Anthropic Accuses Alibaba of Scraping Claude Data With 25,000 Fake Accounts

Anthropic publicly accused Alibaba of systematically harvesting data from its Claude AI assistant through 25,000 fake accounts, a claim that, if accurate, would be one of the largest known thefts of AI training data. The allegations were reported by Semafor and InfoWorld.

Anthropic said Alibaba created the accounts to pull responses from Claude at scale, material that could be used to train competing models or to probe Claude’s behavior and capabilities. The company gave no details of when the activity occurred or how it was detected, and the claims could not be independently verified.

The accusation lands at a charged moment in U.S.-China technology relations. From chip export controls to data security, the rivalry between the two countries has expanded well beyond hardware, and AI data has become a strategic asset in its own right. A company that can capture a rival’s model behavior at scale gains intelligence about its strengths and weaknesses.

The scale is what makes the case notable. Web scraping is common in AI—models are trained on vast amounts of public data—but creating 25,000 accounts to pull data from a single service, if confirmed, points to organized collection rather than incidental scraping. It also suggests the collector wanted to avoid detection, since a handful of accounts would draw attention quickly.

Anthropic’s timing is notable. The company is preparing for an initial public offering, and it has been presenting itself to investors as a business with a defensible moat around its data and models. Going public with an accusation against one of China’s largest technology companies demonstrates that defense in a way a slide deck cannot.

The accusation also serves a commercial purpose. Anthropic sells to enterprises and governments that care about data security, and a company that can show it detects and confronts data theft has a stronger story to tell customers worried about their own information. The episode lets Anthropic frame its security investment as a product advantage rather than a cost.

Alibaba did not immediately respond to requests for comment. The company’s own AI models, including its Qwen family, are among the most widely used open-source models in the world, and Alibaba has positioned itself as a global AI player rather than a purely Chinese one.

The broader fight over AI data is only beginning. Companies are increasingly guarding their models’ outputs, rewriting terms of service to restrict automated access and building detection systems for suspicious usage patterns. The tools used to scrape data have grown more sophisticated, and so have the defenses.

The case also highlights a paradox at the center of the AI industry. Models are trained on data scraped from the public internet, often without permission, and their creators jealously guard their own outputs. The line between legitimate research and theft is drawn differently by every company, and cases like this force the question into the open.

For regulators, the accusation adds to a growing dossier of disputes over AI data. Governments on both sides of the Pacific are drafting rules about training data, model transparency and cross-border data flows, and a high-profile case of alleged theft could inform how those rules are written.

For investors in Anthropic, the episode is a demonstration of value. Data protection has become a selling point, a moat and a risk factor all at once, and the company’s willingness to confront the issue publicly suggests it believes its defenses are strong. Whether the accusations hold up in any forum is a separate question.

The episode also shows how intertwined the AI industry has become with geopolitics.

Companies have developed a quiet arms race around data collection. Services monitor for patterns that suggest automated access—rapid-fire requests, fresh accounts arriving from the same network, queries that seem designed to probe a model’s limits. Terms of service have grown to forbid scraping for model training, and some providers have cut off or sued suspected scrapers. Anthropic’s accusation suggests it believes it caught Alibaba at industrial scale.

The accusation also lands amid a broader debate about open models. Alibaba’s Qwen family is among the most downloaded open-source AI systems in the world, and the company has presented openness as its strategy, releasing models that any developer can use. An accusation that it secretly harvested a rival’s data would sit awkwardly with that positioning, whatever the evidence eventually shows.

The long-term effect may be to accelerate the fragmentation of AI. If companies cannot trust that their models will not be harvested by rivals, they will guard them more closely, restrict access more aggressively and share less. The era of open research and free exchange is giving way to one of walls and watchdogs—and cases like this one are building the walls.

Related Posts

  • September 6, 2026
  • 11 views
Anthropic Moves Its IPO Filing to Late September

The bankers and lawyers running Anthropic’s initial public offering had told investors to expect the company’s registration documents as soon as this week. The calendar has moved. Anthropic now plans…

  • September 6, 2026
  • 12 views
OpenAI Quietly Revises GPT-6 Astra Scores After Launch

When OpenAI released GPT-6 Astra on Sept. 3, the launch post carried the usual furniture of a modern model debut: coding results, speed comparisons and a figure for how often…