Case · DiggingBeagle record

Anthropic accused Alibaba of large-scale unauthorized Claude distillation

Anthropic accused operators affiliated with Alibaba and Qwen of conducting a covert model-distillation campaign against Claude between April 22 and June 5, 2026. Reuters reported more than 28.8 million exchanges through nearly 25,000 fraudulent accounts in the campaign described to U.S. senators. Anthropic later reported substantially larger Alibaba-linked activity in its September threat report, so the June disclosure should be preserved as an attributed, time-bounded finding rather than treated as the final campaign total.

First seen
Apr 22, 2026
Case kind
abuse
AI role
AGAINST AI · WITH AI
Claims
5

Reconstruction

Mechanism & boundary

  1. 01

    Create and operate fraudulent accounts

    The attributed operators distributed querying across a large account population.

    Boundary: account access / model service

  2. 02

    Query Claude at industrial scale

    The June disclosure reports tens of millions of exchanges through nearly 25,000 accounts.

    Boundary: model service / harvested outputs

  3. 03

    Collect model outputs

    Claude responses are treated as synthetic supervision or training material rather than ordinary end-user answers.

    Boundary: harvested outputs / downstream training data

  4. 04

    Use the harvested material for attributed distillation

    Anthropic attributes the operator network and intended capability transfer to Alibaba/Qwen; that attribution remains contested rather than independently adjudicated.

    Boundary: training data / attributed downstream model

Timeline

  1. Apr 22, 2026

    Reported campaign window begins

    activity

    Anthropic's June disclosure places the attributed account-farm activity from April 22 onward.

  2. Jun 5, 2026

    Reported June campaign window ends

    activity

    The time-bounded June disclosure ends the reported campaign window on June 5.

  3. Jun 10, 2026

    Anthropic describes the activity to U.S. senators

    report

    Anthropic's allegation and scale figures are described in its June 10 communication.

  4. Jun 24, 2026

    Reuters reports the allegation

    report

    Reuters reports roughly 28.8 million Claude exchanges through nearly 25,000 fraudulent accounts.

  5. Sep 10, 2026

    Anthropic reports larger Alibaba-linked activity

    followup

    The September threat report makes clear that the June figures are a time-bounded snapshot rather than a stable lifetime total.

Claims & evidence

reported findingsupported

Anthropic's later September 2026 reporting described much larger Alibaba-linked distillation activity, so the 28.8 million figure is a disclosure-specific lower snapshot rather than a stable lifetime total.

  • supports
    Countering misuse of AI: September 2026

    Locator: SRC-ANTHROPIC-TI-SEP10

    Anthropic's later September 2026 reporting described much larger Alibaba-linked distillation activity, so the 28.8 million figure is a disclosure-specific lower snapshot rather than a stable lifetime total.
reported findingsupported

Reuters reported Anthropic's allegation of about 28.8 million Claude exchanges through nearly 25,000 fraudulent accounts between April 22 and June 5, 2026.

reported findingsupported

Anthropic described the activity as unauthorized distillation: operators used fraudulent accounts to harvest Claude outputs in order to transfer capabilities into another model.

reported findingsupported

Reuters reported that the campaign described in Anthropic's June 10 letter operated from April 22 through June 5, 2026.

reported findingcontested

The operator attribution to Alibaba/Qwen is Anthropic's assessment and should remain attributed unless independently corroborated.

Implications

Large-scale model extraction is an abuse-detection problem at the service and identity-cluster level, not only a terms-of-service problem at the individual account level. Attribution and total-volume estimates must remain separate from the directly observed querying scale.

Controls & mitigations

  • Detect coordinated account farms and shared infrastructure rather than relying only on per-account rate limits.
  • Correlate high-volume, repetitive output-harvesting patterns across identities and sessions.
  • Preserve campaign-window measurements separately so later larger totals are not mechanically added to overlapping earlier snapshots.

What remains unknown

  • Alibaba had not publicly validated Anthropic's attribution in the June Reuters report.
  • The exact relationship between the June campaign population and Anthropic's larger September totals requires careful deduplication.

Cite this record

DiggingBeagle. “Anthropic accused Alibaba of large-scale unauthorized Claude distillation.” First seen Apr 22, 2026. https://diggingbeagle.com/cases/anthropic-accused-alibaba-of-large-scale-unauthorized-claude-distillation/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.