NEWS
The Distillation Fight Splits Three AI Security Stocks
CISA’s distillation advisory funds model-access controls, not airport lanes or phone forensics, splitting three AI security stocks on one screen.
CISA, the NSA and the FBI told U.S. AI labs on September 8 to catch fake accounts and quietly change answers used to copy frontier models. Anthropic’s September report then put Alibaba-linked operators at more than 151 million Claude exchanges from May to July. Stock screens folded that fight into three U.S. names tagged as AI security stocks. Only one of those names sells tools that match the federal ask.
Cellebrite DI cracks phones for police. Clear Secure runs airport identity lanes. Tenable Holdings scans networks, cloud and AI tools for exposure. Distillation runs through APIs, proxy “transfer stations” and bulk subscriptions, which is a different bill.
CISA’s Order to Poison Distillation Queries
The joint CISA, NSA and FBI advisory AA26-251A, dated September 8, names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The agencies said those firms had pulled billions of tokens from variants of Claude, GPT, Gemini and Grok since at least late 2024, likely with Chinese government awareness. Distillation, they wrote, is a normal research method. The campaigns they described were industrial, aimed at restricted features, and routed through native APIs, remote clouds, aggregators that hide user metadata, and a gray market of proxies they call transfer stations.
Anthropic had already taken the same charge to Congress. On June 10 it sent a letter to Senators Tim Scott and Elizabeth Warren, chair and ranking member of the Senate Banking Committee. Sarah Heck, Anthropic’s head of policy, wrote that operators tied to Alibaba and its Qwen lab ran more than 28.8 million Claude exchanges from April 22 to June 5 through almost 25,000 fraudulent accounts. That letter is a different window from the later report, not a second count of the same traffic.
The company’s September threat intelligence report raised the Alibaba-linked total to more than 151 million exchanges from May to July, the largest distillation attack it said it had measured, aimed at chain-of-thought transcripts from Opus 4.6 and 4.7. It attributed more than 23 million exchanges in the same span to Moonshot AI, and said Moonshot had silently forwarded some customer requests to Claude instead of answering them with Kimi. DeepSeek, it said, used similar forwarding. The labs already see who is querying them. The new federal ask is to make those answers worse on purpose, then share the names across vendors.
We're publishing our most detailed threat intelligence report to date.
It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them.
We disrupted every operation in the report,…
— Anthropic (@AnthropicAI) September 10, 2026
THE FEDERAL ASK TO U.S. AI LABS
- Detection: Flag odd prompts, accounts, networks and behavior, and watch subscription-to-usage ratios, instant max usage from new accounts, and enterprise-scale throughput.
- Poisoned replies: Quietly alter answers for suspected distillation so the stolen training set is less useful, without tipping off the operator.
- Shared intel: Correlate activity across model providers, cloud platforms and API aggregators so a campaign split across vendors still shows up as one.
That list is a product spec for frontier labs and for whoever sells them abuse detection, identity on API keys, and controls on how enterprises connect models to tools. It is not a spec for unlocking a seized iPhone or waving a face at TSA.
THE POLICY CALENDAR
- April 23, 2026: White House science adviser Michael Kratsios issues a memo that treats industrial-scale distillation by China-based entities as theft of U.S. AI intellectual property.
- June 10, 2026: Anthropic’s letter to Senators Scott and Warren describes the April 22 to June 5 Alibaba-linked campaign.
- September 8, 2026: CISA, NSA and the FBI publish AA26-251A and tell U.S. labs to detect, poison and share.
- September 10, 2026: Anthropic publishes the fuller threat report, including the 151 million Alibaba-linked exchanges.
Chip export rules still matter for training runs. They do not stop a fake account with a stolen key from scraping a hosted model. Distillation is also a method U.S. labs use on their own systems. The fight CISA described is about scale, geoblock bypass and terms-of-service breach, which is why the first buyers of the new controls are the model makers, not a generic “cyber” basket.
Tenable Is Already on the Model Side
Tenable is the name on the screen that actually sells into that second ring. It does not run Claude’s login page. It does sell exposure management for networks, cloud, identities and AI tools, and it has spent 2026 wiring frontier models into that platform.
On May 20 it said Anthropic would power new workflows in Tenable Hexa AI, the agentic engine inside Tenable One, and that Claude would be used for prioritization, remediation and exposure analysis. Jason Clinton, Anthropic’s deputy CISO, put the pitch in lab language, not stock-screener language.
As AI reshapes cybersecurity, organizations need to integrate AI into their security operations. We’re excited to work with Tenable to apply Claude’s capabilities to help customers better understand risk, prioritize action, and respond faster.
Jason Clinton, Deputy CISO, Anthropic, on Tenable’s May 20 partnership announcement
On June 22 Tenable said it had joined OpenAI’s Daybreak cyber partner program, to test GPT-5.5 in defensive workflows. Hexa AI also ships a Model Context Protocol server so customers can bring their own models and still call Tenable’s tool library. That is access control for agents, which is closer to CISA’s third action than a boarding pass is.
On September 8, the same day as the advisory, Tenable said it would bring Claude Mythos 5 into Tenable One. Chief Product Officer Eric Doerr wrote that Adversary View would use Mythos 5 on scan data Tenable already collects, including live connections and plugin output that never became a finding, and return ranked vulnerability chains rather than another alert pile. The company said the feature would debut in the weeks after that note. Tenable also sells Tenable AI Exposure, which it describes as a way to see how an organization is using AI, including shadow AI, and it said Tenable One Cloud Exposure had FedRAMP High and Impact Level 5 authorization.
That does not stop Qwen from scraping Claude. It does put Tenable in the room where enterprises inventory models, lock down MCP tools, and ask a frontier model to reason over their own attack surface. That is the ring around the labs, not the lab itself.
The financials are less dramatic than the product copy. For the quarter ended June 30, Tenable reported revenue of $268.5 million, up 8.6% from a year earlier, and GAAP net income of $3.8 million after a $14.7 million loss a year earlier. GAAP operating margin was 4.6%, against a 3.0% operating loss in the year-ago quarter. Non-GAAP operating income was $66.2 million, or a 24.7% margin, up 540 basis points from 19.3%. Non-GAAP diluted EPS was $0.51. Operating cash flow was $44.7 million and unlevered free cash flow $45.3 million. Recurring revenue was 95% of sales. Remaining performance obligations were $1.03 billion. Full-year revenue guidance is $1.075 billion to $1.081 billion, with non-GAAP diluted EPS of $1.95 to $2.00. The company says it has over 40,000 customers.
What Cellebrite’s FedRAMP High Unlocks
Cellebrite’s AI story is real and it is not this story. On May 6 the company said it had FedRAMP High for Cellebrite Government Cloud, with the Department of Justice as authorizing agency, so federal examiners could use Inseyets and Guardian on sensitive unclassified evidence. Management has said fewer than 100 companies hold that High baseline. The customer is still a detective.
This authorization removes the single biggest barrier between federal investigative agencies and secure, cloud-based digital forensics, investigations and intelligence operations.
Phil O’Reilly, Chief Operating Officer, Cellebrite Federal Solutions, May 6 press release
Cellebrite says more than 7,000 law enforcement, defense and intelligence customers use its software, and that the tools support nearly 3 million legally sanctioned investigations a year. Genesis, an agentic product for investigators, reached general availability on June 10. Early monetization in the first weeks was about $400,000 of annual recurring revenue, with more than half a dozen customers by the end of the second quarter. That is investigative AI for casework, sold into an installed base that already buys phone extraction.
Second-quarter results showed the core still dominates. Annual recurring revenue was $507.8 million, up 21%. Revenue was $131.1 million, up 16%, with subscription revenue of $119.5 million. GAAP net income was $6.4 million. Adjusted EBITDA was $31.8 million, a 24.2% margin. Trailing-twelve-month free cash flow was $144.2 million. The company closed a first major FedRAMP Guardian order with a long-standing federal customer, a seven-figure deal it said was nearly 35 times the roughly $50,000 average annual spend of a typical state or local agency. It also cut full-year ARR guidance to $550 million to $560 million and revenue to $555 million to $561 million after large government deals slipped, while lifting adjusted EBITDA to $153 million to $159 million, about a 28% margin. Shiven Ramji became CEO in August, succeeding Tom Hogan.
Federal cloud clearance helps Cellebrite sell Guardian to DOJ components such as the FBI, ATF and DEA. It does not put the company on CISA’s list of labs that must poison distillation traffic. If a U.S. attorney someday wants a phone in a separate case, Inseyets is the product. The Anthropic versus Alibaba IP fight is an API-abuse and export-control fight.
CLEAR’s Biometrics Live in a Different Budget
Clear Secure is even further from the query stream. Its first-quarter 2026 financial results, released May 6, showed revenue of $253.0 million, up 19.7%, and total bookings of $291.7 million, up 40.8%. Operating income was $62.0 million, a 24.5% margin. Net income was $56.4 million, a 22.3% margin. Adjusted EBITDA was $80.6 million, a 31.9% margin, up 720 basis points. Total members reached 41.0 million, up 31.3%. Active CLEAR+ members reached 8.2 million, up 13.0%. The company counted 60 CLEAR+ airports and 277 retail locations for TSA PreCheck enrollment, with eGates in 43 airports and CLEAR Concierge in 32. CLEAR1, the enterprise identity product, had bookings about five times the year-ago quarter. Second-quarter revenue guidance was $268 million to $271 million. Full-year free cash flow guidance rose to at least $465 million.
CEO Caryn Seidman-Becker tied the quarter to “AI-driven fraud” and said identity is “foundational.” The cash still comes from airport lanes, PreCheck enrollments and a smaller enterprise ID stack used in healthcare and government. A transfer station that resells Claude tokens does not fail a CLEAR+ facial check, and a CLEAR+ facial check does not rate-limit an API. Partnerships with airlines, Samsung, Expedia and General Dynamics widen where the identity graph can travel. They do not make CLEAR a model-protection vendor.
Three Tickers and Their Real Customers
The screen that grouped these names treated “data protection pressure” as one budget. The customers, the contracts and the CISA actions say otherwise.
WHO BUYS WHAT
| Company | Core product | Who pays | Overlap with distillation |
|---|---|---|---|
| Tenable Holdings | Tenable One, Hexa AI, AI Exposure | Enterprises and agencies securing networks, cloud, identities and AI tools; over 40,000 customers | Closest of the three: Anthropic and OpenAI cyber partner, MCP tool control, federal cloud exposure |
| Cellebrite DI | Inseyets, Guardian, Genesis | More than 7,000 law enforcement, defense and intelligence agencies | FedRAMP High evidence cloud; investigative AI for cases, not API abuse defense |
| Clear Secure | CLEAR+, TSA PreCheck enrollment, CLEAR1 | Travelers at 60 airports plus enterprise identity buyers | Biometric identity and airport throughput; no model-access product |
Tenable’s Q2 growth of 8.6% is slower than Cellebrite’s 16% revenue growth and CLEAR’s 19.7%. Profitability on a GAAP basis just turned positive at Tenable, while CLEAR already prints a 22.3% net margin and Cellebrite is profitable on both GAAP and adjusted EBITDA. The distillation overlay does not re-rank those income statements. It only asks which product catalog moves if labs and their enterprise customers spend on the three CISA actions.
$725 Million of Notes at Tenable
On September 10, the same day as Anthropic’s report, Tenable priced an upsized $725.0 million offering of 0.25% convertible senior notes due 2031, after first proposing $650.0 million. Convertible paper is cheap debt with equity optionality, not a distillation contract. It does add dry powder, and dilution risk, at the one name in the trio that is actually shipping model-side features.
Adversary View was still a coming-weeks item as of the September 8 blog, not a billed SKU with disclosed revenue. Hexa’s Advanced tier carries a 60% price premium over standalone vulnerability-management licensing in commentary around the May launch, which is a packaging claim, not a booked mix shift. Tenable One as a share of new sales was 50% in the company’s Q2 deck, which is the platform story investors already had before CISA published.
Cellebrite’s Genesis ARR of about $400,000 after a June 10 launch is a rounding error next to $507.8 million of total ARR, and the FY ARR cut shows federal timing still bites. CLEAR’s 41.0 million members and 31.9% adjusted EBITDA margin are a travel-identity compounder. Pairing either name to a 151 million-query Claude scrape is a theme, not a revenue map.
People arguing the report on X treated it as an IP and privacy event, including whether labs can see forwarded user chats, and whether cheap Chinese tokens already baked in the copied reasoning. They did not treat it as a three-stock screen. Token prices did not wait on a court. The second-order spend, if it shows up in public companies at all, shows up where someone is paid to watch accounts, throttle APIs, inventory shadow models and put a harness around agents.
The Watchlist Filter Nobody Applied
CISA told the labs to detect, poison and share. Anthropic said Alibaba-linked operators ran the largest Claude distillation campaign it has measured, then published the 151 million-exchange count on September 10. Tenable is wiring Mythos 5 into Tenable One and has a new $725.0 million convertible on the books. Cellebrite is selling FedRAMP-cleared evidence cloud and Genesis to detectives. CLEAR is selling faster airport identity. Those are four facts, not one trade.
Disclaimer: This article is news analysis of company releases, a federal cybersecurity advisory and a vendor threat report, and it is informational only. It is not investment advice, a solicitation, or a recommendation to buy or sell shares of Cellebrite DI, Tenable Holdings, Clear Secure or any other security. Readers should consult a licensed financial adviser or other qualified investment professional who can weigh their objectives, risk tolerance and tax situation before making any decision. Revenue figures, product dates, note terms and regulatory statuses reflect the cited disclosures as of the dates on those documents and may change with later filings, guidance or enforcement.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
