They are using stolen api keys and credentials.
Also, it is essential for the model's responses to be without censorship. In reality, responses sent to China by flagship models are known to be weaker.
https://www.anthropic.com/threat-intelligence-report-septemb...
>In one instance, over a ten-day period, Moonshot relayed almost 300,000 customer requests to Anthropic, the vast majority of which were routed to Opus. Moonshot used a proxy service network of 5,380 fraudulent accounts, most of which appeared to be located in Singapore and Japan.
That means they made up the names, basically.