September 11, 2026ResearchAgentsMonitoring

Anthropic Says DeepSeek Relayed 12 Million User Requests Into Claude

Anthropic published its September threat intelligence report on September 10, covering misuse it disrupted between December 2025 and August 2026 across seven harm areas. Six of them are the usual grim inventory: cyber operations, surveillance, influence operations, conventional weapons, biological misuse, scams. The seventh is the one that will get argued about for weeks. Anthropic accuses named Chinese labs of stealing capability by relaying their own users' traffic into Claude.

The centerpiece case, tracked as GTG-16001, alleges DeepSeek used a replay technique against Claude's thinking signatures and forwarded user requests to Claude Opus without those users knowing. 12.1 million exchanges in 14 days in July 2026. Anthropic says the captured material included live credentials for a Russian government database and a PRC police case-management system, which means the accusation is not only about distillation, it is about third parties' secrets passing through a pipe nobody consented to. Zhipu is accused of pushing 770,609 exchanges through a chain-of-thought cleaner over ten days ahead of the GLM 5.3 release. Xiaomi, more than 400,000 requests across over 1,500 accounts.

The agentic cyber section is arguably scarier and got less attention. GTG-20006, a Russian espionage group, used AI for autonomous malware development, evasion, and exfiltration against 20-plus Ukrainian and European targets. ShinyHunters harvested credentials out of 1.8 million Android APKs. Chinese operators under GTG-10007 ran vulnerability research, exploitation, and intel collection as parallel autonomous agents. These are not people asking a chatbot for help. These are loops.

Report at https://www.anthropic.com/threat-intelligence-report-september-2026

Read the HN thread before you take any of it at face value. The top comments are brutal and not unreasonable: how does Anthropic have this much visibility into state actors, why would thin-margin Chinese providers pay Claude rates to serve their own users, and isn't it convenient that the report explains competitors' benchmark scores. Anthropic's countermeasures list, metadata attribution, extraction classifiers, summarized internal reasoning, identity verification, is also a product roadmap. Both things can be true at once: the distillation-by-relay attack is technically real and obvious in hindsight, and a threat report naming three competitors by name is never purely a public service.

Related reading: https://clauday.com/article/91ec5364-c24d-4acc-be8b-35e91b0f085f
← Previous
OpenAI Will Now Run Your Agent Loop For You
Next β†’
The Navier-Stokes Timeline Is the Actual Scandal
← Back to all articles

Comments

Loading...
>_