DeepSeek, Moonshot AI, and MiniMax Claude capability-extraction campaign
Campaign
Summary
Hide ▲
Show ▼
DeepSeek, Moonshot AI, and MiniMax ran an industrial-scale campaign to extract Claude capabilities, using fraudulent accounts and commercial proxy services to gather training data for their own models. The operation generated more than 16 million exchanges across roughly 24,000 accounts, showing sustained and organized abuse rather than ordinary service use. Anthropic attributed the activity through request metadata, IP correlation, and infrastructure indicators. The campaign matters because model extraction can weaken safeguards and accelerate rival model development.
Related Happenings
Shadow-Aether-040 AI-augmented campaign against Mexican government entities
Campaign
First: 13.05.2026 16:00
Last: 13.05.2026 16:00
Sources 1
About this happening:
The **Shadow-Aether-040** campaign used **AI agents** and custom tooling to compromise **six government entities in Mexico**, increasing the risk of follow-on intrusion and **data...
Shadow-Aether-040 AI-augmented campaign against Mexican government entities
CampaignAbout this happening: The **Shadow-Aether-040** campaign used **AI agents** and custom tooling to compromise **six government entities in Mexico**, increasing the risk of follow-on intrusion and **data...
Russian-speaking threat actor campaign expands across multiple victims
Campaign
First: 09.03.2026 01:35
Last: 09.03.2026 01:35
Sources 1
About this happening:
A **Russian-speaking threat actor** ran an **AI-augmented campaign** against **FortiGate security appliances**, using **multiple commercial AI services** to scale compromise attem...
Russian-speaking threat actor campaign expands across multiple victims
CampaignAbout this happening: A **Russian-speaking threat actor** ran an **AI-augmented campaign** against **FortiGate security appliances**, using **multiple commercial AI services** to scale compromise attem...
AI-assisted hacktivist campaign targeting Mexican government agencies
Campaign
First: 06.03.2026 15:37
Last: 06.03.2026 15:37
Sources 1
About this happening:
A **small group of hacktivists** ran an **AI-assisted intrusion campaign** against **at least nine Mexican government agencies**, compromising systems over **multiple months**. Th...
AI-assisted hacktivist campaign targeting Mexican government agencies
CampaignAbout this happening: A **small group of hacktivists** ran an **AI-assisted intrusion campaign** against **at least nine Mexican government agencies**, compromising systems over **multiple months**. Th...
Chinese law-enforcement-linked ChatGPT smear campaign against CCP critics and Sanae Takaichi
Campaign
First: 26.02.2026 02:00
Last: 26.02.2026 02:00
Sources 1
About this happening:
A **ChatGPT** account linked to **Chinese law enforcement** was used to support active **smear campaigns** against **Chinese dissidents** and **Sanae Takaichi**, showing how state...
Chinese law-enforcement-linked ChatGPT smear campaign against CCP critics and Sanae Takaichi
CampaignAbout this happening: A **ChatGPT** account linked to **Chinese law enforcement** was used to support active **smear campaigns** against **Chinese dissidents** and **Sanae Takaichi**, showing how state...
GTIG maps constant multi-vector targeting of the defense industrial base
Target Trend
First: 13.02.2026 18:23
Last: 13.02.2026 18:23
Sources 1
About this happening:
**GTIG** identified a **state-sponsored, hacktivist, and criminal** targeting pattern against the **defense industrial base (DIB)**, raising **persistent espionage and intrusion r...
GTIG maps constant multi-vector targeting of the defense industrial base
Target TrendAbout this happening: **GTIG** identified a **state-sponsored, hacktivist, and criminal** targeting pattern against the **defense industrial base (DIB)**, raising **persistent espionage and intrusion r...
Timeline
-
24.02.2026 08:04 2 articles · 3mo ago
Anthropic discloses large-scale Claude capability extraction
Initial DisclosureAnthropic disclosed that DeepSeek, Moonshot AI, and MiniMax ran industrial-scale campaigns against Claude, using fraudulent accounts and commercial proxy services to generate more than 16 million exchanges across about 24,000 accounts while targeting reasoning, agentic reasoning, tool use, coding, and computer vision; Anthropic said it attributed the activity using request metadata, IP address correlation, and infrastructure indicators, and it responded with classifiers, behavioral fingerprinting, stronger verification, and other safeguards.
Show sources
- Anthropic Says Chinese AI Firms Used 16 Million Claude Queries to Copy Model — thehackernews.com — 24.02.2026 08:04
- Anthropic Says Chinese AI Firms Used 16 Million Claude Queries to Copy Model — thehackernews.com — 24.02.2026 08:04