Quoted claim
The claim after Anthropic's September 2026 threat report: a single, verified picture of how Claude was misused, including industrial-scale distillation by named China-based labs (Alibaba, Moonshot, DeepSeek, Xiaomi, and others).
Where made
Primary: Anthropic, "Detecting and countering misuse of AI: September 2026", published about 10 September 2026. Scope stated by Anthropic: activity disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Models: Haiku, Sonnet, Opus. Anthropic says none of the misuse cases involved Fable or Mythos-class models except one illicit distillation case.
TechCrunch (10 September) and The Hacker News restated the report. Those are restatements of Anthropic, not second measurements.
Supporting number / method
File A. What Anthropic says it banned. Company investigation plus published indicators, not court findings. Three cases carry the weight. The rest of the IOC table is in the report.
GTG-20006 is the Russian-nexus espionage cluster Anthropic calls "consistent with public reporting linking the actor to Midnight Blizzard." Anthropic says more than 20 organizations were in planning or ops (Ukraine and Europe governments, drone supply chain), and that a North African government tech authority lost more than 300,000 national identity records and commercial registry data for more than 500,000 companies. Those counts are Anthropic's.
GTG-50014 is the ShinyHunters-affiliate smash-and-grab: credential harvesting across about 1.8 million Android APKs, terabyte-scale exfil claims, airline, energy, and SaaS examples. Anthropic says it banned associated accounts.
GTG-10007 is the Changsha exploit-foundry cluster: about 50 organizations, autonomous vulnerability research, a collection fleet of 13 scheduled agents.
The report also lists fraudulent Claude resellers and stolen customer API keys (GTG-50021 / GTG-50020; Anthropic says its own systems were not compromised) and nine influence-ops cases (including GTG-54002, about 70 fake news sites and 8,913 articles). Treat those as additional rows in Anthropic's table, not as separately verified campaigns.
File B. Illicit distillation attributions (Anthropic "high confidence"). Keep separate. Anthropic: since February 2026, unauthorized distillation campaigns attributed to PRC-based labs targeting Opus-class models.
| Anthropic ID | Attributed lab | Scale (Anthropic's counts) | Method claim (Anthropic's) |
|---|---|---|---|
| GTG-16005 | Alibaba (Qwen / Tongyi) | More than 151M exchanges May-Jul 2026; peak about 3M/day; more than 3,500 fraudulent accounts | Fixed prompt to exfil Opus 4.6/4.7 chain of thought for SFT into Qwen 3.5-3.7 |
| GTG-16002 | Moonshot (Kimi) | More than 23M exchanges May-Jul; about 300k customer requests relayed in 10 days via 5,380 accounts | Silent forward of customer prompts; chain-of-thought extraction via cross-session replay |
| GTG-16001 | DeepSeek | More than 12.1M exchanges over 14 days in July | Silent relay; third-party harness traffic routed to Opus |
| GTG-16006 | Zhipu (Z.ai) | More than 3.4M exchanges over 17 days Jun-Jul; 770,609 through a chain-of-thought "cleaner" in 10 days | Chain-of-thought cleaner for GLM |
| GTG-16008 | Xiaomi | More than 400k exchanges over 20 days Mar-Apr | Replay MiMo user sessions into Claude for SFT/RL |
| GTG-16012 / 16003 | SenseTime / MiniMax | Reseller / purchased transcript ecosystem | Bought transcripts; MiniMax shell proxy |
TechCrunch's "nearly 200 million exchanges" across five campaigns adds Anthropic's File B figures together. It is not an independent telemetry audit.
Not independently verified: admissions from Alibaba, Moonshot, DeepSeek, Xiaomi, Zhipu, SenseTime, or MiniMax; third-party replication of the exchange counts; customer notices from Moonshot or DeepSeek confirming relay. Anthropic says it does not know if customers were notified.
What would have to be true
For the report to be one verified ledger, distillation attributions would need independent telemetry, regulator findings, or named-lab admissions matching Anthropic's GTG tables. File A IOCs can drive detection engineering today. File B should drive vendor diligence and a rule against merging counts, not a single headline for "Chinese labs stole Claude."
Verdict
overstated if the September report is treated as a single verified threat ledger that settles Alibaba, Moonshot, DeepSeek, and Xiaomi guilt at the published exchange counts.
supported as Anthropic's own disruption-and-IOC narrative for the cyber, influence, and supply-chain GTGs it says it banned, if distillation stays in a separate, attributed file.
Independent confirmation of distillation scale remains UNKNOWN.
Language we will use instead
Anthropic's September threat report is company threat intelligence. We cite GTG case IDs and IOC tables as Anthropic's. Distillation figures for Alibaba (more than 151M), Moonshot (more than 23M), DeepSeek (more than 12.1M), Xiaomi (more than 400k), and related labs stay labeled Anthropic attributions. They are not verified disruptions in the same sense as an account ban Anthropic controlled. We do not merge File A bans with File B alleged distillation into one Claude-misuse count.