Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

DeepSeek’s database was wide open—did hackers get in?

DeepSeek has garnered significant attention for its innovative open-source AI models that aim to compete with established systems like OpenAI

byKerem Gülen
January 31, 2025
in News, Cybersecurity
Home News
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail

DeepSeek, the trending Chinese artificial intelligence (AI) startup, recently exposed one of its databases on the internet, potentially allowing unauthorized access to sensitive data. The exposed ClickHouse database provided full control over its operations, according to Wiz security researcher Gal Nagli.

DeepSeek exposes over a million lines

The exposure included over a million lines of log streams featuring chat history, secret keys, backend details, and other critical information, such as API secrets and operational metadata. Following notification attempts from the cloud security firm, DeepSeek has since fixed the security vulnerability.

The database, which was accessible at oauth2callback.deepseek[.]com:9000 and dev.deepseek[.]com:9000, enabled unauthorized users to execute arbitrary SQL queries via the web browser without requiring authentication. It remains unclear if any malicious actors accessed or downloaded the data before the issue was resolved.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

deepseeks-database-was-wide-open-did-hackers-get-in
Image: Wiz Research

Nagli emphasized the risks of rapid AI service adoption without adequate security measures, highlighting that real risks often stem from basic oversights like accidental database exposure. He stated, “Protecting customer data must remain the top priority for security teams, and it is crucial that security teams work closely with AI engineers to safeguard data and prevent exposure.”

deepseeks-database-was-wide-open-did-hackers-get-in
Image: Wiz Research

DeepSeek has garnered significant attention for its innovative open-source AI models that aim to compete with established systems like OpenAI, positioning its reasoning model R1 as an “AI’s Sputnik moment.” Its AI chatbot rapidly climbed to the top of app store rankings across multiple markets, even as the company faced “large-scale malicious attacks,” which led to a temporary pause in new registrations.

deepseeks-database-was-wide-open-did-hackers-get-in
Image: Wiz Research

In a January 29, 2025 update, DeepSeek acknowledged the database issue and indicated that it is implementing a fix. Concurrently, the company faces scrutiny regarding its privacy policies, with its Chinese affiliations raising national security concerns in the United States.

In related developments, DeepSeek’s applications became unavailable in Italy after the country’s data protection regulator, the Garante, sought information regarding the startup’s data handling practices and its sources of training data. The withdrawal of apps from the Italian market may or may not have been a direct response to these inquiries, as the Irish Data Protection Commission (DPC) has also made similar information requests.

deepseeks-database-was-wide-open-did-hackers-get-in
Image: Wiz Research

OpenAI and Microsoft are investigating whether DeepSeek used OpenAI’s application programming interface (API) without authorization to train its models through a process known as distillation. An OpenAI spokesperson stated, “We know that groups in [China] are actively working to use methods, including what’s known as distillation, to try to replicate advanced US AI models.”

Tags: deepseekFeatured

Related Posts

Speechify adds voice typing and assistant to Chrome

Speechify adds voice typing and assistant to Chrome

November 26, 2025
Copilot exits WhatsApp on January 15 citing policy shift

Copilot exits WhatsApp on January 15 citing policy shift

November 26, 2025
Rockstar co-founder critiques EA and Microsoft’s AI expectations

Rockstar co-founder critiques EA and Microsoft’s AI expectations

November 26, 2025
Gemini’s upcoming Projects feature mirrors ChatGPT workspaces

Gemini’s upcoming Projects feature mirrors ChatGPT workspaces

November 26, 2025
OpenAI moves ChatGPT Voice into main chat thread

OpenAI moves ChatGPT Voice into main chat thread

November 26, 2025
Perplexity launches Instant Buy AI shopping assistant with PayPal

Perplexity launches Instant Buy AI shopping assistant with PayPal

November 26, 2025

LATEST NEWS

Speechify adds voice typing and assistant to Chrome

Copilot exits WhatsApp on January 15 citing policy shift

Rockstar co-founder critiques EA and Microsoft’s AI expectations

Gemini’s upcoming Projects feature mirrors ChatGPT workspaces

OpenAI moves ChatGPT Voice into main chat thread

Perplexity launches Instant Buy AI shopping assistant with PayPal

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy.