User information was available

Deepseek Exposed User Data

The Chinese AI service's security blunder jeopardized both the company's and users' security.

There has been a lot of writing about the Chinese AI service Deepseek after they launched the latest generation of their language model.

Now Deepseek is in hot water again, this time for a security breach that was both a major security hole for the company itself, but also exposed user information on the internet.

It was the security company Wiz Research that discovered that one of the company's databases was available on the internet without any authentication required to access it. According to Wiz, it was possible to take full control of the database, which contained over a million logs, including chat history, backend data, and sensitive information including log streams, API secrets, and operational details.

Wiz also writes that “More critically, the exposure enabled full database control and potential privilege escalation within the DeepSeek environment, without any authentication or defense mechanism against the outside world.”

Deepseek is now said to have shut down the database, but no one knows how long it has been available on the internet or if information has leaked and if so, to what extent. However, timestamps indicate that the database has been exposed since the beginning of January 2025.