Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Did Trump post video of himself hitting Mark Carney with hockey stick? Here’s the truth

    September 9, 2026

    Travelers Face More Flight Delays After Major Air Traffic Disruption at UK Airports

    September 9, 2026

    Asylum applications plummet across EU as governments push for deportation hubs – POLITICO

    September 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Did Trump post video of himself hitting Mark Carney with hockey stick? Here’s the truth
    • Travelers Face More Flight Delays After Major Air Traffic Disruption at UK Airports
    • Asylum applications plummet across EU as governments push for deportation hubs – POLITICO
    • Met police launch inquiry into alleged overseas donations to Reform UK | Reform UK
    • Bridget Phillipson sets up ‘class unit’ as social mobility advisers ditched
    • Who is voting for the far-right Alternative for Germany?
    • Google to fund Finnish AI with €13bn investment and nuclear power pact
    • US says Chinese firms extracted billions of tokens from frontier AI models
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    US says Chinese firms extracted billions of tokens from frontier AI models

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 9, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024.

    A joint advisory from CISA, NSA, and the FBI  states that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens through millions of requests from frontier AI models from Anthropic, OpenAI, Google, and xAI.

    The agencies assess that the scale and sophistication of the operations indicate Chinese government awareness, mentioning that this approach is likely a core development strategy for the offending firms.

    AI model distillation is a legitimate technique in which a “student” model learns from the outputs of a well-trained model, helping researchers and developers reduce training costs and speed up AI deployment.

    However, as Google warned in February, distillation attacks can occur outside these companies’ controlled environments, abusing API access to extract the knowledge and logic of powerful models and compete with them at a fraction of the training cost.

    CISA’s advisory explains that Chinese firms distribute API requests across fraudulent or shared accounts, APIs, cloud services, aggregators, and “transfer station” proxies to bypass geographic restrictions, usage limits, and detection.

    Some of the prompts used attempted to expose restricted chain-of-thought reasoning, while automated systems switched providers and checked whether defenders had degraded the responses.

    “Advanced industrial-scale distillation tactics include chain-of-thought (CoT) reasoning extraction, automated failover between pathways during blocking attempts, and sophisticated quality evaluation frameworks to detect defensive countermeasures,” the advisory explains.

    “China-based AI companies that conduct industrial-scale distillation against U.S. AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model.”

    DeepSeek and MoonShot AI were marked as the top offenders involved in distilling multiple Claude, GPT, Gemini, and Grok models, followed by MiniMax, which targeted Claude, Gemini, and GPT models.

    Alibaba and StepFun are accused of targeting Claude and GPT models to improve their products, while Z.AI allegedly targeted GPT-5.5 and Claude Opus 4.8.

    The advisory recommends that AI companies improve behavioral and infrastructure-level detection, modify responses when distillation operations are suspected, and share intelligence about these campaigns with all stakeholders.

    Potential indicators include new accounts immediately reaching maximum usage, continuous activity without normal human idle periods, shared accounts accessed from numerous IP addresses or user agents, identical prompts across multiple providers, unusually high subscription-to-usage ratios, and coordinated switching between access routes.

    BleepingComputer has contacted all six Chinese AI firms for a statement, and we will add their statements if we get them.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Billions Chinese extracted firms Frontier models tokens
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Veradigm warns of patient data breach after ransomware gang claims attack

    MFA’s Weakest Link: Account Recovery Is the New Attack Path

    Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy

    US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities

    Suno replaces its AI models with a new one trained on licensed music as copyright suits pile up

    SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Did Trump post video of himself hitting Mark Carney with hockey stick? Here’s the truth

    September 9, 2026

    Travelers Face More Flight Delays After Major Air Traffic Disruption at UK Airports

    September 9, 2026

    Asylum applications plummet across EU as governments push for deportation hubs – POLITICO

    September 9, 2026

    Met police launch inquiry into alleged overseas donations to Reform UK | Reform UK

    September 9, 2026
    Latest Posts

    Justice Dept. Subpoenas Times Freelancer in Effort to Identify Sources

    August 1, 2026

    Michigan joins Minnesota in reporting cyberattacks, with FBI investigating | Cybercrime News

    August 1, 2026

    Tiny aerosol particles could supercharge tropical storm clouds

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Did Trump post video of himself hitting Mark Carney with hockey stick? Here’s the truth

    September 9, 2026

    Travelers Face More Flight Delays After Major Air Traffic Disruption at UK Airports

    September 9, 2026

    Asylum applications plummet across EU as governments push for deportation hubs – POLITICO

    September 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.