Anthropic's campaign against what it calls the illicit distillation of its Claude models has moved onto new terrain. In an interview with CNBC published on 3 September 2026, Jacob Klein, the company's head of threat intelligence, said there is "an entire illicit ecosystem to try to gain access to Claude and other models", one that relies on fraud and, in part, on dark web marketplaces trading stolen credit card data and compromised AI accounts.
The allegation
Klein said foreign adversaries are querying Claude at industrial scale and using the answers to train competing systems, a process known as distillation, then selling the resulting models more cheaply. He acknowledged that distillation can be lawful when done with permission and within intellectual property and export control rules, but said that is not what Anthropic believes is happening. "I think competition is great," he said. "The concern here is if you are taking our model, distilling it through fraudulent means, creating millions of fake accounts using stolen credit cards and stolen infrastructure, to then produce a model that doesn't have safeguards in place."
Anthropic has singled out Moonshot AI, alleging that its Kimi K3 model, which launched in July 2026 and has been widely adopted in Silicon Valley, was illegally trained on the newest version of Claude. Earlier in 2026 it made similar allegations against DeepSeek and MiniMax, and it has separately accused Alibaba of a massive "distillation attack" against Claude. OpenAI and Google have published reports describing comparable activity against their own models.
The dark web plumbing
According to Klein, access at this scale depends on identity fraud. Companies such as Moonshot are, in his words, "spinning up tens of thousands, if not hundreds of thousands of fraudulent accounts", using payment details and accounts traded illicitly. Cybersecurity experts told CNBC the problem extends beyond China to Iran, Russia and North Korea, where the labs themselves block access to Claude, Gemini and ChatGPT because of sanctions. Once inside, operators ask thousands rather than dozens of questions and harvest the outputs to train what practitioners call a "student" model. Klein conceded this produces a whack-a-mole problem for defenders. "It's very hard to fully stop this as a problem, but I think slowing it down is good and worthwhile," he said.
Why detection is hard
Travis Lanham, technology chief at cybersecurity firm Armadin and a former Google engineer, told CNBC that abusive traffic blends in because the major labs serve billions of requests and face commercial pressure to keep platforms as accessible as possible while racing rivals. "The millions are relatively small compared to everything," he said, describing the activity as "sneaking in and trying to look like the rest of the crowd".
Policy backdrop
The claims arrive at a sensitive time for Anthropic, which CNBC has reported is valued at close to $1 trillion and could go public as soon as October 2026. In an April 2026 memo, the Trump administration called distillation that undermines American research and proprietary information "unacceptable" and said it would explore "a range of measures to hold foreign actors accountable". Klein also raised national security concerns, citing surveillance and possible use of distilled models in a biological weapons programme, and described what he called a specific campaign by a China-based entity conducting espionage at scale through Anthropic's technology. The CNBC report contains no public evidence for that campaign.
What is established and what is merely claimed
Established: Anthropic has publicly accused Moonshot, DeepSeek, MiniMax and Alibaba of illicitly distilling Claude; its threat intelligence chief says fraudulent accounts are being created at scale, partly via dark web marketplaces; OpenAI and Google report similar activity against their models; the US government has labelled such distillation "unacceptable"; and Kimi K3 has been widely adopted in the United States at a lower price point. Merely claimed: that Kimi K3 was trained on Claude, that Alibaba carried out a "distillation attack", that the named labs themselves operate the fraudulent accounts, and that a China-based entity ran an espionage campaign through Anthropic's systems. None of the four Chinese labs responded to CNBC's requests for comment, and no court or regulator has ruled on any of the allegations.