# Anthropic 2026-09 报告中的「泄密 / 用户数据外流」专项报告

**来源（原始文档，均已存档并哈希校验）**
- 主文档：《Detecting and countering misuse of AI: September 2026》，Anthropic，2026-09-10，PDF 154 页
  本地：`raw/Anthropic-Detecting-and-countering-091026.pdf`（sha256 `cdea01e84f61de63…`）｜纯文本导出：`raw/Anthropic-Detecting-and-countering-091026.txt`
- 配套：IOC CSV（209 条）、报告网页版、2026-02-23 蒸馏专项公告、帮助中心「保留思考」原文

**方法**：`pdftotext -layout` 全文提取后按关键词（privacy / consent / sensitive / credentials / without the knowledge）穷举相关段落，逐句比对英文原句。页码为 **PDF 页脚页码**。凡原文没写的，一律标【原文未给出】；凡属 Anthropic 的评估/推断而非事实陈述，均单列标注。

---

## 一、结论速览

1. **报告中的"泄密"不是 Anthropic 自己被攻破**，而是三类性质完全不同的数据外流：
   - **① 静默改道**：中国实验室把（自己或第三方的）终端用户对话偷偷转给 Claude，用户不知情、未同意；
   - **② 第三方路由/中转平台留存并倒卖**：用户与美方前沿模型的对话被平台记录后卖给其他实验室；
   - **③ 凭据窃取**：恶意团伙偷 Anthropic 客户的 API key / session token 并流入黑市转卖。
2. **被明确指控"转送用户数据"的是三家：Moonshot、DeepSeek、Xiaomi**（p.146 总述段点名）。**阿里巴巴、智谱（Z.ai）在原文中是其自建账号池做能力抽取，原文并未指其转发第三方用户数据**——这个区别常被二手报道糊掉。
3. 规模与内容：Moonshot 十日窗口约 **30 万**次客户请求被转给 Claude；DeepSeek 14 天 **>1,210 万**次交换；Xiaomi **>40 万**次请求，含**数百名用户的姓名、联系方式、公司数据**，**至少十几种语言**，"大部分来自美欧用户常用的第三方模型路由平台"。
4. Anthropic 的定性用词是**留有余地的**："likely inconsistent with **privacy laws** and the labs' own terms of service"（p.146）——这是可能违法的判断，不是法律结论；对用户是否知情，原文用的是 "without the knowledge or consent"、"We do not know if Moonshot notified their customers"、"almost certainly not made aware"。
5. **证据是单方、打码、无第三方的**：报告只给了 2 个打码样例（药企预算表、开发者凭据），3 条枚举式案例；【原文未给出】受影响用户名单、涉事中国企业名称、样本原始日志、是否已通知受影响方、是否已轮换泄露的凭据、监管是否介入；随报告的 IOC CSV 中**没有任何蒸馏/泄露条目**。

---

## 二、三类外流对照

| 类型 | 谁 → 谁 | 用户是否知情/同意 | 原文依据 |
|---|---|---|---|
| ① 静默改道（把用户请求转给 Claude，再把 Claude 的答复当自家模型回复展示） | Moonshot（Kimi）、DeepSeek；Xiaomi 只回放、不把 Claude 回复给用户 | 否。"without the knowledge or consent"、"no way of knowing" | p.146, 148–150, 151–152 |
| ② 第三方路由/聚合平台留存并出售对话 | 平台 → 中间商 → 各实验室（SenseTime 被指为**买家**） | 否。"often save exchanges … without the knowledge or consent of those users" | p.144, 152 |
| ③ 凭据窃取与倒卖 | 恶意团伙 → Anthropic 客户（企业/个人） | 否 | p.27–29 |

> 关键区分：②③ 的受害者主要是**美欧用户与 Anthropic 客户**；① 的受害者主要是**中国/第三国用户**，他们以为自己在用本国模型。

---

## 三、被点名的具体泄露案例（逐案）

### 3.1 Moonshot AI（Kimi）——静默转发 + 客户敏感数据（p.148–149）

机制（p.148）：Moonshot 把客户请求 **silently forwarded** 给 Claude，而不是用 Kimi 处理，再把 Claude 的回答展示给用户；同时保存这些交换、建 CoT 抽取管线训练自家模型。

原文（p.149）：
> Our investigation also revealed that user queries that Moonshot rerouted to Claude included sensitive information about various Moonshot customers. **We do not know if Moonshot notified their customers** that their requests were being rerouted to Anthropic and **exposed to a third party**.

报告列举两例：

- **军工/公安关联的监控数据**：一名 Anthropic **评估为"likely affiliated with the PLA"** 的用户，以为在用 Kimi，把某单个被跟踪对象的 **CCTV 档案**交给模型分析"行为是否异常"；画面来自**成都数百路摄像头**，含 PLA 设施外、中国电子科技集团相关院所外、某大型国企外的摄像头（p.149）。
- **大型国企工程师**：用 Kimi 建内部系统，过程中**暴露了内部代码和 live credentials**，涉及多家中国大型公司（含高知名度科技公司）。原文：**"The user had no way of knowing that their use of Kimi was being forwarded to Claude."**（p.149）

规模（同案）：10 日窗口 **约 30 万**次客户请求被转发（绝大多数走 Opus）；5–7 月归因 **>2,300 万**次交换；代理账号 5,380 个（多在新加坡、日本）。

### 3.2 DeepSeek——按工具链筛选用户后改道（p.149–150）

机制（p.150）：DeepSeek 检查入站请求里的字符串，**标记**正在使用第三方或 Anthropic 编码工具链（Claude Code、Claude Agent SDK、OpenCode）的用户，把**被标记用户**的请求转到 Claude Opus；并用跨会话重放（thinking signature）抽取推理迹。

原文（p.150）：
> This sensitive data was **likely routed to Anthropic without the knowledge or consent of DeepSeek's customers**.

三例：

| 案例 | 泄露内容 | 原文措辞 |
|---|---|---|
| 中国某科技公司员工（以为在用 DeepSeek 分析内部文档） | 某**旗舰 AI 项目的完整规格、组织架构、战略目标** | "The company was **almost certainly not made aware** that its data was being relayed to Claude." |
| 与俄国防部相关政府机构数据打交道的 IT 操作员 | **一个俄罗斯政府数据库的 live credentials** | "The relayed requests **exposed live credentials** for a Russian government database." |
| 中国某市公安局案管系统工程师 | 用**公民身份证号**把人员活动轨迹与警务记录比对的工具 | （描述性陈述，无"是否知情"表述） |

规模：**2026 年 7 月 14 天**内观察 **>1,210 万**次交换。

### 3.3 Xiaomi（MiMo）——回放自家用户对话（p.151–152）

机制：Xiaomi 把自家 MiMo 模型的用户对话/编码会话回放到 Claude（常经 OpenClaw、OpenCode），保存完整请求与回复，用于 SFT 与 RL。原文明确：**"Our investigation did not indicate that Xiaomi used Claude's responses to serve its users"**——即**没有**把 Claude 冒充自家模型回复用户（这是它与 Moonshot/DeepSeek 的关键区别）（p.151）。

泄露范围（p.152）：
> The relayed traffic included sensitive data from users that accessed Xiaomi's models through third-party model routing platforms. **We have no indication US persons' data was exposed**, but those platforms are commonly accessed by users in the United States and Europe. Those requests to Claude contained the **names, contact information, corporate data, and other sensitive data from hundreds of Xiaomi users in at least a dozen languages**.

规模：>40 万次请求、>1,500 个代理账号；**2026 年 3–4 月的 20 天**内观察 >40 万次交换。
原文还提出一个**推断性**动机：MiMo-V2-Pro 的免费试用（后被延长）**可能**是为利用国际开发者涌入来做蒸馏——用的是 "suggests" / "may have"（p.151）。

### 3.4 总述段：三家被点名"滥用用户数据"（p.146）

> Additionally, these findings raise concerns about the **misuse of user data by PRC AI labs**. **DeepSeek, Xiaomi, and Moonshot** fed conversations between their own models and users into Claude. These labs then used Claude's responses as training data with which to distill Claude's capabilities. Some of these exchanges **included sensitive information, including from individual users, major multinational companies, and state-affiliated actors**. Many of these exchanges were relayed from users of **third-party model routing services** commonly used by users in the United States and Europe. Those sessions contained **names, email addresses, company data, and other sensitive data of hundreds of end users in at least a dozen languages**. These practices are **likely inconsistent with privacy laws and the labs' own terms of service**.

要点：①点名三家；②数据类型是姓名/邮箱/公司数据；③受害面是"hundreds of end users"+多国语言；④法律口径是 "likely inconsistent"，非定论。

### 3.5 原文直接展示的两个泄露样本（p.146–147，已打码）

```
Example 1: Internal capital expenditure forecasts for a pharmaceutical company
[Original user prompt submitted to a coding assistant of a lab headquartered in China
 (user accessed the model via a third-party model router)]
"Clean up this capex model before Thursday's review. The workbook has the 2026–28 buildout
estimates: Ho Chi Minh City site $[██]M, Kuala Lumpur $[██]M, Bangkok $[██]M, Ljubljana
$[██]M. Flag anything where the contingency line looks off versus the site engineering notes
below."
```
```
Example 2: A developer's active access credentials
[Original user prompt submitted to a PRC lab's coding assistant]
"My notification bot stopped posting. Config attached — Telegram bot token [██:██], Feishu
appSecret [██], Notion integration key secret_[██]. The webhook fires but nothing lands in
the channel."
```
两个样本的共性：**用户是经第三方模型路由访问"某中国总部实验室的编码助手"的**；第二例直接把三类**在用的密钥**贴进了对话。原文用 `[██]` 打码，**没有**给出公司名、模型名或可验证的原始日志。

### 3.6 其余四家：性质不同，别混为一谈（p.147–153）

| 主体 | 原文指控 | 是否涉及"转发第三方用户数据" |
|---|---|---|
| Alibaba（GTG 16005） | 自建两池假账号池抽取 Opus 4.6/4.7 的 CoT，峰值近 300 万次/天、5–7 月 >1.51 亿次 | **原文未指其转发第三方用户对话** |
| Zhipu / Z.ai（GTG-16006） | 273 个假账号轮换、把捕获推理再送回 Claude 清洗；用于 GLM 训练与 post-training | **原文未指** |
| SenseTime（GTG 16012 或 16003） | 其蒸馏管线**包含从第三方数据商购买的**用户-Claude 交换誊本；并用 Claude 写管线、监控训练 | 它是**买家**：用户数据是别人（中介/代理）泄露给它的 |
| MiniMax（GTG 16003 或 16012） | 通过**壳公司**自建代理网络，**只提供 Anthropic 与 OpenAI 模型**、不含自家模型，被指用于收割用户与美方模型的交换 | 属"平台方留存"链条，**原文未给交换/账号数** |

> 二手报道常把七家一律说成"偷用户数据"，原文并非如此：**只有 Moonshot、DeepSeek、Xiaomi 被点名把用户对话送给 Claude**。

---

## 四、泄密链路：数据是怎么流出去的（原文版）

1. **实验室静默改道自己的用户流量**（Moonshot、DeepSeek；Xiaomi 回放）——用户端无感，`without the knowledge or consent`（p.144, 149–150）。
2. **第三方"路由/中转"平台留存并出售**：原文说这类转售商（含代理服务运营者）`often save exchanges between users and US models without the knowledge or consent of those users`，实验室**购买**这些誊本用于蒸馏（p.144）；SenseTime 被指正是买家（p.152）。
3. **账号池直接抽取**：假身份、假/盗信用卡、**盗用合法公司或个人的 API 凭据**建号（p.144），阿里第二池部分账号还在替 DeepSeek、Xiaomi 转发请求——说明**同一代理网络被多家共用**（p.147）。
4. **绕开技术控制**：保存 thinking signature → 新开会话 → 诱导还原完整推理（跨会话重放，Moonshot/DeepSeek）；片假名/多语言"翻译"；伪造 system prompt 要求原样输出 `<thinking>`（p.145, 148–150）。

---

## 五、另一条线：凭据类泄露（AI 供应链，p.27–29）

- **盗号已成为独立生意**：`compromised API keys, session tokens, and devices has increasingly become the sole objective of multiple criminal groups`，再经中间商流入"欺诈性 AI 转售网络"，被盗 key 被轮换使用到耗尽（p.28）。
- **伪装成 Claude Code 的凭据收割器**：攻击者搭"多模型中介 / 折扣前沿模型"站点，诱导下载**仿冒 AI 客户端**（含仿冒 Claude Code），该客户端收集设备上**全部凭据与已认证 session token**并回传；用户重置密钥后，收割器继续抓新会话（p.28）。
- **GTG-50021**：假"便宜 Claude 接入"，实际**静默转到另一家的模型**，同时装收割器偷 Anthropic 账号凭据并转卖给其他代理转售商（p.28–29）。IOC 含 `kiro[.]cheap`、`awstore[.]cloud` 等。
- 报告明确：相关 key **全部来自 Anthropic 客户环境**，**Anthropic 自身系统未被攻破**；被偷的 key 还被用来跑攻击者的负载（把成本转嫁给受害者）。
- Anthropic 的建议原话：把 AI API key 与 **production credentials 同等对待**；AI 接入**只走授权渠道**。

---

## 六、报告其他章节里的隐私/敏感数据内容（非蒸馏，供完整性）

- **监控章（p.36）**：一名行为者用 AI 搭平台，融合**国家健康标识**、司法系统泄露数据与自身入侵所得，做成可按姓名查询的暗网服务——报告称为"AI 辅助软件工程直接用于**大规模隐私攻击**的最清晰案例之一"，且整平台由一人建成。42 个跟踪实体中至少 14 个被内网访问，外泄约 **12–26 GB** 数据库转储（含政党捐款人名册、1.5 万封邮箱、**含未成年人的学生申请记录**、支付方数据），并设置 live credential interception。
- **网络行动章**：GTG-20006 劫持酒店访客 WiFi 的 DNS，窃取住客信息与设备数据用于定向；对北非某政府科技主管机构的入侵**拖走 30 万余条国民身份记录与 50 余万家公司的商业登记**。
- **生物/两用章（p.132）**：灰市转售平台借 **ZDR（零数据留存）** 隐匿流量，并做"Claude 拒答就把敏感请求 fallback 到竞争对手模型"的机制。
- 提示：以上与"蒸馏链条中的用户数据外流"是**不同章节、不同性质**的问题，写报告时不应混算。

---

## 七、证据强度与不可核实点（务必随报告一起给出）

**原文自证的性质**
- 全部数字来自 **Anthropic 单方平台遥测**（`exchanges observed` / `attributable to`），无第三方审计、无样本日志、无受影响用户名单。
- 展示的证据是 **2 个打码 prompt** + 3 条枚举案例；**未**提供涉事中国企业名称、涉及的具体账号、泄露凭据的处置结果。
- 归因措辞强度不一，须照抄："we assess was **likely** affiliated with the PLA"（评估）、"**almost certainly** not made aware"（推断）、"**likely** inconsistent with privacy laws"（法律判断未定）、"We **do not know** if Moonshot notified their customers"（Anthropic 自认不知情）。
- 与 2026-02-23 专项不同：二月那份写过归因方法（IP 关联、请求元数据、基础设施指标、部分行业伙伴互证、与公开员工档案匹配等）；**九月报告的蒸馏/泄密章没有重复这些方法**，不能自动外推。

**【原文未给出】清单**
1. 受影响用户/企业的**数量与身份**（只说 "hundreds of end users"、"various Moonshot customers"）；
2. 泄露数据的**具体条目**、示例中的公司名与金额；
3. 是否有**通知受影响方**、是否有监管或司法介入；
4. 泄露的 live credentials **是否已撤销/是否被滥用**；
5. MiniMax 壳公司代理、SenseTime 购买誊本的**规模数字**；
6. 蒸馏/泄露相关的 **IOC**（随报告 209 条 IOC 中 `distillation` 命中为 0）；
7. 阿里、智谱是否也转发过第三方用户数据（报告**没有**这样指控）。

---

## 八、与二手报道的差异（本次核对）

| 媒体说法 | 原文实际 |
|---|---|
| TechCrunch："Moonshot 的行动 **似乎直接路由了中国军方的请求**（seemed to route requests directly from the Chinese military）" | 原文是"一名**被评估为可能与 PLA 有关**的用户，**以为自己在用 Kimi**，请求被 Moonshot 转发"——是**用户身份评估 + 平台静默转发**，不是军方直接操作 |
| "Anthropic 观察到近 2 亿次交换、五场行动"（TechCrunch） | 原文无合计；这是把五家数字加总（≈1.899 亿）且时间窗不对齐，与"泄密规模"更不是同一口径 |
| 把 6 月致参议院信函的 2,880 万次 / 2.5 万账号、NSA-FBI-CISA 联合声明混入本报告 | 这两个数字/文件**不在这份九月报告里**（信函为另一时间点的另一份文件） |
| CNBC 转述 151M / 5,380 / 23M、"不知是否通知客户" | 与原文一致，属准确转述 |

---

## 九、实务含义（仅基于原文能支持的部分）

1. **别把 live credential 贴进任何模型对话**：Example 2 就是 Telegram bot token + Feishu appSecret + Notion key 的原生样本；凡贴过的立即轮换。
2. **慎用第三方"模型路由/中转/聚合"平台**：原文直接把它列为"会留存并出售你对话"的一环（`without the knowledge or consent`），且 MiniMax 壳公司案例显示这类网络可以只服务于收割美方模型交换。企业使用 AI 网关时应要求**数据留存与转售的合同约束 + 审计**。
3. **供应商尽调要问数据流向**：若使用 Kimi / DeepSeek / MiMo 等，原文称存在"请求被静默转发到 Anthropic"的情形；采购与合规评估应要求供应商**书面说明**推理流量是否出境、是否转第三方、是否用于训练。
4. **AI key 视同生产凭据**：这是报告的原话建议——按生产系统密钥的生命周期、轮换、最小权限与泄露监控来做。
5. **受影响方权利路径**：如果你是案例中那类企业用户，原文并未给出救济渠道；可核查的现实动作是**向供应商索取数据处理说明**，而非依赖本报告。

---

## 十、关键原文摘录（英 → 中）

1. p.144｜`These resellers include the operators of proxy services, which often save exchanges between users and US models without the knowledge or consent of those users.`
   → 这些转售商包括代理服务的运营者，他们常在用户不知情、未同意的情况下保存用户与美国模型的往来。
2. p.144｜`In other cases, unauthorized labs rerouted requests from their users to Claude—without the knowledge or permission of those users—to harvest exchanges between users and Claude for training.`
   → 另一些情况下，未获授权的实验室把其用户的请求改道给 Claude——未经这些用户知情或允许——以收割用户与 Claude 的往来用于训练。
3. p.146｜`…misuse of user data by PRC AI labs. DeepSeek, Xiaomi, and Moonshot fed conversations between their own models and users into Claude.`
   → ……中国 AI 实验室对用户数据的滥用。DeepSeek、小米与 Moonshot 把自家模型与用户之间的对话喂给了 Claude。
4. p.146｜`Those sessions contained names, email addresses, company data, and other sensitive data of hundreds of end users in at least a dozen languages. These practices are likely inconsistent with privacy laws and the labs' own terms of service.`
   → 这些会话含数百名终端用户的姓名、邮箱、公司数据等敏感信息，涉及至少十几种语言。此类做法很可能违反隐私法及各实验室自家的服务条款。
5. p.149｜`We do not know if Moonshot notified their customers that their requests were being rerouted to Anthropic and exposed to a third party.`
   → 我们不知道 Moonshot 是否通知了客户：他们的请求正被改道至 Anthropic 并暴露给第三方。
6. p.149｜`The user had no way of knowing that their use of Kimi was being forwarded to Claude.`
   → 该用户无从得知自己对 Kimi 的使用正被转发给 Claude。
7. p.150｜`This sensitive data was likely routed to Anthropic without the knowledge or consent of DeepSeek's customers.`
   → 这些敏感数据很可能是在 DeepSeek 客户不知情、未同意的情况下被送到了 Anthropic。
8. p.150｜`The relayed requests exposed live credentials for a Russian government database.`
   → 被转发的请求暴露了一个俄罗斯政府数据库的在用凭据。
9. p.152｜`Those requests to Claude contained the names, contact information, corporate data, and other sensitive data from hundreds of Xiaomi users in at least a dozen languages.`
   → 这些发往 Claude 的请求含数百名小米用户的姓名、联系方式、公司数据等敏感信息，涉及至少十几种语言。
10. p.29｜`…malicious client side applications often spoofing as popular AI harnesses including Claude Code but were in fact credential harvesters that would gather all of the victim's credentials and authenticated session tokens on their device and send them to the attacker.`
    → ……常伪装成 Claude Code 等流行 AI 客户端的恶意程序，实为凭据收割器：收集受害者设备上全部凭据与已认证的会话令牌并送往攻击者。

---

**一句话**：这份原始文档里的"泄密"，核心是 **Moonshot、DeepSeek、Xiaomi 被指在用户不知情/未同意的情况下，把用户对话（含姓名、邮箱、公司数据、监控数据、live 凭据）转送第三方（Anthropic/Claude）**，波及"数百名终端用户、至少十几种语言"；同时报告还有一条独立的**凭据黑市**线索。所有数字均为 Anthropic 单方遥测、样例已打码，**原文明确承认不知道是否通知了客户**，也没有把阿里、智谱指控为转发用户数据。
