You Asked Kimi. Claude Answered. The Customer Was the Last to Know.
Anthropic says Moonshot piped nearly 300,000 Kimi chats to Claude Opus via 5,380 fake accounts, then kept the transcripts for training.

Via Yahoo Finance: Moonshot Secretly Routed User Requests Through Claude, Anthropic Says
The badge on the chatbot is not a guarantee
If your staff picked a chatbot because of its name, its price, or its privacy story, Thursday's report from Anthropic is a reminder that the badge on the product is not the same thing as the model in the pipe. Anthropic says Moonshot AI, the company behind Kimi, silently forwarded customer requests to Claude, showed Claude's answers as if they came from Kimi, and kept at least some of those exchanges for training.
Yahoo Finance carried the Bloomberg account on 10 September 2026. Anthropic's own September 2026 threat-intelligence report is more specific. Over one ten-day stretch, Moonshot relayed almost 300,000 customer requests to Anthropic, the vast majority to Opus, through a proxy network of 5,380 fraudulent accounts that mostly appeared to sit in Singapore and Japan.
Users, Anthropic says, thought they were talking to Kimi. For an owner-led firm, that is not a frontier-lab soap opera. It is a data-routing problem. If the model on the screen is not the model that answers, you do not know who saw the client file, which terms of service applied, or what got stored for someone else's training run.
Undisclosed routing is a business problem, not a lab feud
Model routing itself is ordinary. Firms switch models for cost, speed, or a fallback when one vendor wobbles. The issue Anthropic raises is concealment plus a second use: serving Claude's replies to Kimi customers and then running a chain-of-thought extraction pipeline on the saved transcripts.
Anthropic says it does not allow Claude to be accessed from inside China. The alleged workaround was a pool of fake accounts and proxy "transfer stations" -- disposable identities, rotating access, and, in the broader campaign, stolen API credentials belonging to legitimate companies. Those practices, Anthropic argues, harm the customers whose keys get burned when the traffic is discovered.
The same report puts Moonshot's alleged distillation traffic between May and July 2026 at more than 23 million exchanges. DeepSeek, Anthropic says, used similar silent-relay and reasoning-trace tricks. Alibaba's campaign was larger still: 151 million exchanges in that window, peaking near three million a day.
Anthropic also says some of the Kimi-to-Claude traffic included sensitive customer information, and that it does not know whether Moonshot told those customers their prompts had been sent to a third party. Privilege, HIPAA, FINRA, and plain client confidentiality do not care that the user interface still said "Kimi."
As of this writing, Moonshot has not issued a formal public reply to the 10 September routing claim. Treat the findings as Anthropic's allegations, not a court judgment. The diligence question does not wait for a verdict.
Ask who answers before the next badge swap
Smart firms treat model identity as a contract term, not a marketing claim. The questions are boring. That is the point.
- Ask who actually answers. Put model identity, subprocessors, and any fallback routing in the order form -- including when a vendor may substitute another lab's model without telling you.
- Ban consumer and grey-market front ends for client work. If staff are pasting files into a cheap wrapper or a personal account, you have already lost the chain of custody.
- Log the model ID, not just the product name. "We used Kimi" is not an audit trail. "We used model X at timestamp Y under contract Z" is.
- Separate training consent from inference. If a vendor can keep prompts to improve its own models, that is a different deal than a one-off answer. Say so in writing.
- Keep a continuity card. If a cheap imported assistant is suddenly blocked, sanctioned, or revealed as a pass-through, what do you switch to by Friday?
None of this requires a six-figure AI team. It requires someone to own the inventory -- and to treat "the chatbot said so" as insufficient when a client file is involved.
These users thought they were using a Kimi model, but received responses from Claude instead. -- Anthropic, September 2026
How BuildBrain helps you see the pipe, not just the badge
Most owner-led firms do not have a model-routing scandal. They have a quieter version of the same problem: staff using tools the owner has never approved, vendors that will not name their subprocessors, and no record of where last Tuesday's client summary actually went.
A Shadow-AI Risk Assessment and AI Governance Audit maps what the team actually uses -- including unsanctioned personal accounts and wrappers that do not match the approved list -- and where sensitive data is going. The deliverable is a risk register, a plain-English policy, and a roadmap, not a lecture about geopolitics.
Model Selection and Continuity Planning matches the job to a model you can name, with a fallback so a restricted, repriced, or quietly rerouted vendor does not take the workflow down with it. Managed AI Operations then keeps that inventory and policy from rotting the week after the audit.
The point is not to pick a side in a lab feud. It is to make sure the next prompt your firm sends has a known destination. See managed operations and governance services or book a no-pressure assessment.
If you cannot name the model, you cannot name the risk
The cheap lesson from Thursday is not "never use a Chinese model" and it is not "Anthropic is always the grown-up in the room." It is simpler: if you cannot say which model answered, you cannot say who saw the work.
What should an SME owner do this week? Ask every AI vendor whether they route prompts to another lab, whether they retain chats for training, and which legal entity processes the data. Then inventory the tools staff already use. The gap between those two lists is usually where the trouble lives.
Find out what your team is actually using -- and what your vendors are actually calling -- before the next transcript ends up in someone else's training run. Book a no-pressure assessment when you want that map owned, not hoped for.
This article summarizes publicly reported information and is for general informational purposes only. It does not constitute legal, tax, financial, investment, security, or compliance advice. BuildBrain is not a law firm, accounting firm, or registered investment adviser. Facts, pricing, statistics, and product capabilities cited here reflect the sources listed at the time of writing and may change. Readers should verify current information independently and consult qualified professionals regarding obligations specific to their industry, jurisdiction, and circumstances, including applicable federal, state and local requirements. BuildBrain may have commercial relationships with vendors mentioned; where material, such relationships are disclosed. Nothing in this article is an endorsement of any specific AI product, model, or provider.
