INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
| 2026-10-01 10:42 MEDIUM LOW CYBERATTACK (GENERAL)
Executive Summary
AI-generated
On July 1, 2026, a coordinated distillation campaign was launched by individuals associated with Moonshot AI Associates, a Chinese AI company based in Beijing. The attackers manipulated model interactions to illicitly extract protected reasoning from OpenAI's artificial intelligence models, resulting in 16,000 attempted requests using a relevant extraction pattern from over 4,000 users on July 24 and 25, 2026. This activity was fully disrupted by OpenAI on July 28, 2026. The attackers exploited an architectural vulnerability impacting Claude, Gemini, and GPT models to develop a scalable decryption jailbreak, allowing them to extract private data from the models without compromising direct access or encryption.
Technical Mitigations AI-generated
• OpenAI has deployed additional mitigations to combat the adversarial distillation attack, including checks to detect and hold streamed output that might expose reasoning.
• The company closed a "pathway" that made it possible for someone who already possessed another user's encrypted reasoning to replay it and recover its contents.
• Researchers from MATS Research, ELLIS Institute Tübingen, and Synk found an architectural vulnerability impacting Claude, Gemini, and GPT that could be exploited by attackers.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
technologytechnology
Incident Timeline
July 24 and 25, 2026
Threat actors used a relevant extraction pattern from over 4,000 users to send approximately 16,000 attempted requests on July 24 and 25, 2026.
Click on any entity below to view its context and source!
general_metric
16,000 attempted requests
The activity is said to have begun on July 1, 2026, initially at a low volume before it spiked on July 24 and 25, 2026, to 16,000 attempted requests using a relevant extraction pattern from over 4,000 users.
victims
4,000 users
The activity is said to have begun on July 1, 2026, initially at a low volume before it spiked on July 24 and 25, 2026, to 16,000 attempted requests using a relevant extraction pattern from over 4,000 users.
July 24 and 25
Threat actors used low-level activity to gradually increase attempts at OpenAI's system until July 24 and 25, when they made 16,000 prompts from 4,000 users.
Click on any entity below to view its context and source!
general_metric
16,000 attempted requests
On Wednesday, OpenAI said it first spotted low-level activity on July 1 that gradually increased until July 24 and 25, when it observed 16,000 prompts from 4,000 users that fit a similar “relevant extraction pattern.”
victims
4,000 users
On Wednesday, OpenAI said it first spotted low-level activity on July 1 that gradually increased until July 24 and 25, when it observed 16,000 prompts from 4,000 users that fit a similar “relevant extraction pattern.”
organisation
OpenAI
On Wednesday, OpenAI said it first spotted low-level activity on July 1 that gradually increased until July 24 and 25, when it observed 16,000 prompts from 4,000 users that fit a similar “relevant extraction pattern.”
July 1, 2026
Threat actors used a relevant extraction pattern to target over 4,000 users with attempted requests exceeding 16,000 on July 24 and 25, 2026.
Click on any entity below to view its context and source!
general_metric
16,000 attempted requests
The activity is said to have begun on July 1, 2026, initially at a low volume before it spiked on July 24 and 25, 2026, to 16,000 attempted requests using a relevant extraction pattern from over 4,000 users.
victims
4,000 users
The activity is said to have begun on July 1, 2026, initially at a low volume before it spiked on July 24 and 25, 2026, to 16,000 attempted requests using a relevant extraction pattern from over 4,000 users.
victims
15,000 users
Upon further investigation, the company said it identified related "prompt-pattern activity" across more than 15,000 users.
July 1
Threat actors used low-level activity to gradually increase attempts at OpenAI's system until July 24 and 25, when they made 16,000 prompts from 4,000 users.
Click on any entity below to view its context and source!
general_metric
16,000 attempted requests
On Wednesday, OpenAI said it first spotted low-level activity on July 1 that gradually increased until July 24 and 25, when it observed 16,000 prompts from 4,000 users that fit a similar “relevant extraction pattern.”
victims
4,000 users
On Wednesday, OpenAI said it first spotted low-level activity on July 1 that gradually increased until July 24 and 25, when it observed 16,000 prompts from 4,000 users that fit a similar “relevant extraction pattern.”
organisation
OpenAI
On Wednesday, OpenAI said it first spotted low-level activity on July 1 that gradually increased until July 24 and 25, when it observed 16,000 prompts from 4,000 users that fit a similar “relevant extraction pattern.”
July 28, 2026
OpenAI successfully disrupted a reasoning extraction campaign linked to Moonshot AI Associates on July 28, 2026.
Click on any entity below to view its context and source!
organisation
OpenAI
In addition, OpenAI said it closed a "pathway" that made it possible for someone who already possessed another user's encrypted reasoning to replay it and recover its contents, alongside adding checks to detect and hold streamed output that might expose reasoning.
July 28
OpenAI said it fully disrupted a reasoning extraction campaign linked to Moonshot AI Associates, which had grown to 15,000 suspicious users by July 28.
August 2026
Researchers from MATS Research, ELLIS Institute Tübingen, and Synk discovered an architectural vulnerability in Claude, Gemini, and GPT models that allowed for the interchangeable encryption of reasoning traces across different sessions.
Click on any entity below to view its context and source!
organisation
Claude
In a study published in August 2026, a group of researchers found an architectural vulnerability impacting Claude, Gemini, and GPT that made the encrypted reasoning traces "fully compatible and interchangeable across different sessions, users, and models within a provider's ecosystem."
organisation
GPT
In a study published in August 2026, a group of researchers found an architectural vulnerability impacting Claude, Gemini, and GPT that made the encrypted reasoning traces "fully compatible and interchangeable across different sessions, users, and models within a provider's ecosystem."
organisation
MATS Research
"By injecting an encrypted reasoning trace from a given model into a weaker, and less safeguarded model from the same provider, we force it to decode and output the trace verbatim in plaintext, without ever jailbreaking the more capable model directly," researchers from MATS Research, ELLIS Institute Tübingen, and Synk
said
.
organisation
ELLIS Institute Tübingen
"By injecting an encrypted reasoning trace from a given model into a weaker, and less safeguarded model from the same provider, we force it to decode and output the trace verbatim in plaintext, without ever jailbreaking the more capable model directly," researchers from MATS Research, ELLIS Institute Tübingen, and Synk
said
.
organisation
CoT
The company is also alleged to have retained a subset of these exchanges to train its chain-of-thought (CoT) model.
2026/09/01
Threat actors linked to Moonshot AI Associates allegedly used a stealthy relaying tactic involving Anthropic's rival, Claude, to intercept and respond to customer requests.
Oct 01, 2026
Threat actors associated with Moonshot AI used OpenAI's AI models to illicitly extract protected reasoning.
Click on any entity below to view its context and source!
tactic
T1588.007 - Artificial Intelligence
Ravie Lakshmanan
Oct 01, 2026
Artificial Intelligence / Vulnerability
OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models.
2026/10/01
Threat actors linked to Moonshot AI Associates conducted a coordinated campaign of "systematic" distillation attacks on OpenAI's latest models.
Click on any entity below to view its context and source!
organisation
Moonshot AI Associates
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates.
organisation
Google
Cybersecurity experts at Google and other cybersecurity firms say Chinese companies rely on black or gray markets to acquire thousands of individual accounts for models like Claude and ChatGPT.
organisation
CyberScoop
OpenAI told CyberScoop that it was not sharing any additional information “for security reasons.”
organisation
the Frontier Model Forum
According to OpenAI, the same vulnerability exists in other AI models, and it has shared information about the incident with groups like the Frontier Model Forum.
Tactical Metrics
Metrics
victims
4,000
Users
Click for context!
The activity is said to have begun on July 1, 2026, initially at a low volume before it spiked on July 24 and 25, 2026, to 16,000 attempted requests using a relevant extraction pattern from over 4,000 users.
On Wednesday, OpenAI said it first spotted low-level activity on July 1 that gradually increased until July 24 and 25, when it observed 16,000 prompts from 4,000 users that fit a similar “relevant extraction pattern.”
Metrics
victims
15,000
Users
Upon further investigation, the company said it identified related "prompt-pattern activity" across more than 15,000 users.
Intelligence Sources
The Hacker News
2026-10-01
CyberScoop
2026-09-30
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:38
Comprehensive Tactical Telemetry
Highly Correlated Entities
11x
organisation
Identified Entity
OpenAI Disrupts Reasoning Extraction Campaign Linked to
entity
9x
timeline
Temporal Reference
Oct 01, 2026
date
2x
victims
Users
4,000
users
2x
target region
Target Country
China
country
Contextual Telemetry
Context Block
4 METRICS
tactic
MITRE ATT&CK Technique
T1588.007 - Artificial Intelligence
technique
source region
Origin Country
China
country
general metric
Attempted Requests
16,000
attempted requests
industry
Targeted Sector
Government
sector
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.