U.S. cybersecurity and intelligence agencies say that six Chinese AI companies extracted billions of tokens through industrial-scale distillation attacks on American frontier AI models since at least late 2024.
The agencies, the firms named, and the central assessment
A joint advisory published by the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as operators that "extracted billions of tokens through millions of requests" from frontier models. The agencies "assess that the scale and sophistication of the operations indicate Chinese government awareness," and note that this distillation approach is likely a core development strategy for the offending firms.
How the distillation operations were executed
The advisory documents a mix of well-known and advanced techniques used to mask large-scale queries and to capture model behavior. CISA, NSA, and the FBI say the firms distributed API requests across fraudulent or shared accounts, public APIs and cloud services, aggregators, and so-called "transfer station" proxies to bypass geographic restrictions, usage limits, and detection.
The advisory states that some prompts explicitly attempted to expose restricted chain-of-thought reasoning, while automated systems switched providers and verified whether defenders had degraded responses. As the agencies put it: “Advanced industrial-scale distillation tactics include chain-of-thought (CoT) reasoning extraction, automated failover between pathways during blocking attempts, and sophisticated quality evaluation frameworks to detect defensive countermeasures.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhich models were targeted, and who the worst offenders were
The advisory lists the models and providers that were subject to the extraction campaigns: Anthropic, OpenAI, Google, and xAI models. DeepSeek and Moonshot AI are identified as the top offenders, having distilled multiple Claude, GPT, Gemini, and Grok models. MiniMax focused on Claude, Gemini, and GPT models. Alibaba and StepFun are accused of targeting Claude and GPT models to improve their own products. Z.AI is specifically alleged to have targeted GPT-5.5 and Claude Opus 4.8.
The agencies note a calculated rationale behind the activity: “China-based AI companies that conduct industrial-scale distillation against U.S. AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model.”
Recommended defensive actions and measurable indicators
The advisory calls on AI providers to strengthen behavioral and infrastructure-level detection, to modify responses when distillation operations are suspected, and to share intelligence about these campaigns with all stakeholders. It also supplies concrete potential indicators that defenders should watch for, including:
- new accounts immediately reaching maximum usage limits;
- continuous activity without normal human idle periods;
- shared accounts accessed from numerous IP addresses or user agents;
- identical prompts across multiple providers;
- unusually high subscription-to-usage ratios; and
- coordinated switching between access routes.
The advisory warns that "overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply."
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams will be asked to tune detection for behavioral patterns—automated failover, identical prompts across providers, and account-level anomalies—and to consider modifying model responses when distillation is suspected, as the advisory recommends.
- Policymakers and regulators receive a formal, multi-agency assessment that the operations were large and sophisticated enough to merit a determination of likely state awareness; that assessment frames the issue as both an economic and a national-security concern, according to the advisory.
- Affected enterprises and procurement leaders face two practical pressures: monitoring unusual subscription-to-usage ratios and sharing intelligence with partners, and balancing those efforts against the advisory’s observation that distillation can materially shorten development timelines and reduce training costs for offenders.
The advisory cites prior warnings about abuse of distillation: it notes that "as Google warned in February, distillation attacks can occur outside these companies’ controlled environments, abusing API access to extract the knowledge and logic of powerful models and compete with them at a fraction of the training cost." The report also links its findings to defensive measurement: the Blue Report 2026 "measures defenses technique by technique across 338 million simulations run in customer production environments."
BleepingComputer has contacted all six Chinese AI firms for a statement, and will add their statements if received. The advisory’s immediate agenda is clear—improve detection, alter responses under suspicion, and share intelligence—while the agencies' attribution and the firms named set a narrow, specific policy and operational calculus for the months ahead.




