INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates

| 2026-10-01 10:42 MEDIUM LOW CYBERATTACK (GENERAL)
Executive Summary
AI-generated
On July 1, 2026, a coordinated distillation campaign was launched by individuals associated with Moonshot AI Associates, a Chinese AI company based in Beijing. The attackers manipulated model interactions to illicitly extract protected reasoning from OpenAI's artificial intelligence models, resulting in 16,000 attempted requests using a relevant extraction pattern from over 4,000 users on July 24 and 25, 2026. This activity was fully disrupted by OpenAI on July 28, 2026. The attackers exploited an architectural vulnerability impacting Claude, Gemini, and GPT models to develop a scalable decryption jailbreak, allowing them to extract private data from the models without compromising direct access or encryption.
Technical Mitigations AI-generated
• OpenAI has deployed additional mitigations to combat the adversarial distillation attack, including checks to detect and hold streamed output that might expose reasoning. • The company closed a "pathway" that made it possible for someone who already possessed another user's encrypted reasoning to replay it and recover its contents. • Researchers from MATS Research, ELLIS Institute Tübingen, and Synk found an architectural vulnerability impacting Claude, Gemini, and GPT that could be exploited by attackers.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA NORTH_AMERICA technologytechnology
Incident Timeline
‎July 24 and 25, 2026
Threat actors used a relevant extraction pattern from over 4,000 users to send approximately 16,000 attempted requests on July 24 and 25, 2026.
general_metric 16,000 attempted requests
victims 4,000 users
‎July 24 and 25
Threat actors used low-level activity to gradually increase attempts at OpenAI's system until July 24 and 25, when they made 16,000 prompts from 4,000 users.
general_metric 16,000 attempted requests
victims 4,000 users
organisation OpenAI
‎July 1, 2026
Threat actors used a relevant extraction pattern to target over 4,000 users with attempted requests exceeding 16,000 on July 24 and 25, 2026.
general_metric 16,000 attempted requests
victims 4,000 users
victims 15,000 users
‎July 1
Threat actors used low-level activity to gradually increase attempts at OpenAI's system until July 24 and 25, when they made 16,000 prompts from 4,000 users.
general_metric 16,000 attempted requests
victims 4,000 users
organisation OpenAI
‎July 28, 2026
OpenAI successfully disrupted a reasoning extraction campaign linked to Moonshot AI Associates on July 28, 2026.
organisation OpenAI
‎July 28
OpenAI said it fully disrupted a reasoning extraction campaign linked to Moonshot AI Associates, which had grown to 15,000 suspicious users by July 28.
‎August 2026
Researchers from MATS Research, ELLIS Institute Tübingen, and Synk discovered an architectural vulnerability in Claude, Gemini, and GPT models that allowed for the interchangeable encryption of reasoning traces across different sessions.
organisation Claude
organisation GPT
organisation MATS Research
organisation ELLIS Institute Tübingen
organisation CoT
‎2026/09/01
Threat actors linked to Moonshot AI Associates allegedly used a stealthy relaying tactic involving Anthropic's rival, Claude, to intercept and respond to customer requests.
‎Oct 01, 2026
Threat actors associated with Moonshot AI used OpenAI's AI models to illicitly extract protected reasoning.
tactic T1588.007 - Artificial Intelligence
‎2026/10/01
Threat actors linked to Moonshot AI Associates conducted a coordinated campaign of "systematic" distillation attacks on OpenAI's latest models.
organisation Moonshot AI Associates
organisation Google
organisation CyberScoop
organisation the Frontier Model Forum
Tactical Metrics
Metrics
victims
4,000
Users
Metrics
victims
15,000
Users