Executive Summary
In September 2026, U.S. cybersecurity agencies CISA, NSA, and FBI disclosed that six Chinese AI companies conducted industrial-scale distillation attacks against American frontier AI models since late 2024. DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens through millions of API requests targeting models from Anthropic, OpenAI, Google, and xAI. The attackers used sophisticated techniques including fraudulent accounts, proxy networks, chain-of-thought reasoning extraction, and automated failover systems to bypass geographic restrictions and usage limits, enabling them to replicate advanced AI capabilities at a fraction of normal development costs.
This incident highlights the emerging threat of AI intellectual property theft as nations compete for technological dominance, with state-sponsored actors leveraging legitimate AI development techniques for unauthorized knowledge transfer and competitive advantage.
Why This Matters Now
AI model distillation attacks represent a new frontier in intellectual property theft, where state-sponsored actors can steal years of AI research and billions in development costs through API abuse, threatening U.S. technological leadership.
Attack Path Analysis
Chinese AI companies conducted industrial-scale distillation attacks against US frontier AI models by creating fraudulent accounts and using distributed proxy infrastructure to bypass geographic restrictions. They extracted billions of tokens through automated API requests across multiple providers, employing sophisticated failover mechanisms and quality evaluation frameworks. The attackers used transfer station proxies and cloud aggregators to obscure their activities while conducting chain-of-thought reasoning extraction. The massive scale of token extraction enabled these companies to develop competitive AI models at significantly reduced training costs, representing strategic intellectual property theft with likely Chinese government awareness.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers created fraudulent and shared accounts across multiple AI service providers (Anthropic, OpenAI, Google, xAI) to gain legitimate API access, bypassing normal registration controls and geographic restrictions
MITRE ATT&CK® Techniques
Valid Accounts
Exploit Public-Facing Application
Exfiltration Over Web Service
Automated Exfiltration
Acquire Infrastructure: Web Services
Acquire Infrastructure: Web Services
Web Service
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Identity and Access Management
Control ID: ID.AM-3
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
Digital Operational Resilience Act (DORA) – ICT Risk Management Framework
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
PCI DSS 4.0 – User Authentication
Control ID: 8.2.1
ISO 27001:2022 – User Registration and Deregistration
Control ID: A.9.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
AI model intellectual property theft through industrial-scale distillation attacks threatens competitive advantage, requiring enhanced API security and egress traffic monitoring capabilities.
Information Technology/IT
Sophisticated bypass techniques using fraudulent accounts and proxy infrastructure expose API vulnerabilities, demanding zero trust segmentation and anomaly detection implementations.
Research Industry
Chain-of-thought reasoning extraction and automated failover systems compromise proprietary AI research models, necessitating enhanced threat detection and policy enforcement mechanisms.
Computer/Network Security
Multi-vector distillation campaigns exploiting cloud services and aggregators highlight critical gaps in behavioral detection and cross-platform security intelligence sharing requirements.
Sources
- US says Chinese firms extracted billions of tokens from frontier AI modelshttps://www.bleepingcomputer.com/news/security/us-says-chinese-firms-extracted-billions-of-tokens-from-frontier-ai-models/Verified
- Chinese AI Companies Conduct Industrial-Scale Distillation Against U.S. AI Modelshttps://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251aVerified
- Google says hackers are abusing Gemini AI for all attack stageshttps://www.bleepingcomputer.com/news/security/google-says-hackers-are-abusing-gemini-ai-for-all-attacks-stages/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this industrial-scale AI model distillation attack by constraining distributed proxy access and limiting east-west movement between cloud services and API endpoints.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud-native security fabric would likely constrain the attackers' ability to establish distributed access patterns across multiple AI service providers by enforcing identity-aware routing policies and reducing the scope of cross-service connectivity from compromised endpoints.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely reduce the attackers' ability to rapidly scale usage across multiple API endpoints by constraining workload-to-workload communications and limiting the blast radius of privilege escalation attempts within cloud environments.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely constrain the attackers' ability to seamlessly switch between different AI service providers and cloud platforms by enforcing inspection and policy controls on inter-service communications within and across cloud environments.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility and control would likely reduce the attackers' ability to maintain coordinated automated systems across distributed infrastructure by providing centralized policy enforcement and constraining the scope of cross-cloud command and control communications.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely constrain the massive scale of token extraction by enforcing data loss prevention policies and limiting the volume and frequency of outbound API responses containing sensitive model information.
While some intellectual property exposure would likely remain, the constrained extraction scope and reduced blast radius would limit the completeness of stolen model knowledge and potentially reduce the competitive advantage gained from the distillation attack.
Impact at a Glance
Affected Business Functions
- AI Model Development and Research
- Proprietary Algorithm Protection
- Competitive Intelligence Safeguarding
- Intellectual Property Management
Estimated downtime: N/A
Estimated loss: $500,000,000
Billions of tokens extracted from frontier AI models including proprietary chain-of-thought reasoning, model logic, and training methodologies from Anthropic Claude, OpenAI GPT, Google Gemini, and xAI Grok models. The exposed intellectual property represents years of AI research and development investments.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation and identity-based policies to prevent unauthorized API access patterns and detect account sharing across multiple IP addresses and user agents
- • Deploy egress security controls with FQDN filtering and data loss prevention to monitor and block suspicious outbound traffic to unauthorized AI model aggregators and transfer stations
- • Enable multicloud visibility and anomaly detection to identify continuous automated activity without normal human idle periods and coordinated switching between access routes
- • Establish encrypted traffic inspection and inline threat detection to identify and block industrial-scale token extraction patterns and chain-of-thought reasoning attempts
- • Implement cloud native security fabric controls with real-time policy enforcement to detect and prevent shadow AI usage and unauthorized model distillation activities



