Case · DiggingBeagle record

Anthropic says PRC labs relayed user prompts to Claude for distillation, exposing sensitive data

Anthropic reported that several PRC AI labs covertly relayed user requests to Claude as part of distillation pipelines. In some cases users believed they were interacting with another model while their prompts were forwarded to Anthropic; relayed traffic included sensitive corporate, personal and government-related data. Anthropic attributed examples to Moonshot, DeepSeek and Xiaomi.

Evidence boundary

An explicit boundary statement has not yet been recorded. The evidence ledger defines what can be supported.

Assessment profile

How to read this
Setting
allegation
Exploitation
not established
Impact
Unassessed
Evidence
U - unassessed
Remediation
unknown
AI role
AGAINST AI / WITH AI
Basis and provenance

The provider-attributed prompt relay and data exposure remain contested in the record; source-ID-only locators and unestablished user notifications prevent stronger evidence/exploitation grading. Assessment is a desk review of the retained canonical Claims and cited Source metadata at their recorded cutoff, not a new external verification. Impact remains ungraded. Stored evidence uses source-level locators; passage-level corroboration remains required.

Assessed Sep 24, 2026 using diggingbeagle.assessment/1.

These dimensions are not combined into a threat score. An evidence grade does not establish exploitation or likelihood.

30-second account

Mechanism and trust boundary

Typed chronology

No typed chronology has been recorded. Dates are not inferred from the title or the Release build.

Claims & evidence

7 independently addressable Claims. Expand a Claim to inspect support, contradiction and scope.

CLM-DATAAnthropic says relayed sessions contained sensitive corporate and government-related information, including live credentials in at least one Russian government example.supported

Basis: reported finding

  • supports
    Countering misuse of AI: September 2026primary

    SRC-ANTHROPIC-TI-SEP10

    Anthropic says relayed sessions contained sensitive corporate and government-related information, including live credentials in at least one Russian government example.
Permanent Claim anchor
CLM-LIMITThese are Anthropic threat-intelligence attributions; the affected labs' user-notification practices and full data-retention behavior are not independently established.contested

Basis: reported finding

  • supports
    Countering misuse of AI: September 2026primary

    SRC-ANTHROPIC-TI-SEP10

    These are Anthropic threat-intelligence attributions; the affected labs' user-notification practices and full data-retention behavior are not independently established.
Permanent Claim anchor
CLM-PROXYAnthropic described transfer-station/proxy networks using fraudulent identities, payment methods, credentials and API keys to reach Claude from restricted regions.supported

Basis: reported finding

  • supports
    Countering misuse of AI: September 2026primary

    SRC-ANTHROPIC-TI-SEP10

    Anthropic described transfer-station/proxy networks using fraudulent identities, payment methods, credentials and API keys to reach Claude from restricted regions.
Permanent Claim anchor
CLM-RELAYAnthropic reports that several PRC labs relayed/replayed their users' prompts to Claude as part of distillation workflows.supported

Basis: reported finding

  • supports
    Countering misuse of AI: September 2026primary

    SRC-ANTHROPIC-TI-SEP10

    Anthropic reports that several PRC labs relayed/replayed their users' prompts to Claude as part of distillation workflows.
Permanent Claim anchor
CLM-PRIVACYAnthropic said relayed sessions exposed names, contact data, company information, credentials and other sensitive material from hundreds of end users across at least a dozen languages.supported

Basis: reported finding

  • supports
    Countering misuse of AI: September 2026primary

    SRC-ANTHROPIC-TI-SEP10

    Anthropic said relayed sessions exposed names, contact data, company information, credentials and other sensitive material from hundreds of end users across at least a dozen languages.
Permanent Claim anchor
CLM-DEEPSEEKAnthropic reported more than 12.1 million DeepSeek-attributed exchanges over 14 days in July 2026, including relayed requests containing sensitive enterprise and government information.supported

Basis: reported finding

  • supports
    Countering misuse of AI: September 2026primary

    SRC-ANTHROPIC-TI-SEP10

    Anthropic reported more than 12.1 million DeepSeek-attributed exchanges over 14 days in July 2026, including relayed requests containing sensitive enterprise and government information.
Permanent Claim anchor
CLM-MOONSHOTAnthropic said Moonshot silently forwarded customer requests to Claude and, during one ten-day period, relayed nearly 300,000 customer requests through 5,380 fraudulent accounts.supported

Basis: reported finding

  • supports
    Countering misuse of AI: September 2026primary

    SRC-ANTHROPIC-TI-SEP10

    Anthropic said Moonshot silently forwarded customer requests to Claude and, during one ten-day period, relayed nearly 300,000 customer requests through 5,380 fraudulent accounts.
Permanent Claim anchor

Implications within the documented scope

Controls and mitigations

No controls or verified fix are recorded.

Unknowns and contradictions

  • Exact number of unique users whose data reached Claude is not disclosed.
  • Whether every affected user was notified by the originating lab is unknown.

These are Anthropic threat-intelligence attributions; the affected labs' user-notification practices and full data-retention behavior are not independently established. has a contested assessment or contradictory evidence.

Sources and citation

Material revision history

  1. Sep 25, 2026 · Published version · first publication · revision 39

Cite this record

DiggingBeagle. “Anthropic says PRC labs relayed user prompts to Claude for distillation, exposing sensitive data.” Published by DiggingBeagle Sep 25, 2026. https://diggingbeagle.com/cases/anthropic-says-prc-labs-relayed-user-prompts-to-claude-for-distillation-exposing/

Citation guidance

Independent research

The source stays with the story.

Claims, evidence and corrections remain inspectable. About the project · Our methodology