:

US: CHINESE FIRMS STOLE BILLIONS OF AI TOKENS

AI DESK2 MIN READ
WED, SEP 9, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

U.S. cybersecurity and intelligence agencies have identified six Chinese AI companies conducting large-scale distillation attacks on American frontier AI models since late 2024, extracting billions of tokens in the process.

The coordinated effort represents a significant escalation in AI model theft. Distillation attacks involve querying proprietary AI systems repeatedly to extract their capabilities and knowledge, then using that data to train competing models at a fraction of the original development cost. The Scope U.S. officials confirmed the Chinese firms systematically accessed frontier models—the most advanced AI systems available—and extracted billions of tokens. A single token represents a small unit of text processed by language models. The scale of extraction suggests industrial-level operations rather than isolated incidents. Timeline and Detection The attacks began in late 2024 and continued through early 2025. U.S. cybersecurity agencies detected the pattern through monitoring of API usage and network traffic associated with American AI companies' systems. Implications The theft threatens to compress development timelines for competing AI systems. Rather than investing years and billions in research and development, competitors can use extracted knowledge to accelerate their own models. This represents a direct transfer of intellectual property valued at billions of dollars. The attack method itself is not new—distillation is a known technique in machine learning. However, the scale and coordination indicate organized efforts backed by significant resources. Response U.S. officials have not announced specific countermeasures beyond public disclosure. Options include rate-limiting API queries, implementing detection systems for suspicious access patterns, and diplomatic channels with Chinese government officials. The incident highlights vulnerabilities in how American companies monetize frontier AI through API access. Each query to a model provides potential data points for attackers to reconstruct its underlying knowledge. This disclosure follows years of U.S. concerns about Chinese AI advancement and industrial espionage. The identified companies operate in the Chinese AI sector, competing directly with American firms in developing large language models and related technologies.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Two major US law firms have fallen victim to cyber extortion attacks, with threat actors obtaining and publishing private client documents. The incidents highlight ongoing security vulnerabilities in the legal sector.

1H AGOSecurity Desk

Healthcare technology company Veradigm disclosed a data breach after a ransomware attack on a third-party vendor exposed patient personal information. A cybersecurity incident at the vendor compromised data stored on Veradigm's systems.

2H AGOAI Desk

While multi-factor authentication strengthens account security, attackers are increasingly exploiting password recovery and authentication reset processes. Stronger identity verification at service desks is now critical to block social engineering attacks.

3H AGOIndustry Desk

A group of US lawmakers spanning both parties has called on the government to ban three Indian companies accused of running hacking operations to steal information for litigation purposes.

3H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.