{"data":{"id":"43e1499e-26cf-421e-afa8-30bc08bf14ef","title":"Disrupting a coordinated model-distillation campaign","summary":"OpenAI disrupted a coordinated campaign, first observed in early July, that sought to extract protected reasoning from its models through adversarial distillation. Operators manipulated model interactions, including copying encrypted reasoning from one conversation and asking a model in another to decrypt and transcribe it, rather than breaking encryption or accessing stored conversations. A July 24 and 25 spike reached 16,000 requests from over 4,000 users, and the wider cluster of more than 15,000 users was fully disrupted by July 28. OpenAI attributes a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi.","solution":"OpenAI banned or restricted fraudulent accounts, strengthened signup and infrastructure controls, expanded monitoring for related networks, and strengthened protections for hidden reasoning across users, workspaces, organizations, and model families. It also closed a pathway that allowed someone who already possessed reasoning content to extract it further. Additional mitigation and investigation work is continuing.","labels":["security","industry"],"sourceUrl":"https://openai.com/index/disrupting-a-coordinated-model-distillation-campaign","publishedAt":"2026-09-30T10:30:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"medium","attackType":["model_theft","data_extraction"],"issueType":"incident","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":["OpenAI"],"affectedVendorsRaw":["OpenAI","Moonshot AI","Kimi","Frontier Model Forum"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-09-30T10:30:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}