NSA, FBI, CISA Warn of Industrial-Scale AI Model Distillation Attacks

US agencies say six China-based AI firms used large-scale distillation campaigns to extract capabilities from Claude, GPT, Gemini, and Grok models.

Sep 10, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

US security agencies say six China-based AI companies conducted industrial-scale campaigns to extract capabilities from American frontier models. The activity could give competing developers access to valuable reasoning, coding, and agentic capabilities without bearing the full cost of developing them independently.

The NSA, FBI, and Cybersecurity and Infrastructure Security Agency named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI in the warning. The agencies said the companies collectively obtained billions of tokens through millions of requests involving Claude, GPT, Gemini, and Grok models.

In a Sept. 8 joint cybersecurity advisory, the agencies said the campaigns date to at least late 2024 and likely occurred with the Chinese government’s awareness. They also emphasized that knowledge distillation itself is a legitimate AI-development technique; the alleged abuse involved coordinated extraction, account misuse, proxy infrastructure, and efforts to bypass provider controls.

How industrial-scale AI distillation works

Knowledge distillation uses outputs from a stronger “teacher” model to improve another model. The advisory says the named companies routed requests through native APIs, remote cloud providers, third-party aggregators, and gray-market API proxies known as “transfer stations,” spreading activity across multiple accounts and access paths.

The agencies also documented attempts to extract chain-of-thought reasoning, automatically switch access routes after blocking, and determine whether providers had altered model behavior to frustrate extraction. DeepSeek is the earliest campaign identified, with activity dating to at least late 2024.

Anthropic separately documented large-scale distillation activity involving three of the six companies. On Feb. 23, it said DeepSeek, Moonshot, and MiniMax generated more than 16 million Claude exchanges through approximately 24,000 fraudulent accounts.

The campaigns add another dimension to a threat environment in which attackers are increasingly using AI agents to automate reconnaissance, credential theft, and other attack stages.

China rejected the US allegations on Sept. 9. In an official response, the Ministry of Commerce said the accusations lacked factual and legal grounds and argued that distillation is a widely used, neutral AI-development technique.

Advertisement

Detecting and disrupting distillation campaigns

The agencies recommend comprehensive detection, targeted changes to responses when malicious distillation is suspected, and intelligence sharing across providers and infrastructure partners. Recent efforts to strengthen security around Claude agents also show how monitoring and access controls are expanding alongside AI capabilities.

Organizations can reinforce those defenses through seven measures:

  • Monitor anomalous usage patterns, including rapid usage spikes, unusual subscription-to-usage ratios, and repetitive prompts.
  • Strengthen account verification and identity controls to expose fraudulent registrations, shared credentials, and account rotation.
  • Correlate account, payment, network, and request telemetry to identify activity spread across accounts and services.
  • Deploy behavioral detection for repeated extraction of reasoning, coding, agentic, tool-use, and other high-value capabilities.
  • Harden model and API responses with rate controls and targeted changes when extraction is suspected.
  • Test incident response plans through exercises covering account abuse, proxy-driven extraction, credential misuse, and escalation procedures, building on defenses used against real-world AI-assisted cyberattacks.
  • Share threat intelligence with infrastructure partners to connect indicators distributed across multiple services.

High-volume enterprise AI workloads can generate some of the same signals, making volume alone insufficient to establish malicious activity. Detection requires behavioral context and correlation across identities, infrastructure, and access paths.

As AI becomes core infrastructure, model access is becoming another security boundary requiring identity controls, API monitoring, behavioral analytics, tested response plans, and coordinated threat intelligence.

Read more: Organizations expanding autonomous AI use can also reduce risk by building stronger oversight and controls around AI agents.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.