(TLP:CLEAR) Joint Advisory: China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
Created: Thursday, September 10, 2026 - 14:55
Categories: Cybersecurity, Federal & State Resources, Security Preparedness
Summary: On September 8, 2026, the NSA, CISA, and FBI released a joint Cybersecurity Advisory (CSA), “China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies” (AA26-251A). The authoring agencies allege that several China-based AI firms, including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, have systematically extracted proprietary capabilities from U.S. frontier models through high-volume knowledge distillation, a technique in which a lesser model is trained on the outputs of a more advanced one. According to the advisory, these campaigns have run since at least late 2024 and form the core, rather than a supplement, of the named companies’ model development.
The advisory describes how the actors route requests through native APIs, cloud providers, and third-party aggregators, and use a gray market of proxies known as “transfer stations” to bypass geographic restrictions, evade safeguards, and undermine traceability. It maps the observed tactics to the MITRE ATLAS framework, details several novel tactics not currently in ATLAS, and recommends detection, response, and cross-organization information sharing measures aimed primarily at AI model providers.
Analyst Note: This advisory sits outside the water sector’s usual operational concerns, since its mitigations are directed at AI model developers rather than utilities. That said, it carries relevance worth noting as utilities increasingly adopt AI tools for tasks such as anomaly detection and log analysis. The behavioral indicators the advisory highlights, including fraudulent account creation, obfuscated origin, and abnormal usage patterns, reflect the broader reality that AI systems and the accounts behind them are now high-value targets for espionage and resource theft. Utilities evaluating AI vendors can reasonably ask how those providers detect and respond to account abuse and data extraction, since the integrity of a model a utility relies on depends in part on the provider’s ability to defend it. WaterISAC shares this advisory for situational awareness given the growing role of AI across the sector.
Original Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a
Additional Reading:
Related WaterISAC PIRs: 6, 7, 7.1, 8, 10.1, 12
