Find notable cyber news and cases, enriched with sources, timelines, and signals.

DeepSeek, Moonshot AI, and MiniMax Claude capability-extraction campaign

Campaign
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

DeepSeek, Moonshot AI, and MiniMax ran an industrial-scale campaign to extract Claude capabilities, using fraudulent accounts and commercial proxy services to gather training data for their own models. The operation generated more than 16 million exchanges across roughly 24,000 accounts, showing sustained and organized abuse rather than ordinary service use. Anthropic attributed the activity through request metadata, IP correlation, and infrastructure indicators. The campaign matters because model extraction can weaken safeguards and accelerate rival model development.

Related Happenings

Shadow-Aether-040 AI-augmented campaign against Mexican government entities

Campaign
First: 13.05.2026 16:00 Last: 13.05.2026 16:00 Sources 1

About this happening: The **Shadow-Aether-040** campaign used **AI agents** and custom tooling to compromise **six government entities in Mexico**, increasing the risk of follow-on intrusion and **data...

Russian-speaking threat actor campaign expands across multiple victims

Campaign
First: 09.03.2026 01:35 Last: 09.03.2026 01:35 Sources 1

About this happening: A **Russian-speaking threat actor** ran an **AI-augmented campaign** against **FortiGate security appliances**, using **multiple commercial AI services** to scale compromise attem...

AI-assisted hacktivist campaign targeting Mexican government agencies

Campaign
First: 06.03.2026 15:37 Last: 06.03.2026 15:37 Sources 1

About this happening: A **small group of hacktivists** ran an **AI-assisted intrusion campaign** against **at least nine Mexican government agencies**, compromising systems over **multiple months**. Th...

Chinese law-enforcement-linked ChatGPT smear campaign against CCP critics and Sanae Takaichi

Campaign
First: 26.02.2026 02:00 Last: 26.02.2026 02:00 Sources 1

About this happening: A **ChatGPT** account linked to **Chinese law enforcement** was used to support active **smear campaigns** against **Chinese dissidents** and **Sanae Takaichi**, showing how state...

GTIG maps constant multi-vector targeting of the defense industrial base

Target Trend
First: 13.02.2026 18:23 Last: 13.02.2026 18:23 Sources 1

About this happening: **GTIG** identified a **state-sponsored, hacktivist, and criminal** targeting pattern against the **defense industrial base (DIB)**, raising **persistent espionage and intrusion r...

Timeline

  1. 24.02.2026 08:04 2 articles · 3mo ago

    Anthropic discloses large-scale Claude capability extraction

    Initial Disclosure

    Anthropic disclosed that DeepSeek, Moonshot AI, and MiniMax ran industrial-scale campaigns against Claude, using fraudulent accounts and commercial proxy services to generate more than 16 million exchanges across about 24,000 accounts while targeting reasoning, agentic reasoning, tool use, coding, and computer vision; Anthropic said it attributed the activity using request metadata, IP address correlation, and infrastructure indicators, and it responded with classifiers, behavioral fingerprinting, stronger verification, and other safeguards.

    Show sources