This one's worth opening because the exposed data isn't casual chat—it's a pharma firm's multi-country budget sheet, live Telegram and Feishu credentials, and police ID verification records. Anthropic says a team used 5,380 fake accounts to reroute ~300K user requests to Claude over 10 days.
I'd discount this a bit. The report is Anthropic's alone—backend logs are theirs, named companies haven't responded, and independent researcher Shou's claim of buying a 6TB dataset with SSH keys and cloud tokens is single-source and unverified.
One number stands out: Anthropic estimates 180M+ unauthorized distillation calls—Alibaba at 151M, DeepSeek at 12.1M. DeepSeek specifically routes requests containing Claude Code markers to reasoning models, which means developers writing code are the prime target.
On the defense side, Anthropic's chain-of-thought protection only works for new API accounts, and response signing isn't live yet—both protect model outputs, not user inputs. Contracts don't help either: DeepSeek's terms allow training on inputs, and Kimi's web UI has no opt-out toggle—users must email and wait 5–7 business days.
The practical takeaway: treat every prompt sent through a channel you don't control as public. For critical work, use direct official APIs or self-hosted gateways. Don't treat LLM chat windows as a vault for internal company data.