Anthropic Accuses Alibaba of Extracting Claude AI Capabilities Through 28.8 Million Fraudulent Exchanges
Anthropic has accused Alibaba of conducting the largest known AI model distillation attack against the company, generating 28.8 million Claude exchanges through 25,000 fraudulent accounts between April and June 2026. The letter was sent to the US Senate Banking Committee.

Data centre server racks representing Anthropic's accusation that Alibaba illicitly extracted Claude AI model capabilities through 28.8 million fraudulent exchanges in 2026
Anthropic Accuses Alibaba of Running Largest Known AI Model Theft Campaign Against Claude
US AI company Anthropic has accused Alibaba of conducting what it describes as the largest known distillation attack ever carried out against its Claude AI platform, generating more than 28.8 million exchanges through almost 25,000 fraudulent accounts over a period of 44 days. The campaign, which Anthropic says was conducted between April 22 and June 5, 2026, was attributed to operators affiliated with Alibaba and its AI research division, Alibaba Qwen.
The accusations are contained in a letter dated June 10, 2026, sent by Anthropic to US Senators Tim Scott and Elizabeth Warren, the chair and ranking member of the Senate Banking Committee, ahead of a scheduled congressional hearing on artificial intelligence. The letter was obtained by Reuters.
Alibaba did not immediately respond to a request for comment.
What a Distillation Attack Actually Means
AI model distillation is a technique in which a less capable model is trained on the outputs of a stronger one, effectively transferring learned capabilities without access to the underlying weights, training data, or architecture. Anthropic described the Alibaba campaign as a deliberate effort to accelerate China's ability to reach the capabilities of its frontier Mythos Preview model, which remains restricted to a small number of trusted organisations under Anthropic's Project Glasswing programme.
The scale of the Alibaba campaign represents a material escalation compared to prior incidents Anthropic has disclosed. In February 2026, Anthropic revealed that Chinese AI startup DeepSeek had conducted a distillation campaign involving over 150,000 exchanges, Moonshot AI had reached 3.4 million exchanges, and MiniMax had generated over 13 million. The Alibaba campaign, at 28.8 million exchanges, exceeds all three combined.
GCC Implications
The disclosure carries direct strategic implications for GCC governments and enterprises that have built AI strategies around Anthropic's models. The UAE is one of Anthropic's most significant international partners, with the US-UAE AI Acceleration Partnership formally incorporating Anthropic technology into Abu Dhabi's sovereign AI infrastructure. Qatar's QIA participated in Anthropic's most recent funding round. The integrity and exclusivity of frontier model capabilities are therefore not an abstract concern for Gulf technology leaders but a direct variable in their AI investment calculus.
Anthropic said in the letter it is supportive of the US government's efforts to combat such attacks, including through threat intelligence sharing with private sector AI companies.
Timeline of Escalating Restrictions
The distillation campaign and the Senate letter preceded a significant regulatory event. On June 12, 2026, two days after the letter was sent, the US Commerce Department imposed restrictions on Anthropic's Mythos and Fable models, blocking foreign nationals from accessing them on national security grounds. The restrictions resulted in Anthropic temporarily disabling global access to those models. G7 leaders subsequently discussed a "trusted partners" scheme that could restore access for allied nations, with France's President Macron expressing confidence that progress would be made on broadening access in the weeks ahead.
Alibaba was separately added to the Pentagon's list of Chinese military companies this month, a designation it is challenging in court. The US Commerce Department has so far declined to place DeepSeek on its trade blacklist, despite an interagency committee identifying it as a national security risk, in an effort to avoid escalating tensions with Beijing.
Pattern of Industrial-Scale AI Extraction
Anthropic noted in its February 2026 disclosure that the campaigns it had identified were growing in intensity and sophistication, and called for rapid, coordinated action among industry players, policymakers and the global AI community. The Alibaba campaign, at nearly twice the scale of all previously disclosed incidents combined, suggests that warning was accurate.
For enterprise security teams in the GCC and globally, the practical lesson is specific: API access to frontier AI models is an increasingly active attack surface, and the threat is not limited to conventional credential theft or prompt injection. The systematic extraction of model capabilities through massive, coordinated fraudulent account creation represents a category of threat that enterprise AI governance frameworks must now explicitly account for.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.