28.8 Million Exchanges: Anthropic Alleges Largest-Ever AI Extraction Attack by Alibaba

Anthropic has accused Chinese tech giant Alibaba of orchestrating the largest known "distillation" attack on its AI models, generating over 28.8 million exchanges through nearly 25,000 fraudulent accounts between April and June 2026. The operation, which Anthropic alleges was conducted by operators affiliated with Alibaba and its AI lab Qwen, aimed to illicitly extract capabilities from Anthropic's advanced AI systems, including the Mythos Preview model, to accelerate China's AI development. This comes amid heightened U.S.-China tensions over AI intellectual property theft and follows similar attacks by other Chinese AI firms like DeepSeek, which Anthropic had previously disclosed.

Key Points for Executive Summary

  • Scale of the Attack: Anthropic alleges Alibaba executed the largest known extraction campaign against its AI, generating over 28.8 million exchanges through nearly 25,000 fraudulent accounts between April and June 2026.

  • The Technique: The attack used "distillation," a method of training a less capable model on the outputs of a stronger one, which Anthropic says is a way to accelerate China's ability to replicate its advanced capabilities.

  • Pattern of Threats: This is the latest in a series of similar campaigns, with Anthropic previously disclosing that Chinese firms DeepSeek, Moonshot AI, and MiniMax conducted extraction attacks at scales ranging from 150,000 to over 13 million exchanges.

  • Regulatory Context: The attack was disclosed in a letter to U.S. senators, coming amid the Commerce Department's controversial export restrictions on Anthropic's Mythos and Fable models and ongoing U.S. concerns about China's industrial-scale theft of AI intellectual property.

🤖 AI

US Releases Anthropic's 'Mythos' AI Model to Some US Companies: The U.S. government has permitted Anthropic to release a version of its advanced "Mythos" vulnerability-finding AI model to selected U.S. companies, despite export restrictions for foreign entities. The move is intended to bolster national security by allowing critical domestic industries to use the AI for defensive purposes while maintaining a competitive edge.
Link: https://www.reuters.com/technology/us-releases-anthropic-model-mythos-some-us-companies-semafor-reports-2026-06-26/

Anthropic Accuses Alibaba of Illicitly Extracting Claude AI Model Capabilities: Anthropic has publicly accused Chinese tech giant Alibaba of illicitly extracting the capabilities of its Claude AI model to build a competing product. This allegation highlights the intense global competition in AI and the growing concerns over intellectual property theft and the aggressive copying of cutting-edge models.
Link: https://www.reuters.com/world/china/anthropic-says-alibaba-illicitly-extracted-claude-ai-model-capabilities-2026-06-24/

China's 360 Says It Developed Tools to Match Anthropic's Mythos: Chinese cybersecurity firm 360 Security Technology has unveiled its own AI vulnerability-discovery tools, called "Yitian Tulong," which it claims are a domestic equivalent to Anthropic's Mythos. The move reflects China's strategic interest in developing similar AI capabilities, which are seen as "national strategic assets" that can change the landscape of cyber offense and defense.
Link: https://www.reuters.com/legal/litigation/chinas-360-says-it-has-developed-tools-match-anthropics-mythos-2026-06-24/

UK NCSC Warns Leaders of 'AI Shift' in Cyber Risk: The UK's National Cyber Security Centre (NCSC) has issued a warning to business leaders about the significant "AI shift" in the cyber risk landscape, urging them to act now. The advisory emphasizes that AI is lowering the barrier to entry for cybercriminals and is enabling more sophisticated attacks, making it a board-level priority for all organizations.
Link: https://www.ncsc.gov.uk/news/the-ai-shift-in-cyber-risk-why-leaders-must-act-now

New Policy Memo Outlines Paths Toward AI Transparency: A new policy memo from the Center for Security and Emerging Technology (CSET) argues for the creation of Artificial Intelligence Bills of Materials (AIBOMs) to enhance supply chain security and trust in AI systems. The memo outlines supply- and demand-side paths for policymakers to encourage transparency into the components, datasets, and models used in AI products.
Link: https://securityandtechnology.org/virtual-library/policy-memo/driving-ai-transparency/

💻 Malware and Vulnerabilities

New AWS 'AITM' Phishing Kit Discovered: Datadog security labs uncovered a sophisticated new phishing kit targeting AWS users, which employs adversary-in-the-middle (AITM) techniques to bypass multi-factor authentication. The kit allows attackers to steal session cookies and credentials in real-time, posing a severe threat to cloud infrastructure and highlighting the increasing sophistication of phishing-as-a-service offerings.
Link: https://securitylabs.datadoghq.com/articles/behind-the-console-aws-aitm-phishing-kit-and-beyond/

'Payouts the King' Ransomware Operator Deploys New 'EdgeCution' Malware: A ransomware initial access broker known as "Payouts the King" has been observed deploying a new loader/backdoor malware named "EdgeCution" in recent attacks. This development showcases the evolving business model of ransomware, where specialized actors focus on gaining initial access and selling it to other groups, with new tools being developed to evade detection.
Link: https://www.zscaler.com/blogs/security-research/payouts-king-ransomware-initial-access-broker-deploys-new-edgecution

macOS 'Gaslight' Rust Backdoor Uses Prompt Injection Against Analysts: SentinelOne researchers detailed a new Rust-based backdoor targeting macOS, named "Gaslight," which uses sophisticated prompt injection techniques to turn security analysis against the analyst. The malware is designed to manipulate the output of AI-assisted analysis tools, making it harder to detect and containing a novel evasion strategy.
Link: https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/

WhatsApp VBS RMM Campaign Targets Users: Kaspersky researchers discovered a campaign distributing a Visual Basic Script (VBS) that downloads a Remote Access Trojan (RAT) and targets WhatsApp users. The campaign likely spreads via social engineering in WhatsApp messages, tricking users into executing malicious scripts and highlighting the continued targeting of popular messaging platforms.
Link: https://securelist.com/whatsapp-vbs-rmm-campaign/120290/

📈 Breaches and Incidents

Polymarket Confirms $3.1 Million Theft via Third-Party Breach: Prediction market platform Polymarket confirmed hackers stole approximately $3.1 million in PUSD tokens from at least 11 users after a third-party vendor was compromised, allowing malicious script injection into the platform's frontend . The company has contained the incident, removed the affected dependency, and pledged full refunds to impacted users .
Link: https://techcrunch.com/2026/06/25/polymarket-says-hackers-stole-users-funds/

KDDI Data Breach Exposes Up to 14.2 Million Email Credentials: Japanese telecom giant KDDI disclosed that attackers exploited a vulnerability in third-party software to breach its ISP email system, potentially compromising up to 14.22 million email addresses and passwords . The breach affects six ISPs using KDDI's system, including Biglobe and Nifty, and the company is urging affected customers to change passwords.
Link: https://www.japantimes.co.jp/business/2026/06/24/companies/kddi-data-breach-cyberattack/

Tata Electronics Hit by Cyberattack Claiming Theft of Apple, Tesla Trade Secrets: India's Tata Electronics is investigating a cyber breach after hackers claimed to have stolen sensitive trade secrets related to its work with Apple and Tesla. The incident poses a significant risk to the company's reputation and its relationships with major tech partners, though the full extent of the data compromised remains under investigation .
Link: https://www.cnbc.com/2026/06/23/indias-tata-electronics-hit-by-cyber-breach-claiming-to-expose-apple-tesla-trade-secrets.html

Report: Israel Behind Cyberattack on Iranian Banks: A cyberattack attributed to Israel reportedly targeted several Iranian banks, causing widespread disruption. The attack is believed to be a response to ongoing regional tensions and previous Iranian cyber operations, highlighting the continued use of financial infrastructure as a battleground in state-sponsored cyber conflict.
Link: https://www.telegraph.co.uk/world-news/2026/06/23/israel-behind-cyber-attack-on-iranian-banks/

🚨 Threat Intel & Info Sharing

Mandiant Reveals How Cisco SD-WAN Zero-Day Attacks Gained Root Access: Mandiant detailed the exploitation of a critical zero-day vulnerability in Cisco's SD-WAN solution, which allowed attackers to gain root access to affected devices. The flaw has been actively exploited in attacks since at least 2023, underscoring the urgent need for patching and the sophisticated capabilities of threat actors targeting network infrastructure.
Link: https://www.bleepingcomputer.com/news/security/mandiant-reveals-how-cisco-sd-wan-zero-day-attacks-gained-root-access/

Japan Defense Forces Used USB Drives with China-Linked Virus, Probe Finds: An investigation by Nikkei revealed that Japan's defense forces inadvertently used USB drives infected with malware linked to Chinese threat actors, potentially compromising sensitive military data. The incident highlights persistent supply chain and insider threats facing national defense establishments and the challenges of securing operational technology.
Link: https://asia.nikkei.com/spotlight/cybersecurity/japan-defense-forces-used-usb-drives-with-china-linked-virus-nikkei-probe

U.S. Treasury Sanctions Entities Linked to Illicit Finance: The U.S. Department of the Treasury announced sanctions against a network of entities and individuals involved in facilitating money laundering and illicit finance, disrupting their operations. The action targets key financial enablers of criminal and state-sponsored cyber activities, aiming to degrade the infrastructure used to launder proceeds from ransomware and other cybercrimes.
Link: https://home.treasury.gov/news/press-releases/sb0538

Meta Accidentally Let Employees Access Each Other's Keystroke Data: Meta confirmed an internal error that inadvertently allowed employees to access other users' keystroke data, a significant privacy incident. The company stated the issue was quickly rectified and that it had no evidence the data was misused, but the incident raises concerns about internal data governance and the potential for insider threats.
Link: https://www.wired.com/story/meta-accidentally-let-employees-access-each-others-keystroke-data/

Russia-Linked Group Claims Cyberattack on Ukrainian Banks: A cyberattack, claimed by a Russia-linked group, disrupted the operations of several Ukrainian banks. The attack is part of an ongoing pattern of cyber aggression targeting Ukraine's financial and critical infrastructure sectors, leveraging denial-of-service and other disruptive tactics.
Link: https://www.kommersant.ru/doc/8762344

Algerian Man Extradited to U.S. for Role in Black Market Fraud Conspiracy: An Algerian man has been arrested and extradited to the United States to face charges for his alleged role in a large-scale black market fraud conspiracy. The case underscores international collaboration in pursuing cybercriminals and disrupting transnational fraud operations that exploit online financial systems.
Link: https://www.justice.gov/usao-wdny/pr/algerian-man-arrested-extradited-united-states-his-role-black-market-fraud-conspiracy

Justice Department Seizes Infrastructure Used by Huione Group for Money Laundering: The U.S. Department of Justice announced the seizure of backend infrastructure used by the Huione Group to facilitate money laundering services. The operation represents a significant blow to a major enabler of cybercrime, disrupting the financial plumbing that allows ransomware groups and other illicit actors to move and launder funds.
Link: https://www.justice.gov/opa/pr/justice-department-seizes-backend-infrastructure-used-huione-group-money-laundering-services

Smart TV Apps Found with Residential Proxy SDKs: Researchers discovered that several popular Smart TV apps contain SDKs that effectively turn the devices into residential proxies for third parties. This practice raises significant privacy concerns as it can expose users' home IP addresses to potential abuse by cybercriminals or advertisers without their explicit knowledge or consent.
Link: https://spur.us/blog/smart-tv-apps-residential-proxy-sdks

⚖️ Laws, Policies and Regulations

CISA Sets Urgent Deadline to Fix Cisco Flaw Exploited in Attacks: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive mandating federal agencies to patch the actively exploited Cisco SD-WAN zero-day vulnerability by a strict deadline. The directive underscores the severity of the flaw and the elevated risk to critical network infrastructure, with exploitation actively ongoing.
Link: https://www.bleepingcomputer.com/news/security/cisa-sets-urgent-deadline-to-fix-cisco-flaw-exploited-in-attacks/

CISA Director Nominee Pledges Workforce Expansion at House Hearing: The nominee for the director of CISA, Sean Mullin, testified before a House committee, pledging to expand the agency's cybersecurity workforce and strengthen its partnerships with the private sector. The hearing addressed key priorities, including election security, critical infrastructure protection, and the need to attract and retain top cybersecurity talent.
Link: https://therecord.media/cisa-director-nominee-workforce-hires-mullin-house-hearing

Trump Issues Executive Order with Post-Quantum Encryption Deadline: President Trump has signed an executive order setting a deadline for U.S. government agencies to transition to post-quantum encryption. The order aims to secure federal networks against the future threat of quantum computers, which could break current public-key infrastructure and mandates aggressive timelines for migration.
Link: https://cyberscoop.com/trump-executive-order-post-quantum-encryption-deadline/

European Commission Announces New Cyber Resilience Measures: The European Commission unveiled a new package of measures aimed at strengthening the cyber resilience of critical entities and digital service providers across the bloc. The initiative builds on existing directives, introducing stricter requirements for risk management, incident reporting, and oversight of supply chain security.
Link: https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1444

Ransomware and Data Breaches Drive Spike in Cyber Insurance Claims, Report Finds: A new report from Bitsight reveals that ransomware and data breaches continue to be the primary drivers of cyber insurance claims, with a notable increase in severity. The analysis highlights that the professionalization of ransomware and the increased targeting of cloud environments are major factors contributing to these trends.

📅 Upcoming Events

Security Operations for the Age of AI

Cybersecurity leaders face a new reality: threat actors are moving faster, attack volumes continue to increase, and traditional Security Operations Centres (SOCs) are struggling to keep pace without significantly increasing cost and complexity. At the same time, advances in AI are creating an opportunity to rethink how security operations are designed, managed, and scaled. Organisations that successfully harness AI within their security function can improve resilience, accelerate response times, and unlock greater value from existing security investments.

Join fellow CISOs, security executives, and technology leaders for an exclusive dinner exploring how organisations can evolve from conventional SOC models to AI-enabled and agentic security operations.

If you would like to sponsor any of our future in person or virtual events then please email us on [email protected]

We hope you enjoyed our email briefing! ☕🥮If you want to sponsor our next edition or advertise on our site, drop us an email [email protected].

Thank you for being a part of our newsletter community and you can be part of the community by joining our LinkedIn Group.