WASHINGTON — U.S. cybersecurity and national security agencies are warning that multiple China-based artificial intelligence companies have conducted large-scale campaigns designed to extract proprietary capabilities, reasoning behavior, specialized functions and training value from leading American AI models.
A September 2026 joint cybersecurity advisory issued by the National Security Agency, Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation says the activity goes far beyond ordinary AI research and constitutes what the agencies describe as aggressive, targeted and industrial-scale knowledge distillation against U.S. frontier AI systems.
The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI and says those companies extracted billions of tokens across millions of exchanges or requests involving American frontier models beginning no later than late 2024.
The targeted systems included variants of Claude, GPT, Gemini and Grok, according to the advisory. Federal agencies said the operations were conducted likely with the awareness of the Chinese government and were intended to shorten development timelines, reduce training costs and narrow technological gaps between Chinese AI systems and U.S. frontier models.
Knowledge distillation itself is a legitimate machine-learning technique in which a smaller or less capable model learns from the outputs of a stronger model.
The concern outlined by U.S. agencies is not the technique itself, but the scale, intent and access methods used.
The advisory says the China-based companies systematically extracted restricted proprietary functionality and capabilities from U.S. systems while using infrastructure designed to evade geographic controls, account restrictions, platform safeguards and attribution mechanisms.
Those pathways included native APIs, remote cloud providers, third-party aggregators and a gray market of proxy services referred to as “transfer stations.” These intermediaries allowed users to route requests through infrastructure that obscured their true origin and bypassed access restrictions established by U.S. AI providers.
Federal agencies said the operations also relied on bulk procurement of premium AI subscriptions that could be shared across teams of developers.
More advanced activity included attempts to extract chain-of-thought reasoning, automated switching between access pathways after blocking attempts and quality-control frameworks designed to determine whether U.S. providers had begun degrading or altering responses in an effort to frustrate extraction.
The advisory details extensive activity attributed to DeepSeek.
According to the government assessment, DeepSeek has conducted an organized distillation campaign against U.S. frontier AI systems since at least late 2024 to generate synthetic training data for models including R1 and V3.
The agencies said DeepSeek targeted reasoning capabilities, specialized knowledge areas and proprietary functions in an effort to reduce computing and research costs. They also challenged publicly cited DeepSeek training-cost figures, arguing that those estimates do not account for the value of data and capabilities obtained through extensive distillation activity.
The advisory identifies a broad range of models targeted by DeepSeek, including versions of Claude Sonnet, Claude Opus, Gemini, GPT-4, GPT-4o, GPT-5 and Grok.
The extracted capabilities allegedly included legal specialization, API-driven tasks, reasoning drafts, agentic functions, question-and-answer optimization, supervised fine-tuning, creative writing and occupational writing capabilities.
Moonshot AI is also accused of conducting a widespread distillation campaign beginning by at least mid-2025.
Federal agencies said Moonshot extracted data from multiple U.S. frontier models to improve its Kimi family of systems, targeting supervised fine-tuning, reinforcement learning, software engineering, mathematics, agentic reasoning, tool use, computer vision and other functions.
The advisory also details activity attributed to Alibaba, MiniMax, StepFun and Z.AI.
Alibaba allegedly used outputs from Claude and GPT systems to improve software engineering, customer-service dialogue, virtual-character generation, reinforcement learning, supervised fine-tuning and agentic workflows.
MiniMax allegedly distilled chain-of-thought reasoning, reinforcement learning, supervised fine-tuning and software-engineering capabilities from systems including Claude Code, Claude Sonnet, Claude Opus and Gemini.
Federal agencies said MiniMax also used prompt-injection techniques intended to make Claude Code believe it was operating as a MiniMax product.
StepFun allegedly extracted coding and agentic capabilities from multiple Claude and GPT systems between late 2025 and early 2026.
By mid-2026, the advisory says Z.AI had distilled billions of tokens from GPT-5.5 and Claude Opus 4.8 in an effort to develop chain-of-thought reasoning capabilities for its own model.
The agencies mapped much of the activity to the MITRE ATLAS framework, which tracks adversarial techniques targeting artificial intelligence systems.
Federal analysts identified activity involving infrastructure acquisition, AI inference API access, prompt injection, jailbreak techniques, discovery, collection and exfiltration.
One major concern involves attempts to obtain hidden reasoning processes.
According to the advisory, China-based operators crafted prompts intended to force U.S. models to reveal internal chain-of-thought reasoning despite restrictions preventing those internal processes from being shown directly to users.
DeepSeek was specifically identified as using prompts designed to make models reconstruct or articulate the reasoning behind completed answers step by step.
The advisory says this type of extraction can give a student model more than factual answers. It can provide examples of reasoning methodology that can then be used to improve coding, logical analysis and agentic behavior.
The government assessment also describes the campaigns as highly adaptive.
MiniMax, for example, allegedly redirected exchanges toward a newly released Claude model within 24 hours of its availability, suggesting operators were monitoring new releases and maintaining infrastructure capable of rapidly shifting targets.
Collection operations were also highly focused.
Moonshot AI allegedly used millions of exchanges targeting agentic reasoning, tool use, coding, data analysis, computer-use agents and computer vision.
DeepSeek allegedly targeted reasoning performance, rubric-based grading functions and techniques used by U.S. systems to evaluate response quality.
The advisory says individual campaigns could last from days to months and generate thousands to millions of queries within a single knowledge domain.
Federal agencies characterize the economic implications as significant.
The advisory states that extraction of proprietary functionality representing billions of dollars in research and development costs can reduce the competitive advantage created by that investment and threaten U.S. technological leadership.
The campaigns also relied on operational methods that fall outside existing MITRE ATLAS classifications.
One technique involved systematically bypassing geographic restrictions and creating accounts that concealed their true country of origin before purchasing premium AI subscriptions in bulk.
StepFun allegedly used pools of accounts supporting multiple simultaneous sessions, allowing workloads to be distributed while avoiding quota exhaustion.
Indicators identified by the agencies include accounts accessed through multiple IP addresses and user agents, uninterrupted 24-hour usage lacking normal human idle periods, unusual subscription-to-API consumption ratios and new accounts immediately operating at maximum capacity.
Another technique involved centralized routing infrastructure capable of automatically distributing requests among native APIs, cloud providers, third-party aggregators, relays and vendor account pools.
The advisory also describes automated metadata sanitization intended to remove organizational identifiers that might expose the companies conducting the campaigns.
NSA, CISA and the FBI are urging U.S. AI companies to respond at an ecosystem level rather than treating each account or API anomaly as an isolated event.
The agencies recommend stronger identity verification, monitoring of abnormal usage patterns and greater scrutiny of newly created accounts immediately generating enterprise-scale traffic.
They also recommend targeted defensive response changes when malicious distillation is detected. These can include differential privacy techniques or routing suspicious requests toward less sophisticated models to reduce the training value attackers receive.
The advisory goes further by recommending that companies avoid telling confirmed malicious distillation operators when defensive degradation has been activated.
Federal agencies say quietly reducing reasoning depth, varying response structure or altering output quality can make stolen data less useful while making it more difficult for the operator to determine whether a countermeasure has been deployed.
Cross-company intelligence sharing is another major recommendation.
The agencies argue that activity appearing insignificant within one provider may become identifiable as a coordinated campaign when API providers, cloud platforms, model companies and aggregators compare IP addresses, domains, infrastructure, timing patterns and query volumes.
The advisory notes that proxy networks can manage tens of thousands of fraudulent accounts simultaneously, allowing distillation traffic to be distributed across different providers and mixed with legitimate customer activity.
The government also points to defensive measures from MITRE ATLAS, including query-rate limits, authenticated API access, telemetry logging, adversarial input detection, output obfuscation, AI red-team testing, model hardening and restrictions on public release of sensitive architecture, prompt templates, algorithms and model checkpoints.
The advisory’s central warning is that industrial-scale AI distillation should no longer be viewed as isolated model imitation.
NSA, CISA and the FBI are describing an organized extraction system built around account farms, proxy infrastructure, automated routing, prompt engineering, hidden-reasoning extraction, large-scale API querying and coordinated collection of outputs for use as synthetic training data.
That changes the security problem.
The target is no longer only source code, model weights or conventional proprietary files. The behavior and capabilities exposed through an AI system’s interface can themselves become valuable intellectual property when collected at sufficient scale.
For U.S. AI companies, the advisory establishes a new defensive reality: every legitimate-looking query may contribute a small amount of information, but millions of coordinated queries can become a mechanism for reconstructing capabilities developed through years of research, enormous computational investment and proprietary engineering.
The joint advisory is marked TLP:CLEAR, allowing the information to be shared broadly, and was issued as part of the cybersecurity missions of NSA, CISA and the FBI.
Document Source: National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation — Joint Cybersecurity Advisory, China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies, U/OO/6059854-26 | PP-26-3853, September 2026, Version 1.0. (Free Download)
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



