Skip to main content
Chinese AI lab's fake accounts, 5,380, funnel 300,000 user queries to Anthropic. Data breach.

Editorial illustration for Chinese AI labs used 5,380 fake accounts to relay 300,000 user queries to Anthropic

Chinese AI Labs Used 5,380 Fake Accounts on Claude

3 min read

Anthropic's latest threat intelligence report, covering December 2025 through August 2026, reads less like a product update and more like a case file. The company says it caught 5,380 fake accounts, tied to Chinese AI labs, funneling roughly 300,000 queries through Claude to harvest training data or quietly reroute their own customers' traffic. Alibaba and DeepSeek both show up in the findings, accused of running covert networks that pulled sensitive material, including government surveillance data, through the pipeline.

The report sorts misuse into seven buckets: cyber operations, influence campaigns, surveillance, fraud, biological misuse, conventional weapons work, and unauthorized model distillation. Haiku, Sonnet, and Opus took the brunt of the abuse, while Anthropic's newer Fable and Mythos models turned up in just one distillation case. The company says it's flagging novel misuse patterns rather than routine scams, and that's the frame for the cyber chapter that follows: attacks that used to require skilled operators now don't, which means sophistication itself has stopped being a useful clue for figuring out who's actually behind an intrusion.

Anthropic's new threat report documents eight months of Claude abuse: espionage, nationwide surveillance, weapons software, and distillation by Chinese AI labs.

Why this matters

Anthropic's own numbers tell the story better than any statement from the company could: 5,380 fake accounts, 300,000 relayed queries, ten days. That's not a leak, it's a supply chain. Moonshot AI and DeepSeek weren't jailbreaking Claude for fun, they were farming it for training data while dressing the traffic up as ordinary Kimi users.

For developers building on frontier APIs, this is a reminder that usage terms and geofencing are speed bumps, not walls, against a determined competitor with engineering resources. For founders, it's a preview of how the next generation of Chinese models might get built, on the back of the labs they're supposedly racing against. For researchers, the harder question is about detection: DeepSeek was apparently fingerprinting harness strings to dodge scrutiny, which means the cat-and-mouse game is already fairly sophisticated on both sides.

Anthropic caught this round. Whether that's because its detection is genuinely good or because 5,380 accounts is a clumsy scale of operation is worth watching the next time a report like this drops.

Common Questions Answered

How many fake accounts did Chinese AI labs use to access Anthropic's Claude?

According to Anthropic's threat intelligence report, Chinese AI labs created 5,380 fake accounts to relay approximately 300,000 queries through Claude over an eight-month period from December 2025 through August 2026. These accounts were used to harvest training data and redirect customer traffic without authorization.

Which Chinese AI companies were identified in Anthropic's threat report?

Anthropic's findings specifically named Alibaba, DeepSeek, and Moonshot AI as companies running covert networks to mine Claude for training data. These labs were accused of funneling traffic through fake accounts while disguising it as ordinary user queries from their own customers.

What types of sensitive material were extracted through the fake Claude accounts?

The threat report documents that the fake accounts were used to access sensitive material including government surveillance data, weapons software development, and information related to missile systems and drone swarms. This represents a significant security breach involving both espionage and misuse of the AI platform for weapons-related purposes.

Why does Anthropic consider usage terms and geofencing insufficient protection against this type of attack?

Anthropic's findings demonstrate that determined actors can circumvent usage restrictions and geographic limitations through coordinated fake account networks and traffic obfuscation. The company's conclusion suggests that traditional security measures like terms of service and location-based access controls function as mere speed bumps rather than effective barriers against sophisticated, well-resourced threat actors.

LIVE17:12Meta AI Suggested Invasive Question After User's Cross-Post