Moonshot silently forwarded some customer requests intended for Kimi to Claude and then displayed Claude's responses to users, who thought they were using a Kimi model, according to the report.
In one 10-day period, Moonshot relayed nearly 300,000 customer requests to Anthropic, the vast majority of which were routed to Claude Opus models. The requests were routed through a network of 5,380 accounts that Anthropic described as fraudulent, most of which appeared to be located in Singapore and Japan.
The report said Moonshot saved at least some of those exchanges and extracted Claude's reasoning transcripts to use as training data for its own models.
More than 23 million exchanges were attributed to Moonshot between May and July, according to the report.
Some of the customer requests routed to Claude contained sensitive information. The company said it did not know whether Moonshot had notified customers that their requests were being sent to Anthropic.
The company said DeepSeek — which rose into prominence last year due to its capabilities and cheap costs — also used tactics similar to Moonshot, transferring exchanges to Claude without notifying DeepSeek customers. Anthropic said it observed more than 12 million distillation attacks attributable to DeepSeek over 14 days in July 2026.
The report, which named several other major Chinese AI companies, covers activity the company said it disrupted between December 2025 and August 2026 across seven areas, including cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and distillation.
Alibaba, Moonshot, DeepSeek, Xiaomi and Anthropic did not immediately respond to CNBC's requests for comment.
