Korean Stock & Equity Research

Data-driven analysis of Korean listed companies, combining financial fundamentals with supply chain and operations insights. Not investment advice.

  • 2026. 9. 21.

    by. Koreanalysis Team

    Table

      반응형

      Anthropic's September 10, 2026 threat report accuses seven China-based AI labs of running large-scale campaigns to extract Claude's capabilities — and two of them, Moonshot's Kimi and DeepSeek, allegedly went further, secretly rerouting real user queries to Claude's own servers and showing users the responses as if they were their own models' work. That rerouting, if accurate, is what turned an intellectual-property dispute into something closer to a data-security incident, since it means whatever users typed into Kimi or DeepSeek may have passed through a US company's infrastructure without their knowledge.

      반응형

      What Exactly Did Anthropic Accuse These Companies Of?

      Anthropic's report identifies seven distinct campaigns, tracked since February 2026, totaling roughly 190 million exchanges with Claude. The largest, attributed to Alibaba, involved more than 151 million exchanges between May and July 2026, peaking near 3 million requests a day, run through more than 3,500 fraudulent accounts using a fixed prompt designed to extract Claude's chain-of-thought reasoning for training Alibaba's Qwen models. Moonshot AI (the maker of the Kimi assistant) generated more than 23 million exchanges over the same window through roughly 5,380 fraudulent accounts, largely registered in Singapore and Japan. DeepSeek's campaign was more concentrated: over 12 million exchanges in just 14 days in July 2026. Smaller campaigns were attributed to Zhipu/Z.ai, Xiaomi, SenseTime, and MiniMax.

      What separates Moonshot and DeepSeek from the others is the routing allegation. Rather than only scraping Claude's outputs to train their own models offline, Anthropic says these two companies covertly forwarded live, real user requests to Claude, then displayed Claude's answers to their own users as if they had come from Kimi or DeepSeek — reportedly around 300,000 real customer requests routed this way over a 10-day period in Moonshot's case.

      How Sensitive Was the Data That Got Exposed?

      According to Anthropic's report, the practical consequence of that routing was that several categories of sensitive Chinese data ended up passing through Claude's systems without the original users' knowledge. The report describes a user believed to be affiliated with the People's Liberation Army who uploaded surveillance footage from hundreds of cameras in Chengdu — including cameras outside PLA facilities and China Electronics Technology Group Corporation installations — while apparently believing they were using Kimi. It also describes an engineer at a major Chinese state-owned enterprise who exposed internal source code and active login credentials while building internal systems, and engineers building a case-management tool for a municipal Public Security Bureau that linked citizens' national ID numbers to their movements and police records, reportedly using DeepSeek. Separately, the report says an IT operator exposed live credentials tied to a Russian government database connected to Russia's Ministry of Defense.

      Where the Seven Campaigns Stack Up

      Company Scale Method
      Alibaba (Qwen) 151M+ exchanges, 3,500+ accounts Offline training-data extraction
      Moonshot AI (Kimi) 23M+ exchanges, 5,380 accounts Extraction + live user-query rerouting
      DeepSeek 12M+ exchanges in 14 days Live user-query rerouting
      Zhipu / Xiaomi / SenseTime / MiniMax Under 4M exchanges each Mix of proxy access, purchased transcripts

      ⚠️ This is Anthropic's own account, not an independently verified investigation

      Every figure and incident above comes from Anthropic's own threat intelligence report — the accuser in this dispute. As of this writing, no independent third-party security audit has confirmed these specific findings, and no on-the-record response, denial, or confirmation from Alibaba, Moonshot, or DeepSeek has surfaced in Western press coverage. That doesn't mean the report is wrong — Anthropic has a strong incentive to be accurate given the reputational and legal stakes of publishing false claims about named competitors — but readers should treat the specific data-exposure details as one company's documented allegations rather than settled fact until independently corroborated.

      Wasn't Korea Already Worried About Exactly This?

      In a sense, yes — and this is the part of the story with the clearest Korea angle. In February 2025, Korea's Personal Information Protection Commission (PIPC) pulled DeepSeek from Korean app stores after finding the company had transferred domestic user data abroad without proper consent. DeepSeek was unavailable in Korea for roughly two months before returning in April 2025, after updating its policies to comply with Korea's Personal Information Protection Act and giving users the ability to refuse having their data transferred to companies based in China or the United States — with the PIPC stating it would continue monitoring DeepSeek's compliance going forward.

      That earlier episode was about DeepSeek transferring Korean user data to its own servers in China. What Anthropic's report now alleges is a different and, in some ways, more surprising twist: user data that people believed was staying within a Chinese AI app's own systems may have instead been forwarded to a US company's servers, without the app disclosing that redirection to anyone. For Korean regulators who were already treating DeepSeek's data-handling practices with active suspicion, this is exactly the kind of development likely to justify continued, rather than relaxed, scrutiny.

      ✅ What to watch from here

      • Whether Alibaba, Moonshot, or DeepSeek issue any formal on-record response, denial, or confirmation to Anthropic's report.
      • Whether Korea's PIPC or MSIT issue any fresh guidance on DeepSeek, Kimi, or other Chinese AI apps in light of this report, given the PIPC's stated intent to keep monitoring DeepSeek's compliance.
      • How this affects Alibaba specifically, since it is US-listed and already under close investor scrutiny — reputational disputes tied to data practices and IP theft claims can move sentiment even without regulatory action.

      If Anthropic's account holds up, the real story here isn't that Chinese AI labs tried to copy a competitor's model — it's that some of their users' data may have ended up somewhere those users never agreed to send it.

      What Should Investors Watch Next?

      This dispute sits alongside Anthropic's broader push this quarter for industry-wide AI safety standards, including CEO Dario Amodei's early-September call for a coordinated pacing plan across AI labs — a story Koreanalysis has covered separately, including its connection to SK Telecom's equity stake in Anthropic. Whether this distillation report becomes a factor in that broader safety-standards push, or stays a narrower commercial and diplomatic dispute between Anthropic and its Chinese rivals, is worth watching over the coming weeks.

      Frequently Asked Questions

      Q1. What did Anthropic accuse Chinese AI labs of doing?

      A. Anthropic's September 2026 report accuses seven China-based AI labs — including Alibaba, Moonshot AI (Kimi), and DeepSeek — of running large-scale campaigns using fraudulent accounts to extract Claude's outputs for training their own models, totaling roughly 190 million exchanges since February 2026. It further alleges that Moonshot and DeepSeek secretly rerouted some real user queries to Claude and passed the responses off as their own.

      Q2. Is it true that sensitive Chinese military and police data was exposed to Claude?

      A. That is what Anthropic's report claims, describing incidents involving PLA-linked surveillance footage, a Public Security Bureau tracking tool, and exposed corporate and Russian government credentials. These are Anthropic's own findings and have not been independently verified by a third party or confirmed by the companies named as of this writing.

      Q3. Has Korea taken any action against DeepSeek or similar Chinese AI apps?

      A. Yes. Korea's Personal Information Protection Commission suspended DeepSeek from Korean app stores in February 2025 over unauthorized data transfers abroad, and it returned in April 2025 after policy changes, with the PIPC stating it would continue monitoring compliance.

      If Anthropic's account holds up, the real story here isn't that Chinese AI labs tried to copy a competitor's model — it's that some of their users' data may have ended up somewhere those users never agreed to send it.
      반응형