does that mean for the customer at the other end?
It means their prompts went to an American company. Anthropic lists some of what arrived: a user it assesses was likely PLA-affiliated, loading CCTV footage from hundreds of cameras in Chengdu — including cameras outside PLA facilities — and asking whether a tracked individual was "behaving abnormally". Engineers at a Chinese state-owned enterprise pasting in live credentials. Engineers building a case-management tool for a municipal Public Security Bureau that compares a person's movements against police records by national ID number. And, through DeepSeek, an IT operator handling data from a Russian government agency tied to its defence ministry, whose relayed requests exposed live credentials for a Russian government database.
Two Chinese labs appear to have spent the spring turning themselves into an intelligence feed for a company in San Francisco.
Not on purpose. That is arguably worse.
Now the Russian case, which is the one a security team should read twice. Anthropic designates it GTG-20006 (their internal label for an actor abusing AI, not a public one) and says the attribution is consistent with public reporting linking the actor to Midnight Blizzard; one operator used the handle "JackPoterz". The toolkit was ordinary enough — two families of Windows implants, a mobile exploitation kit, a browser credential stealer, a phishing platform, an admin console. The loop around it was not.
If their monitoring AI agents identified that any of their deployed malware was detected by a security product, agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections. The agents were designed to continue iterating on GTG-20006's toolkit until it was undetected.
More than 20 organisations sat in the actor's planning, reconnaissance or live operations: ministries, defence and intelligence bodies, embassies, think tanks, defence-industrial firms, concentrated in Ukraine and Europe. They bulk-exported the mailboxes of at least two drone component makers and stole a complete software development kit for a drone vision system (the manufacturers are not named), then spent days reverse-engineering it down to the bill of materials and an unannounced product. To reach indirect targets they compromised three vendors running hotel guest WiFi and rewrote DNS records, so a traveller connecting from a lobby handed over their traffic and device identifier.
Our read is that the distillation figures are the part built to be quoted and the detection loop is the part that changes anyone's Monday. Static signatures have been the economic backbone of endpoint security: a defender writes one, and the attacker pays in labour to route around it. An agent that rebuilds a binary until it comes back clean charges that cost to an API meter instead. Anthropic's own line — that sophistication has stopped being a reliable signal of who is behind an operation — is the sentence security vendors will spend a year arguing with. We would expect at least one major endpoint vendor to publish evasion telemetry showing a step change in unique hashes per campaign before the end of the first quarter of 2027. If that data comes back flat, this was a capability demonstration rather than a shift, and we will say so.
You should be sceptical of parts of this, and the reasons deserve saying out loud. Anthropic is grading its own homework, naming commercial rivals on evidence it does not show, in a week when its own safety record is the subject of a viral resignation. No methodology accompanies the attribution of an account cluster to a named company. The distillation section also doubles as an argument for export policy, and Anthropic surely knows it.
Two things pull the other way. Google published an adversarial-distillation threat tracker earlier this year and OpenAI has made the same complaint since early 2025, so this is not one vendor's invention. And the relay findings are the rare accusation the accused party's own customers can check: if you ran a Kimi or DeepSeek session through a coding harness this summer, where your tokens actually went is now a live question, and neither company has answered it.
The report's own footnote is the sharpest bit. A proxy platform serving virologists, blocked by Anthropic's biosecurity classifier while helping draft a chikungunya gain-of-function grant, built a fallback that forwarded refused prompts to a competitor's model. Safety, at that point, is a routing decision made by somebody else.

