U.S. cybersecurity agencies accused several Chinese artificial-intelligence companies on Tuesday of conducting industrial-scale extraction of capabilities from American frontier AI models, a campaign they say was carried out with the knowledge of the Chinese government and aimed at narrowing the technology gap while cutting development costs.
The Cybersecurity and Infrastructure Security Agency, National Security Agency and Federal Bureau of Investigation released an advisory detailing how the companies used multiple routes — including APIs, cloud providers, third-party aggregators and a gray-market network of proxies known as "transfer stations" — along with fraudulent accounts, bulk subscriptions and automated systems to evade detection.
The campaigns, which the agencies said extracted "billions of tokens across millions of exchanges from U.S. models since at least late 2024," targeted reasoning, coding, agentic functions and question-and-answer optimization, according to the advisory.
DeepSeek ran organized campaigns aimed at developing its R1 and V3 models by targeting U.S. systems including Claude, Gemini, GPT and Grok, the advisory said. Alibaba used industrial-scale distillation to improve its Qwen family of models. The advisory also named Moonshot AI, MiniMax, StepFun and Z.AI as entities implicated in the activity.
Alibaba and MiniMax are listed on the Hong Kong exchange under tickers 9988 and 0100 respectively; Z.AI trades under 2513 on the same bourse. The other firms are privately held.
The agencies recommended that U.S. AI companies strengthen monitoring for anomalous usage, alter responses to suspected distillation attempts and share intelligence across model providers, cloud platforms and API aggregators.
The advisory comes amid escalating tensions between Washington and Beijing over technology competition, raising fresh questions about the security of proprietary AI systems and the safeguards protecting them from state-backed extraction efforts.












