Anthropic PBC accused Alibaba Group Holding Ltd. of conducting a large-scale illicit campaign to access its Claude artificial intelligence model. The effort reportedly used almost 25,000 fraudulent accounts to generate more than 28.8 million exchanges with Claude between April 22 and June 5, 2026 [1, 2, 3, 4, 5, 6, 7].

Anthropic said the attack targeted Claude's most advanced capabilities, including software engineering, agentic reasoning, and long-horizon task planning [8, 2, 3, 5, 7]. It described the effort as a "distillation" attack, where a less capable model is trained using outputs from a stronger one to shortcut costly training and research and development expenses. Anthropic said such illicit distillation attacks help Chinese AI developers reach frontier model capabilities without bearing the usual resource costs [1, 2, 3, 4, 6, 9, 7].

The campaign reportedly used obfuscation techniques and proxy networks to evade detection [2]. Anthropic said the attack occurred after former President Donald Trump took steps to curb illicit AI distillation attacks on US models [2, 3]. The US government also imposed export controls this year restricting foreign access to Anthropic's latest models citing national security concerns [3, 9].

Anthropic sent a letter dated June 10, 2026, to US Senators Tim Scott and Elizabeth Warren outlining the allegations and calling for coordinated government and industry action to combat unauthorized distillation [1, 2, 3, 4, 5, 6, 9, 7]. A spokesperson said, "We believe combating the threat of illicit distillation requires coordinated action between government and industry, and we will continue working with Congress and the Administration to maintain American AI leadership" [3]. Sarah Heck, head of policy at Anthropic, added, "These distillation attacks are carried out illicitly, systematically, and at an industrial scale to harvest US AI capabilities across frontier labs and repackage them as their own without incurring the training and R&D costs required to train US frontier models" [9].

Following Anthropic’s accusations, Alibaba’s shares in Hong Kong fell as much as 4.9%, hitting a 16-month low [10, 11, 9]. Alibaba did not immediately respond or comment on the allegations [1, 3, 4, 5, 6, 9].

Anthropic said Alibaba was among several Chinese AI firms previously identified conducting similar illicit distillation campaigns in 2026, alongside startups DeepSeek, Moonshot, and MiniMax. Those campaigns generated over 150,000, 3.4 million, and 13 million exchanges respectively [1, 3, 6, 9]. Additionally, Alibaba was added to the Pentagon’s Chinese military companies list in June 2026, a designation it is challenging [1, 6, 9].

The timeline of the campaign runs from April 22 to June 5, with the letter to US senators on June 10 and public reports emerging around June 24-25 accusing Alibaba of the illicit access [1, 2, 3, 4, 5, 6, 7].

US government export controls and increased congressional scrutiny are expected to continue as authorities respond to the threat of illicit AI model distillation attacks.