Open Doors for Hackers: DeepSeek Left Confidential Data Exposed Online

watch 1m, 4s
views 2

15:49, 30.01.2025

Researchers from Wiz Research discovered an open ClickHouse database containing over a million records of confidential user information from the Chinese AI assistant DeepSeek. The publicly accessible data included unencrypted chat logs, secret keys, logs, backend, and server information.

"We conducted a reconnaissance of DeepSeek's public infrastructure and came across a database that required no authentication. This meant that anyone could access logs containing real chat messages, internal secrets, and system data," Wiz Research specialists reported.

Upon discovering the vulnerability, the Wiz team immediately contacted DeepSeek, and the company promptly restricted access, removing the database from the internet.

Privacy Policy Under Scrutiny

It was revealed that the ClickHouse database was accessible on the servers oauth2callback.deepseek.com:9000 and dev.deepseek.com:9000. The incident raises serious concerns about the data protection measures claimed by DeepSeek. According to the company’s privacy policy, all user data is stored on secure servers located in China. However, experts discovered that personal user information—including IP addresses, logs, device data, cookies, crash reports, keystroke patterns, and rhythms—remains on DeepSeek’s servers even after an account is deleted.

Wiz Research, a cybersecurity company operating since 2020, continues to monitor cloud services for vulnerabilities. Meanwhile, the DeepSeek situation once again raises concerns about the security of users' personal data in AI services.

Share

Was this article helpful to you?

VPS popular offers

-18.4%

CPU
CPU
4 Xeon Cores
RAM
RAM
2 GB
Space
Space
75 GB SSD
Bandwidth
Bandwidth
2 TB
wKVM-SSD 2048 Metered Windows

24 /mo

/mo

Billed annually

-15%

CPU
CPU
6 Xeon Cores
RAM
RAM
8 GB
Space
Space
100 GB SSD
Bandwidth
Bandwidth
80 Mbps
DDoS Protected SSD-wKVM 8192 Windows

101 /mo

/mo

Billed annually

-20.5%

CPU
CPU
6 Xeon Cores
RAM
RAM
16 GB
Space
Space
150 GB SSD
Bandwidth
Bandwidth
10 TB
KVM-SSD 16384 Metered Linux

95 /mo

/mo

Billed annually

-10%

CPU
CPU
2 Epyc Cores
RAM
RAM
1 GB
Space
Space
10 GB NVMe
Bandwidth
Bandwidth
Unlimited
KVM-NVMe 1024 Linux

7.2 /mo

/mo

Billed annually

CPU
CPU
6 Epyc Cores
RAM
RAM
8 GB
Space
Space
100 GB NVMe
Bandwidth
Bandwidth
Unlimited
Keitaro KVM 8192
OS
CentOS
Software
Software
Keitaro
/mo

Billed monthly

-10%

CPU
CPU
6 Xeon Cores
RAM
RAM
16 GB
Space
Space
400 GB HDD
Bandwidth
Bandwidth
Unlimited
KVM-HDD 16384 Linux

50 /mo

/mo

Billed annually

-4.7%

CPU
CPU
3 Xeon Cores
RAM
RAM
1 GB
Space
Space
40 GB HDD
Bandwidth
Bandwidth
300 Gb
wKVM-HDD HK 1024 Windows

10.33 /mo

/mo

Billed annually

-9.2%

CPU
CPU
4 Xeon Cores
RAM
RAM
4 GB
Space
Space
100 GB SSD
Bandwidth
Bandwidth
Unlimited
10Ge-wKVM-SSD 4096 Windows

72 /mo

/mo

Billed annually

-20.2%

CPU
CPU
1 Xeon Core
RAM
RAM
1 GB
Space
Space
50 GB SSD
Bandwidth
Bandwidth
300 GB
wKVM-SSD 1024 HK Windows

19 /mo

/mo

Billed annually

-10%

CPU
CPU
3 Xeon Cores
RAM
RAM
1 GB
Space
Space
40 GB HDD
Bandwidth
Bandwidth
Unlimited
KVM-HDD 1024 Linux

6.1 /mo

/mo

Billed annually

Other articles on this topic

cookie

Accept cookies & privacy policy?

We use cookies to ensure that we give you the best experience on our website. If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the HostZealot website.