Federal cybersecurity and intelligence agencies on Tuesday accused six China-based artificial intelligence companies of running industrial-scale campaigns to extract proprietary features from leading U.S. models.
DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI were all named in the joint advisory. Officials alleged the companies, “likely with Chinese government awareness,” pulled billions of tokens across millions of requests from U.S. AI systems. The list included variants of Claude, GPT, Gemini, and Grok. The activity dates back to at least late 2024.
Cybersecurity and Infrastructure Security Agency (CISA) Acting Director Nick Andersen said that CISA is committed to promoting the secure use of AI.
“We strongly urge AI companies to take immediate steps to safeguard their platforms against knowledge distillation campaigns that threaten to close the gap in advancements made by American companies,” Andersen said.
Knowledge distillation is a standard research method where a smaller model learns from the outputs of a larger one. The three agencies—CISA, the National Security Agency, and the FBI—differentiated legitimate research from “aggressive, malicious, and targeted distillation activities at an industrial scale.”
DeepSeek, formally Hangzhou DeepSeek Artificial Intelligence Basic Technology Research Co. Ltd., has run an organized campaign since at least late 2024, according to the agency, to feed synthetic training data into its R1 and V3 models.
Targets included Claude 3.7, Claude Sonnet 4 and 4.5, Claude Opus 4.1, Gemini 2.5 Pro and Flash previews, GPT-4, GPT-4o, GPT-5, and Grok 4. Officials called DeepSeek’s widely cited $5.6 million training figure misleading, saying it leaves out the cost of data taken through distillation.
Moonshot AI, or Beijing Moonshot Technology Co. Ltd., was accused of a broad campaign since at least mid-2025. The advisory said the firm pulled substantial Claude Fable 5 data for its Kimi-K3 model and GPT-4o data for Kimi-K2.
The new advisory recommends three steps for U.S. model providers, including hunting anomalous prompts, accounts, and usage spikes; quietly degrading answers when a distillation campaign is suspected; and sharing intelligence across companies, clouds, and API aggregators.
“Large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable,” Kratsios said.
Alibaba, the agencies contended, distilled Claude-4, Claude Opus, Claude Sonnet, and GPT-5 in late 2025 to hasten software engineering, customer-service dialogue, and image creation for its Qwen family of models. MiniMax, or Shanghai MiniMax Co. Ltd., used Claude Code, Claude Sonnet 4, Claude Opus, and several Gemini versions to improve its M2 model. Officials said MiniMax even attempted prompt injections to convince Claude Code it was actually a MiniMax product.
StepFun distilled a string of Claude and GPT-5 variants between late 2025 and early 2026 for its Step 4 model. By mid-2026, Z.AI had taken billions of tokens of GPT-5.5 and Claude Opus 4.8 data for chain-of-thought reasoning, the advisory said.
“There is nothing innovative about systematically extracting and copying the innovations of American industry,” Kratsios wrote at the time. “And there is nothing open about supposedly open models that are derived from acts of malicious exploitation.”
The memo also said the campaigns “allow those actors to deliberately strip away security protocols from the resulting models and undo mechanisms that ensure those AI models are ideologically neutral and truth-seeking.”
“This administration supports open-source models, but what we do not support is IP theft,” Bessent said in July. “If we see, especially, that overseas models are stealing from our great companies, we have the ability to sanction them because of this theft.”
“There’s a very technical AI word for it called distillation, but you and I would call it theft.”
CISA, the National Security Agency, and the FBI said the effort sits at the center of those firms’ development plans.

