Six Labs, Billions of Tokens: NSA, CISA and FBI Formally Accuse China's AI Firms of Industrial-Scale Model Distillation
Joint advisory AA26-251A names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, alleging they distilled billions of tokens from Claude, GPT, Gemini and Grok since late 2024 — and prescribes a quiet-poison playbook for defenders.
On September 8, 2026, the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the Federal Bureau of Investigation published a joint cybersecurity advisory that reads less like a routine threat bulletin and more like the formal opening of a new front in the technology contest between the United States and China. Designated AA26-251A, the advisory names six China-based AI companies — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI — and accuses them of conducting “aggressive, malicious, and targeted” knowledge distillation campaigns against U.S. frontier models since at least late 2024.
The core allegation is stark. According to the agencies, the distillation campaigns “form the core — not merely a supplement” of these companies’ AI development strategy. Likely with Chinese government awareness, the six firms are said to have extracted billions of tokens across millions of exchanges and requests from U.S. frontier models, including variants of Claude, GPT, Gemini, and Grok. The activity, the advisory states, violates the U.S. companies’ terms of use and directly threatens U.S. technological leadership.
What the advisory actually says
Knowledge distillation is a legitimate and widely used machine learning technique: train a smaller, less capable model on the outputs of a larger, more capable one. CISA’s accompanying announcement is careful to acknowledge this. The problem, in the government’s framing, is when the technique is used to acquire a competitor’s capabilities in less time and at less cost than developing them legitimately. “We strongly urge AI companies to take immediate steps to safeguard their platforms against knowledge distillation campaigns that threaten to close the gap in advancements made by American companies,” said CISA Acting Director Nick Andersen.
The advisory then walks through what each named company allegedly did:
- DeepSeek is described as running an organized distillation campaign since at least late 2024 to generate synthetic training data for its models, including R1. The agencies say DeepSeek targeted reasoning capabilities, specialized optimizations, and domain-specific functions to cut compute and research costs — and that the company’s famous $5.6 million training cost figure is misleading because it excludes the cost of data acquired through malicious distillation. Between late 2024 and mid-2025, DeepSeek allegedly distilled from Claude 3.7, Claude Sonnet 4, Claude Sonnet 4.5, Claude Opus 4.1, Gemini 2.5 Pro Preview, Gemini 2.5 Flash Preview, GPT-4, GPT-4o, GPT-4 Mini, GPT-4 Nano, GPT-5, and Grok 4 to train its R1 and V3 models.
- Moonshot AI is said to have run a widespread campaign since at least mid-2025, extracting significant Claude Fable 5 data to train Kimi-K3 and GPT-4o data for Kimi-K2, using millions of exchanges targeting agentic reasoning and tool use, coding and data analysis, computer-use agent development, and computer vision.
- Alibaba allegedly distilled Claude-4, Claude Opus, Claude Sonnet, and GPT-5 in late 2025 to improve software engineering, customer service dialogue, and image and character creation in its Qwen family.
- MiniMax is accused of distilling chain-of-thought reasoning, reinforcement learning, supervised fine-tuning, and software engineering capabilities for its M2 model from Claude Code, Claude Sonnet 4, Claude Opus, Gemini 1, Gemini 2.5 Pro, and Gemini 3 Pro — and of using Claude Code for internal software development, including prompt injections designed to trick Claude Code into believing it was a MiniMax product.
- StepFun allegedly distilled data from Claude Opus 4.1 and 4.5, Claude Sonnet 4.5, Claude Haiku 4.5, GPT-5 Mini, GPT-5 Pro, GPT-5.1, GPT-5.1 Codex, and GPT-5.2 between late 2025 and early 2026 to improve coding and agentic functions of its Step 4 model.
- Z.AI is said to have distilled billions of tokens of GPT-5.5 and Claude Opus 4.8 data by mid-2026 to develop chain-of-thought reasoning capabilities.
The tradecraft: transfer stations and sanitized metadata
For infrastructure watchers, the most interesting section of the advisory is its description of how the campaigns were run. The companies allegedly routed requests through native APIs, remote cloud providers, and third-party aggregators that obfuscate user metadata, and used a gray market of API proxies known as “transfer stations” to bypass geographic restrictions, evade safeguards, and undermine traceability. Cost savings reportedly came from bulk purchases of premium subscriptions shared across developer teams.
More advanced tactics include chain-of-thought reasoning extraction, automated failover between pathways when blocking attempts occurred, and quality evaluation frameworks built specifically to detect defensive countermeasures — a cat-and-mouse layer that implies the attackers were actively measuring whether they were being served degraded output.
The agencies mapped the activity to the MITRE ATLAS framework across adversary lifecycle phases from resource development through exfiltration, citing fraudulent account creation and jailbreak prompts that force models to reveal hidden chain-of-thought reasoning. DeepSeek reportedly employed prompts instructing models to “imagine and articulate the internal reasoning behind completed responses” — a technique for reconstructing the reasoning traces that frontier labs deliberately withhold from outputs. MiniMax, according to the advisory, redirected its exchanges to a new Claude model within 24 hours of its release.
Four techniques are described as novel: regional restriction evasion combined with subscription exploitation, centralized request routing infrastructure, automated request metadata sanitization, and systematic quota and cost optimization.
The defender’s playbook — including quiet poisoning
The recommended mitigations go well beyond “add rate limits.” The agencies urge three immediate actions: implement comprehensive detection of anomalous prompts, accounts, networks, and behaviors; deploy targeted response changes that subtly alter responses to suspected malicious distillation attempts; and establish cross-organization intelligence sharing across model providers, cloud platforms, and API aggregators.
That middle recommendation deserves attention. Response changes, the advisory says, can include differential privacy or serving downgraded models to suspected distillation requests — and companies should vary those changes across requests to complicate the attackers’ quality evaluation frameworks. Most strikingly, the advisory recommends against informing users suspected of malicious distillation when their responses are altered, while stating that AI safety researchers and third-party evaluators should be informed of model changes. In other words: quietly poison the well, but tell the safety community you are doing it.
The advisory also lists mitigations drawn from MITRE ATLAS — query rate limits, controls on access to production models, AI telemetry logging, output obfuscation, adversarial red teaming, model hardening, ensembles, and limits on the release of model artifacts — and cites NIST’s adversarial machine learning taxonomy, including differential privacy with its noise-versus-utility tradeoff.
Detection indicators are concrete enough for any provider to act on immediately: shared accounts used from multiple IP addresses and user agents, sustained around-the-clock usage without human variation, anomalous subscription-to-usage ratios, and brand-new subscriptions that immediately run at maximum usage.
Context: from rumor to doctrine
The U.S. government has been building toward this moment for over a year. A White House framing of adversarial distillation as a national-security concern, an IISS analysis of distillation attacks in the US–China contest in May, a State Department global warning about alleged Chinese AI theft in April, Treasury Secretary Scott Bessent’s July threat of sanctions against Chinese AI developers, and a deepening congressional investigation into PRC AI models have all pointed the same direction. What AA26-251A adds is specificity: named companies, named victim models, named techniques, and a named framework (MITRE ATLAS) for tracking what is effectively a new category of industrial espionage.
Two things make this advisory consequential beyond the attribution itself. First, the timing: it lands days before the first dedicated US–China AI safety dialogue of Trump’s second term, planned for mid-September and led by Scott Bessent, where Washington reportedly wants joint monitoring of AI-driven cyberattacks. The advisory hands negotiators a documented, attribution-backed grievance — and a preview of what “self-policing by labs,” one of the floated proposals, is supposed to prevent. Second, the operational detail: by publishing detection indicators and mitigation guidance, the agencies are effectively converting every U.S. frontier provider into a sensor in a collective defense architecture, calling for coordinated response across government, private industry, and allied nations. Industry disclosures cited in the advisory document proxy networks managing tens of thousands of fraudulent accounts simultaneously.
Whether the named companies or Beijing respond — and whether the advisory precedes sanctions under the authorities Bessent flagged in July — will define the next phase of this contest. For model providers, the message is that distillation defense is now a matter of national-security doctrine, not just terms-of-service enforcement. For everyone else, it is a reminder that the “open versus closed” model debate has quietly acquired a state-actor dimension: the gap being closed is not just commercial.
Sources
- [1] https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a
- [2] https://www.unite.ai/nsa-cisa-fbi-warn-china-based-ai-firms-distill-us-frontier-models/
- [3] https://www.wttlonline.com/stories/us-agencies-warn-of-chinese-efforts-to-copy-american-ai-models,15669
- [4] https://aiweekly.co/ai-news-today