Federal cybersecurity and intelligence agencies accused six China-based artificial intelligence companies on Tuesday of running industrial-scale campaigns to extract proprietary features from leading U.S. AI models, naming the companies in a joint advisory and alleging the activity took place likely with Chinese government awareness.
DeepSeek, Moonshot , Alibaba, MiniMax, StepFun and Z. were all identified in the advisory. Officials alleged the companies pulled billions of tokens across millions of requests from U.S. AI systems, including variants of Claude, GPT, Gemini and Grok. The activity dates back to at least late 2024, according to the advisory.
The Cybersecurity and Infrastructure Security Agency, the National Security Agency and the FBI jointly issued the warning. CISA Acting Director Nick Andersen said the agency is committed to promoting the secure use of AI and urged companies to take immediate steps to safeguard their platforms against knowledge distillation campaigns that he said threaten to close the gap in advancements made by American developers.
What knowledge distillation is
Knowledge distillation is a standard research method in which a smaller model learns from the outputs of a larger one. The three agencies drew a distinction between legitimate research uses of the technique and what they described as aggressive, malicious and targeted distillation activities conducted at industrial scale.
The advisory said the firms routed traffic through native application programming interfaces, remote cloud providers and third-party aggregators that strip user metadata. A gray market of proxy services, referred to in the advisory as transfer stations, helped the companies avoid geographic blocks, circumvent terms-of-service restrictions and obscure their activity. Bulk premium subscriptions shared across developer teams kept costs down.
The significance of the allegations
The advisory represents one of the more specific and direct accusations made by U.S. government cybersecurity agencies against named Chinese companies, and it comes at a moment of significant tension in U.S.-China technology competition. The inclusion of Chinese government awareness as a qualifier acknowledges the agencies do not have definitive proof of direct government direction but assess it as likely.
Knowledge distillation at the scale described, billions of tokens across millions of requests, would allow smaller models to approximate capabilities of the larger ones they are trained against without the underlying research investment. If accurate, the activity would represent a significant shortcut in developing competitive systems.
The named companies span a range of China’s AI ecosystem, from major technology conglomerates to specialized developers. Each denial from the named companies, if any are issued, would be assessed against what the advisory describes as a technical forensic record.
The broader context
The advisory is consistent with a broader U.S. government posture of using public attribution of specific activities rather than relying solely on sanctions or diplomatic channels to deter technology transfer. Public advisory naming places reputational and commercial pressure on named companies and signals to their customers and partners what government agencies allege they are doing.
CISA‘s advisory is available through the agency’s official cybersecurity advisory publication system.

