China probes DeepSeek and Moonshot over alleged data leaks to Anthropic

China probes DeepSeek and Moonshot over alleged data leaks to Anthropic

Beijing opens investigations after US intelligence agencies claim Chinese AI firms routed millions of sensitive queries through Anthropic's Claude models

Chinese authorities are reportedly investigating two of the country’s most prominent AI companies, DeepSeek and Moonshot AI, over allegations that sensitive Chinese user data was funneled to US servers through Anthropic’s Claude models. The probes follow accusations from Anthropic and US government agencies that paint a picture of industrial-scale intellectual property extraction dressed up as normal API usage.

The core allegation is striking in its scope. Anthropic claims the Chinese firms created roughly 24,000 fraudulent accounts and conducted more than 16 million exchanges with Claude, effectively reverse-engineering the model’s capabilities in reasoning and coding for a fraction of what it cost to develop them.

The scale of the alleged operation

DeepSeek alone was linked to over 12 million exchanges in just 14 days during July 2026, with some queries reportedly containing sensitive corporate information. Moonshot AI allegedly routed approximately 300,000 customer requests through 5,380 accounts within a 10-day window in September 2026, on top of more than 23 million exchanges between May and July.

Advertisement

MiniMax, another Chinese AI firm caught up in the allegations, reportedly accounted for 13 million exchanges. DeepSeek’s share was around 150,000 in the initial accounting, while Moonshot AI clocked over 3.4 million, though those figures ballooned dramatically in subsequent months.

Anthropic’s terms explicitly prohibit China-based entities from using its models for distillation. The firms allegedly circumvented those restrictions using proxy networks.

Washington weighs in

The NSA, CISA, and FBI issued a joint advisory in September 2026 identifying a network of six Chinese companies conducting industrial-scale distillation campaigns against leading US AI models. The advisory stated that these operations had been ongoing since late 2024 and suggested that the Chinese government was likely aware of the activity.

Because Moonshot AI allegedly routed actual customer queries, including ones containing sensitive information, through Claude’s infrastructure, real Chinese user data may have transited US servers.

OpenAI had already accused DeepSeek of similar intellectual property violations earlier in 2026, making Anthropic’s allegations part of a pattern rather than an isolated incident.

Beijing’s uncomfortable position

The Chinese investigation puts Beijing in a peculiar spot. On one hand, DeepSeek and Moonshot AI are crown jewels of China’s AI ambitions. On the other hand, if Chinese user data, including potentially sensitive corporate and government information, was indeed flowing through American servers, that’s a domestic political liability. Chinese data protection laws are strict on paper, and regulators have shown willingness to crack down on companies that violate them, as Didi’s 2021 experience demonstrated.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
China probes DeepSeek and Moonshot over alleged data leaks to Anthropic
China probes DeepSeek and Moonshot over alleged data leaks to Anthropic

Beijing opens investigations after US intelligence agencies claim Chinese AI firms routed millions of sensitive queries through Anthropic's Claude models

Chinese authorities are reportedly investigating two of the country’s most prominent AI companies, DeepSeek and Moonshot AI, over allegations that sensitive Chinese user data was funneled to US servers through Anthropic’s Claude models. The probes follow accusations from Anthropic and US government agencies that paint a picture of industrial-scale intellectual property extraction dressed up as normal API usage.

The core allegation is striking in its scope. Anthropic claims the Chinese firms created roughly 24,000 fraudulent accounts and conducted more than 16 million exchanges with Claude, effectively reverse-engineering the model’s capabilities in reasoning and coding for a fraction of what it cost to develop them.

The scale of the alleged operation

DeepSeek alone was linked to over 12 million exchanges in just 14 days during July 2026, with some queries reportedly containing sensitive corporate information. Moonshot AI allegedly routed approximately 300,000 customer requests through 5,380 accounts within a 10-day window in September 2026, on top of more than 23 million exchanges between May and July.

Advertisement

MiniMax, another Chinese AI firm caught up in the allegations, reportedly accounted for 13 million exchanges. DeepSeek’s share was around 150,000 in the initial accounting, while Moonshot AI clocked over 3.4 million, though those figures ballooned dramatically in subsequent months.

Anthropic’s terms explicitly prohibit China-based entities from using its models for distillation. The firms allegedly circumvented those restrictions using proxy networks.

Washington weighs in

The NSA, CISA, and FBI issued a joint advisory in September 2026 identifying a network of six Chinese companies conducting industrial-scale distillation campaigns against leading US AI models. The advisory stated that these operations had been ongoing since late 2024 and suggested that the Chinese government was likely aware of the activity.

Because Moonshot AI allegedly routed actual customer queries, including ones containing sensitive information, through Claude’s infrastructure, real Chinese user data may have transited US servers.

OpenAI had already accused DeepSeek of similar intellectual property violations earlier in 2026, making Anthropic’s allegations part of a pattern rather than an isolated incident.

Beijing’s uncomfortable position

The Chinese investigation puts Beijing in a peculiar spot. On one hand, DeepSeek and Moonshot AI are crown jewels of China’s AI ambitions. On the other hand, if Chinese user data, including potentially sensitive corporate and government information, was indeed flowing through American servers, that’s a domestic political liability. Chinese data protection laws are strict on paper, and regulators have shown willingness to crack down on companies that violate them, as Didi’s 2021 experience demonstrated.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.