Anthropic said the groups used networks of fake accounts, stolen credit cards and API keys to access Claude and extract capabilities including reasoning, coding and tool use.

The company said the largest campaign, linked to Alibaba-affiliated operators, generated around 151 million exchanges over three months. According to Anthropic, the activity peaked at about 3 million exchanges per day, making it the largest distillation attack it has measured.

Anthropic also alleged that Moonshot and DeepSeek secretly routed some customer requests to Claude through proxy services. Users were allegedly shown Claude generated responses while believing they were interacting with other AI models, allowing the exchanges to be collected for training rival systems.

The company said some of the captured conversations contained sensitive information belonging to individuals, multinational companies and state affiliated actors, raising concerns over user privacy.

Anthropic said the groups accessed Claude through proxy services and relay networks that created thousands of accounts using fake identities. It also alleged that some transcripts were obtained from third-party data resellers that stored user conversations without consent.

In response, Anthropic said it has banned reseller accounts and unverified users from restricted regions. The company has also changed how Claude handles its internal reasoning, saying it now provides summarized reasoning rather than exposing detailed internal reasoning, making stolen transcripts less useful for training.

The allegations come amid growing concerns in the AI industry over the unauthorized extraction of advanced AI capabilities and increasing competition between US and Chinese AI companies.