Executive Summary
U.S. intelligence agencies NSA, CISA, and FBI have accused Chinese AI companies including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of conducting systematic industrial-scale distillation attacks against American frontier AI models since late 2024. These companies extracted billions of tokens from Anthropic Claude, OpenAI GPT, Google Gemini, and SpaceXAI Grok models through bulk premium subscriptions, API abuse, and proxy networks to circumvent geographic restrictions. The attacks violated terms of service and resulted in significantly reduced development timelines and costs for Chinese AI models while undermining intellectual property protections of U.S. companies.
This incident highlights the evolving landscape of AI-powered intellectual property theft and the increasing sophistication of state-sponsored technology transfer operations, demonstrating how legitimate AI research techniques can be weaponized for competitive advantage at national scales.
Why This Matters Now
This represents a new frontier in intellectual property theft where AI models themselves become both the target and the weapon, with Chinese companies systematically extracting proprietary capabilities from U.S. frontier AI models at industrial scale, threatening American AI competitiveness and national security.
Attack Path Analysis
Chinese AI companies conducted systematic intellectual property theft through industrial-scale distillation attacks on U.S. frontier AI models. Attackers used obfuscated accounts, VPNs, and proxy infrastructure to bypass geographic restrictions and access APIs. They distributed operations across multiple platforms and providers to evade detection while extracting billions of tokens. Sophisticated automation and failover mechanisms enabled continuous data extraction from Claude, GPT, Gemini, and Grok models. Extracted capabilities were used to train competing AI models, reducing development costs and timelines. The campaign resulted in unauthorized replication of proprietary AI functionalities and competitive advantage theft.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers used VPNs, obfuscated accounts, and third-party aggregators to bypass geographic restrictions and gain unauthorized API access to U.S. frontier AI models
MITRE ATT&CK® Techniques
Valid Accounts: Cloud Accounts
Remote Services: Cloud Services
Automated Exfiltration
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Acquire Infrastructure: Virtual Private Server
Proxy: Multi-hop Proxy
Account Discovery: Cloud Account
Data from Cloud Storage Object
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Incident Response Plan Testing
Control ID: 12.10.4
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – Third-Party Risk Management
Control ID: Article 11
CISA ZTMM 2.0 – Identity Verification and Access Controls
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Security of Network Services
Control ID: A.13.1.2
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Direct target of intellectual property theft through AI model distillation attacks, requiring enhanced API security and egress traffic monitoring capabilities.
Computer/Network Security
Must implement zero trust segmentation and threat detection capabilities to protect against sophisticated multi-cloud distillation campaigns and unauthorized data exfiltration.
Information Technology/IT
Vulnerable to compromised credentials and fraudulent accounts enabling industrial-scale AI model extraction through encrypted traffic and east-west security bypasses.
Government Administration
Critical infrastructure implications from foreign AI capabilities development requiring enhanced visibility controls and compliance with NIST cybersecurity framework implementations.
Sources
- U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grokhttps://thehackernews.com/2026/09/us-agencies-accuse-china-ai-firms-of.htmlVerified
- CISA, NSA, and FBI Warn: China-Based AI Companies Targeting U.S. AI Models with Industrial-Scale Knowledge Distillationhttps://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251aVerified
- CISA, NSA, and FBI Warn China-Based AI Companies Targeting U.S. AI Models with Industrial-Scale Knowledgehttps://www.cisa.gov/news-events/news/cisa-nsa-and-fbi-warn-china-based-ai-companies-targeting-us-ai-models-industrial-scale-knowledgeVerified
- Anthropic Says Chinese AI Firms Used 1.6 Million Prompts to Illegally Extract Claude Capabilitieshttps://thehackernews.com/2026/02/anthropic-says-chinese-ai-firms-used-16.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the scope and effectiveness of this AI intellectual property theft campaign by constraining network paths and limiting cross-cloud lateral movement between extraction infrastructure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial access attempts would likely face constrained network reachability and reduced ability to establish persistent connections across cloud environments hosting AI model APIs
Control: Zero Trust Segmentation
Mitigation: Privilege escalation attempts would likely be constrained through workload isolation that limits the scope of credential-based access across AI platform infrastructure
Control: East-West Traffic Security
Mitigation: Cross-platform lateral movement would likely be significantly constrained, reducing attacker ability to distribute operations seamlessly across multiple cloud environments and API providers
Control: Multicloud Visibility & Control
Mitigation: Command and control coordination would likely face reduced effectiveness due to constrained visibility and limited ability to orchestrate failover mechanisms across segmented cloud environments
Control: Egress Security & Policy Enforcement
Mitigation: Large-scale token extraction would likely be constrained through controlled egress paths that limit the volume and destinations of outbound AI model responses
While intellectual property theft may still occur, the constrained extraction scope would likely result in incomplete model capabilities and reduced competitive advantage for threat actors
Impact at a Glance
Affected Business Functions
- Artificial Intelligence Model Development
- Proprietary Research and Development
- Intellectual Property Protection
- Advanced AI Capabilities and Features
Estimated downtime: N/A
Estimated loss: N/A
Billions of tokens extracted from proprietary U.S. frontier AI models including reasoning capabilities, specialized optimizations, domain-specific functions, software engineering skills, customer service dialogue functionality, and advanced AI model training data from Claude, GPT, Gemini, and Grok variants
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict API access based on verified identity and device posture rather than geographic controls alone
- • Deploy Egress Security & Policy Enforcement to detect and block suspicious automation patterns and bulk data extraction attempts
- • Enable Multicloud Visibility & Control to correlate activity across providers and identify distributed distillation campaigns
- • Utilize Threat Detection & Anomaly Response capabilities to baseline normal API usage patterns and alert on industrial-scale extraction activities
- • Implement Cloud Native Security Fabric controls to provide real-time inspection and autonomous response to AI model abuse and shadow AI risks



