CISA Names DeepSeek and Five Rivals in AI Distillation Warning
Security / news
CISA Names DeepSeek and Five Rivals in AI Distillation Warning
The Tuesday advisory says Moonshot AI trained its Kimi K3 model on outputs from Anthropic's Claude Fable, and it tells U.S. AI companies to quietly degrade suspect accounts rather than block them outright.
The National Security Agency, the FBI and the Cybersecurity and Infrastructure Security Agency said Tuesday that six China-based AI companies have run industrial-scale campaigns to extract the capabilities of U.S. frontier models since at least late 2024, according to advisory AA26-251A. The named companies are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI.
The advisory describes the activity as "systematic extraction of proprietary functionalities and capabilities of U.S. AI companies' models," pulling in "billions of tokens across millions of exchanges" from Anthropic's Claude models, OpenAI's GPT models, Google's Gemini and xAI's Grok. The three agencies said the scale and coordination make distillation "the core, not merely a supplement," of the named companies' AI development strategy.
Which company is accused of copying which model
The advisory ties specific products to specific sources, more detail than the typical joint cybersecurity bulletin carries.
| Chinese company | Accused of distilling | Product built |
|---|---|---|
| DeepSeek | Multiple versions of Claude, GPT and Gemini | R1 and V3 models |
| Moonshot AI | Anthropic's Claude Fable | Kimi K3 |
| Moonshot AI | OpenAI's GPT-4o output | Kimi K2 |
| Z.AI | Unspecified U.S. models, at industrial scale | Billions of distilled tokens by mid-2026 |
How the agencies say it was hidden
The companies used fraudulent accounts, bulk premium subscriptions and proxy routing services the advisory calls "transfer stations" to bypass regional restrictions and avoid detection, according to the advisory. The agencies said the activity was likely carried out with the Chinese government's awareness, and that it has let Chinese models narrow the performance gap with U.S. systems while cutting research, development and compute costs.
What CISA wants companies to do instead of blocking accounts
"We strongly urge AI companies to take immediate steps to safeguard their platforms against knowledge distillation campaigns," CISA Acting Director Nick Andersen said in a press release accompanying the advisory. Rather than simply banning accounts flagged for suspected distillation, the advisory recommends serving them "subtly altered responses," alongside anomaly detection for prompt patterns and cross-company intelligence sharing on suspicious indicators.
The advisory does not disclose how the agencies attributed specific training pipelines, such as Kimi K3's, to specific source models, nor does it estimate a dollar cost to the American companies whose outputs were used. It also does not say whether Anthropic, OpenAI, Google or xAI have adopted the degrade-rather-than-block approach, or whether any of the six named companies responded to the accusation before publication. CISA has published several other advisories this same week, including one on an actively exploited Chrome flaw and one on a Patch Tuesday count regulators still dispute, leaving little public capacity to detail how any single finding, including this one, was verified.
Sources: CISA/NSA/FBI advisory AA26-251A, Sept. 8, 2026; CISA press release, Sept. 8, 2026; Help Net Security, Sept. 9, 2026.
Sources
More in Security
- 01Cisco and Acronis Share a CISA Deadline, Not a Severity ScoreOne flaw needs no password and no user interaction, the other needs an attacker already logged in, and CISA gave federal agencies the same three days to fix both.
- 02Bransys ELD App Shipped With Hardcoded Login CredentialsCISA disclosed three flaws Sept. 17 in the trucking compliance app, including a hardcoded password a researcher says exposed live location and engine data from every connected truck on a subset of fleets.
- 03MikroTik Patches RouterOS Flaws Attackers Exploited FirstPoland's national CERT says attackers began exploiting the chained flaws on Sept. 2, a day before MikroTik shipped a fix, and more than 122,500 routers were still reachable a week later.
- 04Attackers Exploit a JFrog Artifactory Bug in Four DayswatchTowr says attackers began minting administrator tokens by abusing a default empty join key, CVE-2026-82329, within days of JFrog's own patch shipping.