Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

DeepSeek’s database was wide open—did hackers get in?

DeepSeek has garnered significant attention for its innovative open-source AI models that aim to compete with established systems like OpenAI

byKerem Gülen
January 31, 2025
in News, Cybersecurity
Home News
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail

DeepSeek, the trending Chinese artificial intelligence (AI) startup, recently exposed one of its databases on the internet, potentially allowing unauthorized access to sensitive data. The exposed ClickHouse database provided full control over its operations, according to Wiz security researcher Gal Nagli.

DeepSeek exposes over a million lines

The exposure included over a million lines of log streams featuring chat history, secret keys, backend details, and other critical information, such as API secrets and operational metadata. Following notification attempts from the cloud security firm, DeepSeek has since fixed the security vulnerability.

The database, which was accessible at oauth2callback.deepseek[.]com:9000 and dev.deepseek[.]com:9000, enabled unauthorized users to execute arbitrary SQL queries via the web browser without requiring authentication. It remains unclear if any malicious actors accessed or downloaded the data before the issue was resolved.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

deepseeks-database-was-wide-open-did-hackers-get-in
Image: Wiz Research

Nagli emphasized the risks of rapid AI service adoption without adequate security measures, highlighting that real risks often stem from basic oversights like accidental database exposure. He stated, “Protecting customer data must remain the top priority for security teams, and it is crucial that security teams work closely with AI engineers to safeguard data and prevent exposure.”

deepseeks-database-was-wide-open-did-hackers-get-in
Image: Wiz Research

DeepSeek has garnered significant attention for its innovative open-source AI models that aim to compete with established systems like OpenAI, positioning its reasoning model R1 as an “AI’s Sputnik moment.” Its AI chatbot rapidly climbed to the top of app store rankings across multiple markets, even as the company faced “large-scale malicious attacks,” which led to a temporary pause in new registrations.

deepseeks-database-was-wide-open-did-hackers-get-in
Image: Wiz Research

In a January 29, 2025 update, DeepSeek acknowledged the database issue and indicated that it is implementing a fix. Concurrently, the company faces scrutiny regarding its privacy policies, with its Chinese affiliations raising national security concerns in the United States.

In related developments, DeepSeek’s applications became unavailable in Italy after the country’s data protection regulator, the Garante, sought information regarding the startup’s data handling practices and its sources of training data. The withdrawal of apps from the Italian market may or may not have been a direct response to these inquiries, as the Irish Data Protection Commission (DPC) has also made similar information requests.

deepseeks-database-was-wide-open-did-hackers-get-in
Image: Wiz Research

OpenAI and Microsoft are investigating whether DeepSeek used OpenAI’s application programming interface (API) without authorization to train its models through a process known as distillation. An OpenAI spokesperson stated, “We know that groups in [China] are actively working to use methods, including what’s known as distillation, to try to replicate advanced US AI models.”

Tags: deepseekFeatured

Related Posts

OpenAI is now planning a new screenless AI companion device

OpenAI is now planning a new screenless AI companion device

May 22, 2025
Google’s AI just got ad-ified

Google’s AI just got ad-ified

May 22, 2025
New Spotify hub now helps users track future music drops

New Spotify hub now helps users track future music drops

May 22, 2025
The Llama for Startups initiative could fuel a whole new wave of GenAI apps

The Llama for Startups initiative could fuel a whole new wave of GenAI apps

May 22, 2025
Amazon tests AI voiceovers for its product listings

Amazon tests AI voiceovers for its product listings

May 22, 2025
Is 16GB of VRAM for just 9 AMD’s new gaming sweet spot?

Is 16GB of VRAM for just $349 AMD’s new gaming sweet spot?

May 21, 2025

LATEST NEWS

OpenAI is now planning a new screenless AI companion device

Google’s AI just got ad-ified

New Spotify hub now helps users track future music drops

The Llama for Startups initiative could fuel a whole new wave of GenAI apps

Amazon tests AI voiceovers for its product listings

Is 16GB of VRAM for just $349 AMD’s new gaming sweet spot?

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy.