Anthropic’s September 2026 threat-intelligence report describes Claude misuse it says it identified and disrupted between December 2025 and August 2026. TechCrunch and CNBC-TV18, reporting on that document, said Anthropic attributed 151 million Claude exchanges from May to July 2026 to an Alibaba campaign aimed at producing training material for Alibaba’s Qwen models. Anthropic’s own report page frames the period across seven harm areas, including illicit distillation; the 151 million figure and Alibaba attribution appear in secondary coverage of the report rather than in the truncated primary page retrieved for this story.

TechCrunch said the traffic peaked at nearly three million exchanges per day and was spread across 3,500 accounts that shared a single fixed prompt used to extract chain-of-thought. CNBC-TV18 said the transcripts were converted into supervised fine-tuning data used to help train Qwen 3.5, 3.6, and 3.7. CNBC-TV18 also said the allegations against Alibaba come solely from Anthropic’s investigation, have not been independently corroborated, and that Anthropic does not disclose the technical basis for attributing the campaign to Alibaba. Retrieved September coverage said Alibaba had not publicly responded.

TechCrunch said Anthropic observed nearly 200 million exchanges linked to distillation attacks, attributed to five separate campaigns. CNBC-TV18 said Alibaba is one of seven China-based labs Anthropic says it has identified running such campaigns against Claude since first disclosing the practice in February 2026, and that the report also names DeepSeek, Moonshot AI, Xiaomi, Zhipu (Z.ai), SenseTime, and MiniMax.

TechCrunch reported that a campaign from Moonshot AI, maker of Kimi, seemed to route requests directly from the Chinese military, including a query asking Claude to assess CCTV footage for abnormal behavior. Over one 10-day period, Anthropic says nearly 300,000 requests were routed to Claude through a network of 5,000 accounts, primarily targeting Anthropic’s Opus model, TechCrunch reported. CNBC-TV18 said shared proxy infrastructure funneled requests for DeepSeek and Xiaomi after an Alibaba-linked account pool was banned. Those routing details rest on Anthropic’s account as relayed by trade press.

On its report page, titled “Detecting and countering misuse of AI: September 2026,” Anthropic said the document covers activity it disrupted across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Anthropic said Claude Haiku, Sonnet, and Opus models were used, and that none of the misuse cases involved Claude Fable or Mythos-class models except one illicit distillation case. The company said that in each case it disrupted the activity, used what it learned to strengthen safeguards, and shared intelligence with authorities and industry partners where appropriate.

Separately, Anthropic described an actor it tracks as GTG-20006. The company said its attribution is consistent with public reporting linking the actor to Midnight Blizzard. Anthropic said the actor used AI-automated workflows against Ukrainian and European government, diplomatic, and defense targets. It said the actor bulk-exported the mailboxes of at least two drone component manufacturers, targeted a military drone maker, and stole a complete proprietary software development kit for a drone vision system.

The 151 million-exchange figure is distinct from an earlier Anthropic allegation. Business Insider and Decrypt reported that a June 10, 2026 letter from Anthropic to Senate Banking Committee Chair Tim Scott and Ranking Member Elizabeth Warren alleged that operators affiliated with Alibaba and its Qwen AI lab generated more than 28.8 million exchanges with Claude between April 22 and June 5 through almost 25,000 fraudulent accounts. Tech Times said the letter was first reported by Bloomberg on June 24. The Next Web reported at the time that Alibaba had no comment on the allegations.

If Anthropic’s attribution holds, the September figures describe industrial-scale extraction of Claude reasoning traces for rival model training, alongside separate cyber-espionage cases in the same brief. What remains contested is the Alibaba link itself: the public case rests on Anthropic’s investigation as summarized by TechCrunch and CNBC-TV18, without an independent audit of the attribution method and without a retrieved public reply from Alibaba.