Anthropic Accuses Alibaba of "Distilling" Claude: 25,000 Fake Accounts
On June 24, 2026, Anthropic, the company behind the AI assistant Claude, went public with an explosive file: it accuses the Chinese giant Alibaba of "illicitly" extracting the capabilities of its Claude models. According to Anthropic, operators tied to Alibaba’s Qwen AI lab used roughly 25,000 fake accounts to run close to 28.8 million exchanges with Claude between April 22 and June 5, 2026.
Anthropic calls it the largest "distillation" campaign ever detected against its models. The term is technical, but the story touches something every company using AI tools should care about: who really owns a model’s capabilities, and what happens when someone tries to copy them without permission. Here is a plain explanation of what happened, and why it is worth a few minutes of your attention even as a small business in Quebec.
Quick answer: Anthropic accuses Alibaba of creating 25,000 fake accounts to query Claude 28.8 million times and copy its strongest capabilities (code, reasoning, complex tasks). Anthropic wrote to American lawmakers. Alibaba has not commented on these specific allegations, which have not been independently verified. For a business, the lesson is clear: AI tools come with rules of use, and account security matters more than ever.
1. What exactly Anthropic accuses Alibaba of
In a letter addressed to American officials, Anthropic states that operators affiliated with Alibaba and its Qwen lab deployed thousands of fraudulent accounts to get around its access restrictions. The goal, according to Anthropic: query Claude millions of times in order to harvest its answers and put them to use.
The figures Anthropic puts forward are specific:
- Roughly 25,000 fraudulent accounts used to hide the activity.
- 28.8 million exchanges with the Claude models.
- A concentrated window between April 22 and June 5, 2026.
- A precise target: Claude’s most advanced capabilities, namely software development, agentic reasoning and planning long, complex tasks.
Anthropic describes the operation as "brazenly" and "illicitly" carried out. Some caution is in order, though: at this stage these are one party’s allegations. Alibaba has not responded publicly to these specific accusations, and several outlets note that the facts have not been independently verified. What follows is Anthropic’s version, not a verdict.

2. What is "distillation", exactly?
The word sounds academic, but the idea is simple. Distilling an AI model means training a weaker model to imitate the answers of a stronger one. Instead of building the intelligence from scratch, you ask the leading model millions of questions, collect its answers, and use them to school a more modest model until it starts to resemble the original.
Anthropic calls this case "adversarial distillation": in its telling, the operators multiplied fake accounts precisely to slip past the guardrails and vacuum up as many answers as possible without being spotted. Picture watching an expert at work in secret for weeks in order to copy their method, except here the scale runs into tens of millions of interactions.
This kind of practice raises two fundamental questions for the industry:
- Ownership of capabilities: training frontier models costs a fortune. Copying them cheaply changes the competitive balance.
- Respect for the terms of service: most AI providers explicitly forbid using their outputs to train a rival model.
This is not the first episode of its kind either. Back in February 2026, Anthropic reported spotting three "industrial scale" distillation campaigns tied to other labs. The Alibaba case marks, in Anthropic’s view, a sharp step up in scale.
3. Why this story goes beyond Anthropic and Alibaba
At first glance it looks like a squabble between two technology giants. The matter has reached the United States Congress, though. According to several sources, lawmakers are considering adding an amendment to a defence bill to sanction entities that run this kind of campaign. Distillation is moving from a technical debate into political and regulatory territory.
For a business here at home, three takeaways are worth keeping:
- AI has become a strategic asset. A model’s capabilities are now guarded the way you would guard an industrial recipe or a client database.
- Account abuse is a real threat. Twenty-five thousand fake accounts is not a rounding error. Mass creation of fraudulent accounts is exactly the kind of activity your own systems should be able to detect.
- Terms of service matter. When your business connects an AI tool to its data, knowing what the provider allows and forbids is not a legal footnote, it is risk management.
This is precisely the grey zone where an IT partner helps you see clearly. Our managed IT services include guidance on choosing and governing the cloud and AI tools you adopt, so there are no unpleasant surprises later.
![]()
4. What your business can take from this in practice
You do not need to train AI models to draw lessons from this case. Here are simple, useful steps whatever the size of your company:
- Read the terms of use for AI tools before you connect them to sensitive data. Know what is permitted with your information.
- Protect your access. Two-factor authentication and strong passwords cut the odds that your own accounts get used for questionable activity.
- Watch for unusual behaviour. A sudden spike in sign-ins or in account creation is a signal you should not ignore.
- Centralize your tools. A handful of well-governed solutions beats a dozen AI applications each employee has connected on their own.
- Pick serious providers. The fact that Anthropic detected the campaign and acted on it shows why it pays to work with vendors who actually watch how their platforms are used.
There is an encouraging irony in this story: if Claude attracts this kind of interest, it is precisely because its abilities in code, reasoning and task automation are among the strongest on the market. For a small business, the point is not to copy those capabilities but to use them safely and with proper controls.
Frequently asked questions
What is AI model distillation?
It is a technique that trains a weaker model to imitate the answers of a more advanced one. You query the leading model heavily, collect its answers, then use them to bring a more modest model closer to its performance. Most AI providers forbid it in their terms of service.
Has Alibaba acknowledged any of this?
No. As of this writing, Alibaba has not commented publicly on these specific allegations. Several outlets note that Anthropic’s accusations have not been independently verified. This is one side’s account, and it is worth following over the coming weeks.
Does this make Claude less trustworthy for my business?
Not at all. The case concerns an attempt to extract the model’s capabilities, not a flaw that would expose your data. If anything, the fact that Anthropic detected the activity and reacted quickly points to active monitoring of its platform. As always, what matters is how you govern the way these tools connect to your information.
Stay ahead of AI without flying blind
News about Claude and artificial intelligence arrives fast, and not all of it carries the same weight for a business. Our job is to filter the noise and help you adopt the right tools, the right way, with the right guardrails. Take a look at our managed IT services for businesses, or write to us through our contact page: we take the time to answer your questions about AI, security and the cloud, without needless jargon.
Sources: CNBC · Tom’s Hardware · Bloomberg · The Next Web · OKTO Solutions
Reading about AI is one thing. Connecting it to your own data is another: artificial intelligence in business, custom AI application development and our IT services in Quebec City.