Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
U.S. Claims China AI Firms Exploit Top American Models

U.S. Claims China AI Firms Exploit Top American Models

Posted on September 9, 2026 By CWS

U.S. cybersecurity and intelligence agencies have issued serious allegations against Chinese AI companies, accusing them of large-scale exploitation of American AI models. According to a joint bulletin from the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI), these firms have been involved in ‘systematic extraction’ of proprietary functions from leading U.S. AI technologies through distillation attacks.

Industrial-Scale Exploitation of AI Models

The U.S. agencies describe these actions as integral to the development strategies of Chinese AI firms, with operations occurring on an industrial scale. While distillation is a standard technique in AI research, the agencies claim that companies in China are using it maliciously to extract restricted features from U.S. frontier AI models. The bulletin highlights that firms such as DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have been involved in these activities since late 2024.

These companies allegedly saved costs by purchasing premium subscriptions from U.S. AI providers and sharing them among development teams. Their tactics include extracting chain-of-thought reasoning, employing automated failover methods during blocking attempts, and utilizing advanced quality evaluation frameworks to bypass defensive measures.

Specific Allegations Against Chinese Firms

The NSA, CISA, and FBI outlined specific instances of these distillation activities. DeepSeek reportedly targeted reasoning capabilities to develop its R1 and V3 models, while Moonshot AI extracted Claude Fable 5 data for its Kimi-K3 model and GPT-4o data for Kimi-K2. Alibaba is accused of distilling several Claude and GPT variants to enhance its models’ functionalities. MiniMax and StepFun have also been implicated in similar activities aimed at improving their respective AI capabilities.

Z.AI is noted for extracting billions of tokens from GPT-5.5 and Claude Opus 4.8 to refine its CoT reasoning features. These unauthorized access attempts violate the terms of service of the U.S. models, often involving APIs, remote cloud services, and third-party aggregators to conceal user data.

Countermeasures and Broader Implications

This ongoing situation has led U.S. agencies to advise AI companies on strengthening their security measures. Suggested actions include implementing detection systems for distillation attempts, modifying responses to potential threats, and correlating activities across various platforms to identify distributed campaigns.

Ismael Valenzuela, Vice President of Labs, Threat Research, and Intelligence at Arctic Wolf, emphasized the need for coordinated responses against these sophisticated adversaries, noting the challenges posed by the replication of advanced AI features by Chinese firms. He warned that even businesses not directly linked to frontier AI models should be aware of the potential risks, as access abuse could appear legitimate, posing broader security threats.

The situation underscores the importance of vigilant cybersecurity defenses and international collaboration to safeguard technological advancements from unauthorized exploitation.

The Hacker News Tags:AI, Alibaba, China, CISA, Cybersecurity, DeepSeek, distillation attacks, FBI, Moonshot AI, NSA, U.S. models

Post navigation

Previous Post: AI-Powered Cyberattack Exploits PaperCut Vulnerabilities
Next Post: Google Releases Patches for 180 Android Vulnerabilities

Related Posts

BKA Unveils Key Figures in REvil Ransomware Operations BKA Unveils Key Figures in REvil Ransomware Operations The Hacker News
SideCopy Targets Afghan Finance Ministry with Xeno RAT SideCopy Targets Afghan Finance Ministry with Xeno RAT The Hacker News
BengalSEO Campaign Exploits Bing for Malware and Scams BengalSEO Campaign Exploits Bing for Malware and Scams The Hacker News
Managing Shadow AI Tools Efficiently in the Workplace Managing Shadow AI Tools Efficiently in the Workplace The Hacker News
State-Sponsored Hackers Exploiting Libraesva Email Security Gateway Vulnerability State-Sponsored Hackers Exploiting Libraesva Email Security Gateway Vulnerability The Hacker News
40 npm Packages Compromised in Supply Chain Attack Using bundle.js to Steal Credentials 40 npm Packages Compromised in Supply Chain Attack Using bundle.js to Steal Credentials The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Job Offers on LinkedIn to Spread Malware
  • HelmGuard Secures $7.3M to Enhance AI Governance and Security
  • Microsoft Defender Vulnerability Bypass Exposed
  • ClearFake Crypto Stealer Exploits Vulnerabilities
  • Google Releases Patches for 180 Android Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Job Offers on LinkedIn to Spread Malware
  • HelmGuard Secures $7.3M to Enhance AI Governance and Security
  • Microsoft Defender Vulnerability Bypass Exposed
  • ClearFake Crypto Stealer Exploits Vulnerabilities
  • Google Releases Patches for 180 Android Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark