Chinese Companies Misuse American AI Technology Resulting in Data Breach: Industry Says Chinese Communist Party Secretly Monitors Military and Police Data

In a recent disclosure by the American artificial intelligence company Anthropic, it has been revealed that multiple Chinese AI enterprises have been allegedly forwarding some requests or user conversations to the Claude model without the users’ knowledge. Several industry insiders in China have indicated that the incident has caught the attention of the Chinese regulatory authorities, who are currently investigating the potential leakage of sensitive and confidential data.

According to Anthropic’s threat intelligence report released on September 10, companies such as Yuezhianmian, DeepSeek, Alibaba, Zhifu, Xiaomi, Shangtang, and MiniMax in China have been accused of obtaining Claude’s outputs through proxy services and fraudulent accounts for training their respective models. Yuezhianmian and DeepSeek, in particular, have been accused of directly forwarding customer requests to Claude and presenting the answers generated by Claude to users.

The report revealed that within 10 days, Yuezhianmian had forwarded nearly 300,000 customer requests to Anthropic, involving 5,380 fraudulent accounts, with the majority located in Singapore and Japan. From May to July 2026, Anthropic observed over 23 million interactions attributed to Yuezhianmian.

Mr. Chu, a Chinese AI engineer, mentioned that following the exposure of the incident, his company has started tightening internal management. He stated that such events are now considered a disgrace, and company executives have instructed them to be extra cautious.

According to Mr. Chu, he understands that relevant departments in the Chinese government are investigating whether military personnel have violated rules by using foreign AI products. He mentioned that military personnel are not allowed to discuss military-related content in a networked environment without permission. If the situations disclosed in the Anthropic report are true, it clearly involves illicit operations by internal military personnel.

He also disclosed an incident where a soldier wrote a year-end summary for the unit while connected to the internet. In less than 20 minutes of being online, the soldier’s computer detected a hacker intrusion, resulting in disciplinary action against the soldier.

Mr. Chu emphasized that the Chinese military imposes restrictions on the use of networked devices by personnel handling sensitive information, and the improper use of AI tools may pose data security risks.

The report further revealed an instance where a Chinese state-owned enterprise engineer used Kimi to develop internal systems and unknowingly submitted internal codes of several Chinese enterprises along with valid access credentials. Anthropic stated that the user was unaware that the requests had been forwarded to Claude.

An insider from China’s network management department, using the pseudonym Hu Chenfeng, indicated that the events disclosed by Anthropic have shaken relevant departments within the Chinese government. Some users unknowingly submitted data related to Chinese surveillance systems and military activities to American AI models for processing.

Hu Chenfeng mentioned that the departments are currently verifying how much sensitive and confidential data may have entered the systems of American AI companies before the exposure of this incident. He emphasized that this is not just a scandal but a situation that needs investigation regarding the usage and retention of data by different units.

He also stated that the extent of the data involved could not be accurately determined at present, and whether third parties have used the related content is also uncertain. He assessed that some data might have leaked, and the long-term existence of such operations could lead to significant data loss.

On September 12, Yuezhianmian issued a statement on its official Weibo denying rumors circulating on the internet about its founder Yang Zhilin and employees being taken away, calling the information “pure fabrication and malicious rumors” and reporting the matter to public security authorities. Reuters had previously approached relevant Chinese companies mentioned in the Anthropic report for inquiries, but Yuezhianmian, DeepSeek, and other companies did not respond immediately.

As of the time of reporting, the Cyberspace Administration of China, Ministry of Industry and Information Technology, Ministry of Public Security, and Ministry of National Defense of the People’s Republic of China have not publicly announced any investigations into the matter.

A technical employee, using the pseudonym He Shanmin, from a technology company in Hangzhou, Zhejiang Province, informed a reporter from Da Ji Yuan that following events like this, departments under the Chinese State Council and relevant state-owned enterprises may receive internal notifications to investigate individuals who violate regulations by using circumvention tools and further restrict the use of VPNs.

He Shanmin mentioned that in mainland China, using most American AI models requires the use of VPNs or other proxy tools, with some data being submitted to overseas models through these channels. Companies are concerned that their internal data may flow to competitors through domestic model platforms, hence preferring foreign AI. They believe that foreign companies place a higher emphasis on intellectual property rights and would adhere to confidentiality responsibilities even when handling user-submitted analysis content.

He Shanmin also pointed out that the disclosed situation indicates that even if companies do not directly use Claude, data can still be transferred overseas through domestic AI platforms or third-party proxy services, with users possibly unaware of the actual location of the model and server processing the data.

Public information indicates that in the field of artificial intelligence, “model distillation” typically refers to training smaller models with the outputs of large models to reduce training costs and enhance model capabilities. Anthropic stated that the identified activities utilized proxy networks, false identities, virtual credit cards, and stolen API keys, violating the company’s terms of service and regional access restrictions.