You apparently did not read the source materials. Let me quote the Anthropic threat report for you:
I accepted your CISA reference. I'll accept references from other similar organizations or law enforcement. I am unwilling to defer to Anthropic as they have a clear conflict of interest with billions of dollars on the line and a track record of manipulative behavior.
Having said this I remain disappointed in the continued failure to read your own references. This is a report titled "Detecting and countering misuse of AI" it speaks in general terms about AI and misuse of AI services for crime. It is not focused entirely on the distillation issue by leading Chinese AI firms.
The quote you referenced:
"These groups then often sell that access through brokers, which often feed into fraudulent AI reseller networks that rotate in new stolen API keys and session tokens until they exhaust their usage. Malicious actors also use or purchase these stolen API keys and session tokens from brokers for their cyber attack operations."
Is in reference to the section on crime and the use of AI to commit crimes under the heading "AI supply chain as target, loot, and attack compute". This is separate from the Chinese distillation allegations.
In fact NONE of the named distillation campaigns described on pg147 thru the end of the report GTG 16005, GTG-16002, GTG-16001, GTG-16006, GTG-16008, GTG-16012, GTG-16003 say anything whatsoever about stolen credit cards or stolen credentials. I wonder why that is? Why does CISA not mention the stolen credit cards and stolen credentials? Perhaps because it never happened?
Over the last several months, unauthorized labs have developed increasingly sophisticated methods to circumvent our defenses and harvest the capabilities of US frontier models. These labs generally access Anthropicâ(TM)s models by routing requests through proxy services, also known as âoetransfer stations.â To circumvent our geographic restrictions and related controls, these proxy services create thousands of new accounts using false identities, fake or stolen credit cards, and stolen API keys. They will often use stolen API credentials belonging to legitimate companies or individuals to give unauthorized entities access to US frontier models. These fraudulent activities harm legitimate customers. The graphic below illustrates the life cycle of an illicit distillation campaign.
This is general language that speaks to "unauthorized labs" without naming names and incurring associated libel per se liability. It is impossible from the language to link stolen cards and stolen credentials to any particular or any subset of AI firms because no such linkage is present in the text.
If you separately have credible evidence of stolen credit cards and stolen credentials being used by the relevant leading Chinese AI firms I am interested in learning more about it.
I'd implore you to stick to the facts and actually read the source materials before accusing others of 'peddling bullshit.' Your claim that AI distillation doesn't use hacked credentials is patently false.
Please just stop digging. You obviously just CTRL+F for keyword and cut and paste without even bothering to understand the context of the statements. This same sloppiness is pervasive throughout your statements.
The underlying argument you are peddling is also rather crazy in its own right. A "distillation attack" does not require stolen credit cards or stolen credentials. The modality of access to the teacher model is not even relevant to its definition. It doesn't stop being a "distillation attack" even if the lab paid the normal rate for access to the model.
That someone somewhere performing distillation to improve their models uses a stolen credit card to do so is irrelevant... It doesn't in any way justify calling distillation an attack.
Imagine if I decided going to a supermarket and filling the shopping cart up to the brim would be called a "shopping attack" ... when someone calls my bullshit term out I turn around and point to some rando who filled their cart and didn't pay on their way out to justify the attack terminology... even though most people who fill their shopping carts to the brim and do pay are still performing a "shopping attack".
This is the exact same logic you are attempting to peddle here. It make no sense.