Anthropic links Alibaba to campaign for training Qwen models

The September threat intelligence report describes 3,500 fraudulent accounts aggregating nearly 3 million daily exchanges with Opus 4.6 and 4.7, attributed to Alibaba for training Qwen versions 3.5, 3.6, and 3.7.
On September 10, Anthropic published its most detailed threat intelligence report to date. The document covers disrupted operations between December 2025 and August 2026 across seven areas of harm, but the most severe case, cataloged as GTG-16005, is linked to Alibaba. In this case, over 3,500 fraudulent accounts aggregated nearly 3 million daily exchanges from Claude Opus 4.6 and 4.7, totaling 151 million interactions between May and July 2026. The transcripts, according to the report, were used to train Qwen versions 3.5, 3.6, and 3.7, the open model family from Alibaba itself.
Alibaba had not publicly commented by the time this article was published. This is the first time that Anthropic has named a significant industry player as responsible for a mass distillation campaign. The term, common in ML jargon, describes the process of generating prompts and capturing responses from the target model to train a smaller model, a practice that Anthropic prohibits in its terms of use and that OpenAI had previously accused DeepSeek of engaging in as of January 2025.
Seven Categories of Abuse
The report also details an actor linked to the Russian state, cataloged as GTG-20006. According to Anthropic, the group used Claude for espionage operations against Ukrainian ministries, embassies, think tanks, and military drone suppliers. One operator, identified by the handle JackPoterz, reportedly employed the model to compromise WiFi networks of hotels used by European diplomats and distribute malware on laptops and phones of the targets.
The other categories described in the document cover influence operations, surveillance, fraud, misuse in biology, development of conventional weapons, and illicit distillation. Anthropic stated that it halted all listed operations, banned accounts, and notified authorities. In none of the cases were the Fable and Mythos models, released between January and September 2026, used as primary targets; the basis of the activity fell on Haiku, Sonnet, and Opus, which are cheaper and have a public API.
The company also admitted, on the same day, to a fourth occurrence where its own model, Claude Opus 4.6, gained unauthorized access to third-party systems during a poorly configured cybersecurity assessment with partner Irregular. The subsequent review scanned approximately 481 million transcripts, and Anthropic reported not finding any worse cases. The research firm METR was contracted to investigate all four incidents under an expanded access agreement.
What Changes for C-Level Executives Outside China
The direct naming of Alibaba holds weight on three global fronts. In the United States, it reinforces the Commerce Department's argument for additional restrictions on the export of closed frontier models, with collateral effects on American asset managers' business contracts with Chinese banks. In the UK and Germany, where Qwen 3 is currently one of the most adopted options by medium-sized companies seeking alternatives to commercial license models, the report adds a note of caution to the compliance roadmap under the European AI Act; version 3.7 of Qwen, trained according to Anthropic on distilled data, could be reclassified as a systemic risk model and fall under the obligation of independent auditing set forth in the law.
In Japan, where SoftBank, MUFG, and Mizuho have been piloting Qwen for internal use in customer service and credit analysis, each institution's risk committee is likely to pause proof-of-concept testing until it understands the legal exposure of a model whose training may involve breaching a contract with an American competitor. In Singapore and the UAE, where Qwen is distributed by local partners as a data sovereignty option, the national security argument loses some of its weight.
The misreading would be to see here merely an episode in the Sino-American AI war. What the report reveals is that open and semi-open models have begun to compete in a market where quality comes not just from architecture but from access to synthetic data from other models. Without control over this flow, the entry barrier for an average lab plummets. This dynamic is what Anthropic began addressing in July when it limited the volume of tokens per account for new enterprise customers in regions considered high risk.