Three US agencies have accused DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI of running industrial-scale campaigns to extract capabilities from American frontier models. The NSA, CISA and FBI say the activity has targeted variants of Claude, GPT, Gemini and Grok since at least late 2024, and likely occurred with Chinese government awareness. The named companies’ responses were not included in the report.
The agencies describe networks of fraudulent accounts sending thousands or millions of coordinated prompts, sometimes through proxy services that evade geographic restrictions. They also cite jailbreak prompts intended to make models reveal hidden reasoning, with outputs then used as synthetic training data.
Recommended defenses include stronger user verification, monitoring unusual subscription and traffic patterns, and sharing indicators across companies and allied governments. The guidance also suggests secretly switching suspected accounts to weaker models or altering response depth so extracted data is less valuable.
Those measures carry risks for legitimate customers. False positives could reduce answer quality without warning, while tighter identity checks raise privacy concerns. The agencies acknowledge that providers will have to balance security with user experience and should disclose model changes to safety researchers and independent evaluators.