Back to all lessons
Awareness Lessons
last month

China-Based AI Labs Exploited Fake Accounts and Stolen Credentials to Clone Claude at Industrial Scale

Seven Chinese AI labs, including major players like DeepSeek and Alibaba, systematically abused Anthropic's Claude API by using networks of fake accounts, stolen credentials, and illicitly obtained API keys to harvest over 151 million AI exchanges. The root cause is a failure to enforce robust access control and behavioral monitoring capable of detecting coordinated, large-scale misuse patterns across distributed accounts. This matters because it demonstrates that AI intellectual property and sensitive user interaction data can be exfiltrated at industrial scale when API access governance is weak. Beyond IP theft, the harvesting of user data raises serious privacy concerns for individuals whose interactions were captured without consent. This case sets a critical precedent for the entire AI industry to treat API abuse as a first-class security threat.

Tactical Insight

Immediate actions

  • Audit all active API keys and revoke any associated with suspicious usage patterns, abnormal request volumes, or unverified account origins.
  • Implement rate limiting and behavioral anomaly detection on API endpoints to flag accounts generating unusually high or structured query volumes.

Long-term improvements

  • Enforce strong identity verification (e.g., KYC checks) for API account creation to prevent fake or pseudonymous account networks from scaling.
  • Develop and deploy AI-specific abuse detection models that can identify distillation attack signatures, such as systematic capability probing or bulk synthetic data harvesting.
  • Establish contractual and technical controls in Terms of Service enforcement, including automated account suspension pipelines for policy violations.

Detection measures

  • Centralize and correlate API usage logs across accounts to surface coordinated activity that may appear benign in isolation but reveals a pattern at aggregate scale.
  • Set up threat intelligence sharing pipelines with peer AI companies to identify cross-platform credential abuse and coordinated campaigns early.