At a glance
On September 9, 2026, federal security agencies exposed intellectual property theft targeting American artificial intelligence developers.
| Field | Details |
|---|---|
| Actor or Group | China-based AI firms including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI |
| Activity Type | Malicious knowledge distillation, API scraping, and model capability extraction |
| Targets or Victims | Frontier US artificial intelligence developers (OpenAI, Anthropic, Google, xAI) |
| Scale | Billions of tokens extracted across millions of queries |
| Jurisdiction Status | Joint warning issued by CISA, NSA, and FBI; ongoing intelligence monitoring |
| Source | CISA, NSA, and FBI Joint Cybersecurity Advisory |
Executive Summary
Federal security agencies revealed that foreign artificial intelligence firms are harvesting capabilities from American frontier models. This aggressive campaign targets reasoning architectures, software coding tools, and domain-specific skills. Consequently, officials warn that malicious AI distillation threatens fair technological competition worldwide.
What Happened in the Model Extraction Campaigns
Foreign development teams extracted proprietary capabilities from leading American machine learning models. According to federal authorities, “China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core-not merely a supplement-of their AI development strategy.”
These entities query advanced commercial APIs at an unprecedented scale. Specifically, operators bypass regional access controls through an underground network of proxy servers called transfer stations. These transfer stations resell unauthorized model access at heavily discounted rates. Furthermore, the actors purchase large pools of premium consumer subscriptions to hide bulk extraction traffic.
Mechanics of API Transfer Stations
Foreign development teams distribute automated requests across several platforms to evade rate limits. For instance, they switch between native developer APIs, cloud hosting platforms, and third-party aggregators. Automated infrastructure systems scrub client metadata to erase organizational identifiers. Additionally, these systems monitor query quotas and shift traffic when providers throttle connections.
Eliciting Hidden Reasoning Traces
Furthermore, attackers use tailored prompt injection techniques to extract proprietary logic. Frontier systems normally conceal their inner thought chains from standard user interfaces. However, the attackers design prompts that force models to expose hidden reasoning steps. As the advisory notes, “DeepSeek employed prompts instructing models to imagine and articulate the internal reasoning behind completed responses and write it out step by step.” Consequently, these extracted reasoning steps train rival student models at minimal cost.
Who Is Behind the Distillation Operations
Federal agencies identify multiple commercial technology firms based in China as the primary operators. The authoring agencies state that these activities occur “likely with Chinese government awareness.” The named companies include DeepSeek, Moonshot AI, Alibaba Group, MiniMax, StepFun, and Z.AI. Analysts express high confidence in these attributions based on multi-source infrastructure telemetry and query correlation.
According to the joint cybersecurity advisory published by CISA, these firms pursue model theft to accelerate development cycles. By extracting data from American systems, these competitors compress multi-year research efforts into weeks. For example, MiniMax retargeted new commercial models within twenty-four hours of public release. Meanwhile, Moonshot AI systematically queried specialized coding and mathematical reasoning endpoints to bolster its internal tools.
Impact and Scale of the Extraction Activity
The scale of this extraction activity involves billions of tokens collected across millions of API sessions. Targeted models include versions of Claude, GPT, Gemini, and Grok. In particular, DeepSeek extracted training material to build its R1 and V3 systems. The company claimed its models required only $5.6 million in compute training expenses.
However, federal officials dispute these figures as unverified claims. The joint advisory explains that “DeepSeek’s publicly quoted training costs of $5.6M are misleading as it does not include the true cost of the data acquired through extensive malicious distillation.” By stealing high-value synthetic outputs from American systems, foreign developers save massive computational investments.
Moreover, StepFun reportedly gathered data from numerous frontier models to refine its Step 4 software agents. In another case, Z.AI extracted billions of tokens to enhance reasoning paths. These actions siphon intellectual property worth billions of dollars in private research capital.
How Organizations Can Protect AI Models
Federal agencies recommend several defensive measures to protect machine learning infrastructure against malicious AI distillation. Model providers must establish rigorous behavioral monitoring across all customer accounts. Specifically, security teams must monitor subscription-to-usage ratios and track accounts that immediately hit maximum throughput quotas.
Deploying Response Degradation Defenses
Additionally, defenders should alter response fidelity when systems detect suspected scraping activities. Rather than blocking queries outright, platforms can introduce subtle variations in reasoning paths. For example, providers can return responses generated by smaller, downgraded models without alerting the client. This strategy degrades training dataset quality without revealing defensive thresholds.
Cross-Ecosystem Information Sharing
Finally, technology providers must establish shared intelligence networks across the broader cloud ecosystem. Individual vendors struggle to detect distributed scraping operations on their own. Therefore, cloud hosts, API aggregators, and model creators should correlate query volumes and infrastructure indicators. Applying differential privacy noise to API outputs also provides mathematical protection against parameter theft. By combining rate limits, anomaly detection, and shared threat data, organizations can safeguard critical technological advances.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!