Anthropic accused Alibaba Group (NYSE: BABA) of orchestrating the largest known attempt to illicitly extract capabilities from its Claude AI models, detailing a coordinated scraping campaign that generated nearly 29 million exchanges over six weeks through tens of thousands of fake accounts.
In a letter first reported by Bloomberg and dated June 10, Anthropic told the Senate Banking Committee that operators affiliated with Alibaba and its AI lab, Alibaba Qwen, used nearly 25,000 fraudulent accounts to conduct 28.8 million exchanges with Claude between April 22 and June 5.
The operation specifically targeted Claude’s most commercially valuable capabilities — software engineering and agentic reasoning — in what Anthropic called “the largest known distillation attack on Anthropic to date.”
The method Anthropic describes is known as adversarial distillation — systematically querying a more advanced AI model at scale to harvest its outputs, then using those outputs to train a competing model at a fraction of the original development cost.
Unlike conventional IP theft, it requires no access to source code. Anthropic warned that models built this way often lack the safety guardrails of the originals, creating risks that extend beyond intellectual property loss.
This is a really massive unauthorized distillation campaign.
— Kyle Chan (@kyleichan) June 24, 2026
For comparison, reported from Anthropic:
– DeepSeek: 150,000 exchanges
– Moonshot: 3.4 million
– MiniMax: 13 million
– Alibaba: 28.8 million https://t.co/1dIHlAfML0
The letter, addressed to Committee Chair Sen. Tim Scott, R-S.C., and Ranking Member Sen. Elizabeth Warren, D-Mass., said Alibaba “ignored the Trump Administration’s warnings” in proceeding with the campaign. It was sent ahead of a scheduled Senate hearing on AI and simultaneously shared with White House officials.
Alibaba faces compounding pressure in Washington. The company was added to the Pentagon’s blacklist of businesses alleged to support China’s armed forces earlier this month — a designation it is contesting in federal court. Anthropic’s letter cited that listing directly.
The Alibaba operation dwarfs prior attacks Anthropic has disclosed. In February 2026, the company revealed distillation campaigns by three Chinese AI labs: DeepSeek generated more than 150,000 exchanges, Moonshot AI generated more than 3.4 million, and MiniMax generated more than 13 million. The Alibaba operation generated more than 28.8 million exchanges — nearly 75% more than the combined total of all three prior campaigns.
Two days after Anthropic sent the letter, on June 12, the Commerce Department imposed export restrictions on its most advanced Fable 5 and Mythos 5 models, blocking access by any foreign national — including Anthropic’s own foreign national employees — over concerns the models could be used by military and intelligence organizations in China and other countries of concern.
Read: Anthropic Suspends Fable 5 Access After US Government Export Control Order
Anthropic disabled access to the models globally. As of this week, the company said little progress had been made with White House officials to restore access.
As of this writing, Alibaba has not officially commented on the matter. The company’s shares fell nearly 3% on Wednesday and have lost 32% year-to-date.
Anthropic used the letter to urge Congress to clarify antitrust guidelines so US companies can share threat intelligence on distillation attacks more freely. “Distillation attacks turn hundreds of billions of dollars in American investment and R&D into a massive subsidy for our geopolitical competitors,” the company wrote.
Anthropic — currently valued at $965 billion in private markets and preparing for an IPO — said the threat requires coordinated action from industry, cloud providers, and policymakers.