SCMP China Probes DeepSeek and Moonshot Over Data Routes Exposed in Anthropic's Espionage Report
China's cyberspace regulator summoned the seven labs named in Anthropic's September 10 threat-intelligence report, then narrowed its probe to DeepSeek and Moonshot — examining whether sensitive Chinese data reached Anthropic's US servers through the API routing schemes the report described.
China’s Cyberspace Administration summoned all seven Chinese AI labs named in Anthropic’s 154-page threat-intelligence report, then narrowed the investigation to DeepSeek and Moonshot AI, The Information reported September 22 (via reporters Qianer Liu and Jing Yang). Regulators are examining whether sensitive Chinese data reached Anthropic’s US servers through the routing schemes the report described — a cross-border data-security question, not a model-copying one.
What Anthropic alleged
Anthropic’s September 10 report accused Chinese labs of routing massive volumes of API traffic through its systems under false pretenses. The attributed figures: Moonshot routed 23 million-plus exchanges between May and July, including roughly 300,000 customer requests over a ten-day window through 5,380 fraudulent accounts in Singapore and Japan that displayed the traffic as Kimi’s own; DeepSeek routed 12.1 million-plus exchanges over a fourteen-day July window; Alibaba led the pack at 151 million exchanges from May to July. The report framed the activity as state-linked AI espionage infrastructure.
Some of the allegedly routed material was sensitive. Citing the South China Morning Post, aiweekly reports the data included municipal Public Security Bureau case-management records and surveillance footage from near PLA facilities in Chengdu — the kind of material Beijing treats as a national-security matter when it crosses borders.
Why this matters for developers
This is the second-order effect of Anthropic’s disclosure: the report was written as a threat warning to the West, but its most immediate regulatory consequence is landing on the accused labs at home. No penalties have been announced and the review is continuing, but the probe puts DeepSeek and Moonshot — two of the most widely used Chinese models in Western developer tooling — under a new layer of political risk. Teams building on DeepSeek’s API for cost reasons should be watching whether this turns into usage restrictions or data-handling mandates that change the service’s terms.
It also marks a sharp escalation in how AI labs’ threat reports are being weaponized by governments. Anthropic named names with unusual specificity; Beijing is now acting on that specificity with its own enforcement lens. Expect the next round of threat-intelligence disclosures to be written with this boomerang in mind.
One detail worth sitting with: the CAC summoned all seven named labs before narrowing to two. That initial sweep — Alibaba, Xiaomi, SenseTime, MiniMax, Zhipu, Moonshot, DeepSeek — reads as a compliance signal to the entire Chinese AI sector, not just an investigation of two companies. For Western teams, the practical read is that any dependency on a Chinese lab’s API now carries a regulatory tail risk that did not exist a month ago. If DeepSeek is load-bearing in your stack because of its pricing, this is the week to price out what a forced migration would cost.