China Launches Probe into DeepSeek and Moonshot AI Over Alleged Data Leaks to Anthropic
China’s Cyberspace Administration (CAC) has opened an investigation into two prominent AI startups DeepSeek and Moonshot AI over allegations that they secretly routed sensitive user data to Anthropic’s servers. The probe follows a 154-page threat intelligence report published by Anthropic on September 10, which accused seven China-based labs, including the two firms, of "illicit distillation" training smaller AI models using outputs from Anthropic’s Claude without authorization.
Anthropic alleged that the companies rerouted queries to its servers, effectively providing users with Claude’s responses at a lower cost. The CAC has since narrowed its focus to DeepSeek and Moonshot, summoning executives and staff for interviews after visiting their offices. Regulators are examining whether police, military, or state-linked corporate data was transferred to U.S.-based servers, raising national security concerns.
The timing of the investigation is particularly sensitive for Moonshot, which confidentially filed for a Hong Kong IPO on September 3, targeting a $50 billion valuation and a $3 billion raise. Any findings from the probe would need to be disclosed in its prospectus before the listing proceeds. Meanwhile, the allegations come just ahead of a September 24 summit between U.S. President Donald Trump and Chinese leader Xi Jinping, where AI governance is expected to be a key topic.
No penalties have been announced, but the investigation underscores Beijing’s scrutiny of AI development amid rising tensions over data security and intellectual property. The case also highlights the growing global competition in AI, with China leveraging Anthropic’s own detection methods to police its domestic industry.
Source: https://www.yahoo.com/news/world/articles/china-probes-deepseek-moonshot-over-213103454.html
DeepSeek AI cybersecurity rating report: https://www.rankiteo.com/company/deepseek-ai
Kimi (Moonshot AI) cybersecurity rating report: https://www.rankiteo.com/company/kimi-ai-linkedin
"id": "DEEKIM1790217824",
"linkid": "deepseek-ai, kimi-ai-linkedin",
"type": "Breach",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Artificial Intelligence / Technology',
'location': 'China',
'name': 'DeepSeek',
'type': 'AI Startup'},
{'industry': 'Artificial Intelligence / Technology',
'location': 'China',
'name': 'Moonshot AI',
'type': 'AI Startup'},
{'industry': 'Artificial Intelligence / Technology',
'location': 'United States',
'name': 'Anthropic',
'type': 'AI Company'}],
'attack_vector': 'Unauthorized API routing / Data exfiltration',
'data_breach': {'data_exfiltration': 'Yes (alleged routing to Anthropic’s '
'servers)',
'sensitivity_of_data': 'High (national security implications)',
'type_of_data_compromised': 'Sensitive user data, potentially '
'including police, military, or '
'state-linked corporate data'},
'date_detected': '2024-09-10',
'date_publicly_disclosed': '2024-09-10',
'description': 'China’s Cyberspace Administration (CAC) has opened an '
'investigation into two prominent AI startups DeepSeek and '
'Moonshot AI over allegations that they secretly routed '
'sensitive user data to Anthropic’s servers. The probe follows '
'a 154-page threat intelligence report published by Anthropic '
'on September 10, which accused seven China-based labs, '
"including the two firms, of 'illicit distillation' training "
'smaller AI models using outputs from Anthropic’s Claude '
'without authorization. Anthropic alleged that the companies '
'rerouted queries to its servers, effectively providing users '
'with Claude’s responses at a lower cost. Regulators are '
'examining whether police, military, or state-linked corporate '
'data was transferred to U.S.-based servers, raising national '
'security concerns.',
'impact': {'brand_reputation_impact': 'High (for DeepSeek and Moonshot AI)',
'data_compromised': 'Sensitive user data, potentially including '
'police, military, or state-linked corporate '
'data',
'legal_liabilities': 'Potential regulatory fines, legal actions',
'operational_impact': 'Regulatory scrutiny, potential IPO delays '
'for Moonshot AI',
'systems_affected': 'Anthropic’s servers (indirectly), DeepSeek '
'and Moonshot AI’s infrastructure'},
'investigation_status': 'Ongoing',
'motivation': 'Cost reduction / Competitive advantage / Intellectual property '
'theft',
'references': [{'date_accessed': '2024-09-10',
'source': 'Anthropic Threat Intelligence Report'},
{'source': 'Cyberspace Administration of China (CAC)'}],
'regulatory_compliance': {'regulations_violated': 'Potential violations of '
'China’s data security and '
'cybersecurity laws',
'regulatory_notifications': 'CAC investigation '
'initiated'},
'response': {'law_enforcement_notified': 'Cyberspace Administration of China '
'(CAC)'},
'threat_actor': 'DeepSeek and Moonshot AI (alleged)',
'title': 'China Launches Probe into DeepSeek and Moonshot AI Over Alleged '
'Data Leaks to Anthropic',
'type': 'Data Leak / Unauthorized Data Transfer',
'vulnerability_exploited': 'Lack of access controls / Unauthorized model '
'distillation'}