Chinese military personnel use Moonshot for surveillance, outsourced to overseas

According to the latest report, it was believed that the Chinese military personnel were using the Chinese artificial intelligence (AI) startup company Moonshot to handle monitoring affairs, only to find out that it was subcontracted to Anthropic, a company based in the United States.

Anthropic released a report on Thursday, September 10, detailing how Chinese AI companies attempted to clone AI models by transferring real query requests from Chinese users to American AI models through a transit platform network.

Multiple instances revealed that during the illegal distillation of foreign AI by Chinese AI companies, internal secrets of the Chinese Communist Party (CCP) or Chinese enterprises were accidentally exposed. It is reported that Anthropic has already suspended the accounts involved in these unauthorized uses. Here are some examples:

Example One:

A Chinese military user used Moonshot’s Kimi model to analyze monitoring data. He loaded surveillance data from hundreds of CCTV cameras in Chengdu targeting specific individuals, including cameras outside military facilities, cameras from an affiliate of China Electronics Technology Group Corporation, and cameras from a large state-owned enterprise (SOE).

Moonshot transmitted this data to Anthropic’s Claude model through an intermediary network for analysis.

Example Two:

A Chinese engineer used Kimi to build an internal system for a large state-owned enterprise in China. In the process of using Kimi, the user inadvertently leaked internal codes and real-time certificates of several large Chinese companies, including some well-known tech firms.

Unbeknownst to the users, their requests to Kimi were forwarded to Claude for answers.

Example Three:

An employee of a Chinese technology company used DeepSeek’s AI tools to analyze internal documents containing sensitive information, such as complete specifications of a flagship AI project, organizational structure, and strategic objectives.

DeepSeek forwarded this data to Claude.

Example Four:

DeepSeek forwarded a request from an IT operator to Claude. The operator was responsible for handling data from a government agency related to the Russian Ministry of Defense. These transmissions exposed real-time certificates of the Russian government database.

Example Five:

An IT engineer from a public security bureau in a Chinese city wanted to develop a tool to match individual movements with police records using ID numbers. When constructing a case management system, he used DeepSeek, which subsequently forwarded these requests to Claude.

Anthropic stated that Chinese AI companies, including Moonshot AI and DeepSeek, used these intermediaries to forward query requests from their millions of users (including sensitive data like location information and passwords) to Claude model.

The report pointed out that these Chinese companies accessed Claude through these transit stations and distilled the interaction information between their customers and products like Claude through monitoring, some of which went beyond conventional distillation methods and resembled meticulously planned illegal tactics.

As a result, users engaging in illegal or malicious activities using Chinese AI are unaware that their operations are quietly being forwarded to Claude and may be exposed to the public eye.