Educational & easy-to consume visual guides to understanding attacks & enhancing resilience
In late January 2025, DeepSeek, the new AI model, faced a large-scale cyber attack soon after it started getting worldwide attention. Due to the attack, the AI platform had to temporarily limit new registrations. The incident included a Distributed Denial-of-Service (DDoS) attack, malicious infostealer packages impersonating developer tools being uploaded to the Python Package Index (PyPI), and the exposure of two unsecured databases containing sensitive user and operational information.
These databases held over a million log entries with user chat history, API keys, backend details, and operational metadata, accessible via a web interface without authentication.
The exposure of DeepSeek's databases led to immediate disclosure by Wiz Research, prompting DeepSeek to secure the exposure. However, Italy's data protection authority banned DeepSeek due to privacy concerns, and US lawmakers introduced a bill to ban DeepSeek from federal devices. Texas also investigated DeepSeek for alleged data privacy law violations. These actions were taken in response to the security vulnerabilities and data breaches associated with the cyber attack.
We’ve captured everything that took place in this headline-making cybersecurity incident in our DeepSeek Cyber Attack Timeline and DeepSeek Cyber Attack Summary Image.
Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.
In late January 2025, just as DeepSeek's AI assistant surged in popularity and overtook ChatGPT as the top free app on the Apple App Store, the platform was hit by what it described as large-scale malicious attacks, reported to be a DDoS against its API and web chat, forcing it to temporarily limit new registrations. Separately, security firm Wiz Research found an unsecured, publicly accessible ClickHouse database exposing over a million log entries, and threat actors uploaded malicious infostealer packages to PyPI impersonating DeepSeek developer tools. Together these made it one of the most scrutinised AI security incidents of 2025.
The main events began on 27 January 2025, when DeepSeek confirmed the attack and limited registrations, and Wiz Research disclosed the exposed database the same day. The malicious PyPI packages were uploaded on 29 January 2025. Regulatory action followed through late January and February 2025, including Italy's ban on 30 January, a proposed US federal-device ban on 7 February, and a Texas investigation on 14 February.
The attacker or attackers behind the reported DDoS were not identified and remain unknown. The exposed ClickHouse database was found by Wiz Research through responsible security research rather than by a malicious actor. The malicious PyPI packages were uploaded by an 'aged' account that had been created in June 2023 with no prior activity; no named threat actor was confirmed in reporting.
Wiz Research identified a publicly accessible, completely unauthenticated ClickHouse database belonging to DeepSeek, hosted at oauth2callback.deepseek.com and dev.deepseek.com on ports 8123 and 9000. It held over a million log entries containing user chat history in plaintext, API keys and secret keys, backend details and operational metadata. The exposure reportedly allowed full database control and potential privilege escalation, with no authentication required.
Wiz Research mapped DeepSeek's external attack surface and identified around 30 internet-facing subdomains. Most looked benign, but beyond the standard web ports the team found two unusual open ports (8123 and 9000) that led to the open ClickHouse database. Wiz disclosed the issue responsibly to DeepSeek, which promptly secured the exposure.
The disruption that forced DeepSeek to limit registrations was reported to be a distributed denial-of-service (DDoS) attack against its API and web chat platform. DeepSeek itself described the cause as large-scale malicious attacks on its services. This was separate from the database exposure and the PyPI package campaign, which were distinct issues that emerged at the same time.
Threat actors uploaded two malicious infostealer packages to the Python Package Index (PyPI) named 'deepseeek' and 'deepseekai' (version 0.0.8), impersonating developer tools for the DeepSeek AI platform. Once run on a developer's machine, they stole user and system data and environment variables such as API keys, database credentials and infrastructure access tokens, exfiltrating them to a command-and-control server via the legitimate automation platform Pipedream.
Despite quick detection and removal by PyPI, 222 developers downloaded the two packages, most from the United States (117), followed by China (36), then Russia, Germany, Hong Kong and Canada. Anyone who installed them was advised to immediately rotate their API keys, authentication tokens and passwords, as these may have been compromised.
No ransom was reported in connection with the incident. Downtime was limited to a few hours, during which DeepSeek temporarily restricted new registrations as a precaution while existing users could continue to log in as usual.
Yes, as a related security concern. The security firm KELA reported that its AI red team was able to jailbreak the DeepSeek R1 model across a wide range of scenarios, generating malicious outputs, and assessed it as significantly more vulnerable than comparable models such as ChatGPT. This highlighted model safety and guardrail weaknesses alongside the infrastructure exposures.
Italy's data protection authority, Garante, banned DeepSeek from operating in the country on 30 January 2025 over privacy concerns and ordered it to disclose details of its data practices within 20 days. In the United States, lawmakers introduced the 'No DeepSeek on Government Devices Act' on 7 February 2025, and the Texas Attorney General opened an investigation into alleged data-privacy violations on 14 February 2025, also requesting information from Google and Apple.
The DeepSeek incident shows how fast-scaling platforms can expose data when security does not keep pace with growth. The key lessons are that misconfigured, unauthenticated databases are a critical risk; secrets and chat data should never sit in plaintext logs; developers face supply-chain and typosquatting threats on package registries; and AI model safety and guardrails matter as much as infrastructure security. Cyber Management Alliance helps organisations build these capabilities through training, cyber crisis tabletop exercises and incident response planning.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.