Observed Signal · Jun 30, 2026 · Cyberattack / Espionage · Source: CNBC Technology · Impact: 3/5 · Sentiment: Negative

China-linked cyberattacks expand to steal U.S. AI

Executive Signal Summary

U.S. and industry sources warn that China-linked actors are increasingly targeting American AI technology through both technical intrusions and human-level exploitation. CrowdStrike reported Chinese entities accounted for more than half of state-sponsored intrusions against technology firms (12 months through March 31). Startups are particularly exposed because they often lack enterprise-grade defenses and are vulnerable to AI-amplified social engineering and insider risks. Anthropic has accused Chinese companies, including Alibaba, of illicit attempts to appropriate its capabilities; Copyleaks reported stylistic similarities between China’s DeepSeek R1 and OpenAI’s ChatGPT. An Agentiq Capital founder alleged an employee from China intentionally altered code to harm fundraising and filed a complaint with the FBI. Experts and U.S. agencies say economic espionage targeting AI threatens national security, raises startup operating costs, and could accelerate foreign narrowing of AI capability gaps.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Rises in state-linked cyberespionage targeting AI can accelerate foreign capability gains, increase security and compliance costs for startups and vendors, and raise national-security and supply‑chain risks for the broader technology ecosystem.

SIGNAL RADAR

Track CrowdStrike Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • CrowdStrike warned of increasing cyberattacks from China-based entities aimed at stealing AI and said Chinese entities accounted for more than half of state-sponsored intrusions targeting technology companies in the 12 months through March 31.
  • Anthropic accused Chinese companies, including Alibaba, of illicit attempts to steal its AI capabilities; Alibaba did not respond to requests for comment.
  • Copyleaks reported that outputs from Chinese startup DeepSeek’s R1 model resembled OpenAI’s ChatGPT roughly three-quarters of the time, suggesting the model may have been trained on U.S.‑developed data.
  • Brian Abbott, founder and CEO of Agentiq Capital, alleged a hired employee from China intentionally altered code and content to impede the company's venture funding; the employee was dismissed and Abbott said a complaint was filed with the FBI.
  • Industry experts warned startups are especially vulnerable due to limited security resources and AI‑amplified social engineering; Anthropic launched a Claude Corps program to train 1,000 people and match them with U.S. non-profits.

Connected Companies & Entities

4 Entities mapped

“U.S.-based cybersecurity giant CrowdStrike has warned of increasing cyberattacks from China-based entities aimed at stealing artificial inte...”

“American tech start-up Anthropic has also accused Chinese companies, including Alibaba, of illicit attempts to steal its AI capabilities....”

“Last year, U.S.-based AI content detection startup Copyleaks said the responses generated by Chinese startup DeepSeek’s R1 model resembled t...”

“DeepSeek and OpenAI did not immediately respond to requests for comment....”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: CNBC Technology•Published: Jun 30, 2026
Original Coverage Title: “China-linked actors target more than technology as AI competition with U.S. intensifies”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

CybersecurityJun 10, 2026

CrowdStrike: China Escalating AI Cyberespionage

CrowdStrike warned in a June 2026 report that China-affiliated state-sponsored actors have increased targeted cyberattacks against U.S. technology companies to steal AI capabilities and intellectual property. The firm said China-nexus actors accounted for more than 58% of state-sponsored targeted attacks against tech firms in the 12 months ending March 31, 2026, and that attackers maintained persistent access to North American tech organizations by exploiting vulnerabilities. CrowdStrike also reported North Korea-affiliated actors attempting to infiltrate IT workforces for revenue generation. The Cyberspace Administration of China did not respond to requests for comment. The story references earlier complaints from Anthropic and OpenAI about Chinese firms extracting competitive intelligence and notes recent public releases of Anthropic’s Claude Fable 5.

Read assessment
AI & TechnologySep 10, 2026

US Agencies Accuse Chinese AI Companies of Copying US Models

The FBI, NSA, and CISA jointly issued advisory AA26-251A accusing six Chinese AI companies—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.ai—of systematically extracting capabilities from US frontier models such as Anthropic's Claude, OpenAI's GPT, Google's Gemini, and xAI's Grok. The alleged operations, ongoing since late 2024, involved mass-purchased fake accounts, API exploitation, and proxy services, with probable knowledge of the Chinese government. These actions reportedly reduced development costs and timelines for the Chinese firms. China denied the allegations as groundless, urging cooperation. The advisory recommends US companies boost security monitoring, restrict anomalous high-volume accounts, and even degrade answers for suspected attackers, a measure with potential collateral impact. This development intensifies US-China AI competition and raises concerns over model distillation.

Read assessment
AISep 9, 2026

US Accuses Chinese AI Firms of Industrial-Scale Model Theft

The United States is escalating its technological conflict with China by targeting Chinese AI companies DeepSeek, Moonshot AI, and Alibaba for allegedly using model distillation to systematically extract capabilities from American AI systems. US authorities, citing national security concerns, accuse these firms of bypassing access restrictions and using automated methods to harvest model outputs for training their own models. Anthropic reported identifying over 3.4 million suspicious interactions with its Claude models from Moonshot AI, while OpenAI flagged activities consistent with adversarial distillation attempts by DeepSeek. The dispute highlights the growing importance of model distillation as both a legitimate development tool and a point of contention, with potential implications for licensing, trade secrets, and access controls. The US government is treating advanced AI as dual-use technology, similar to chip export restrictions, which could lead to sanctions affecting cloud services, chips, and other components.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.