DeepSeek’s Database With Chat History and Sensitive Information Leaked, Says Cybersecurity Firm

A cybersecurity firm found a publicly accessible ClickHouse database belonging to DeepSeek that shows internal data.

Advertisement
Written by Akash Dutta, Edited by Siddharth Suvarna | Updated: 31 January 2025 19:45 IST
Highlights
  • The leaked data includes over a million lines of log streams
  • It is said to contain chat history, secret keys, and backend details
  • Recently, DeepSeek said that it was hit by a cyberattack

The firm said the DeepSeek data could be accessed without any external authentication

Photo Credit: Reuters

DeepSeek's dataset might have suffered public exposure, claimed a cybersecurity research firm. As per a report, a publicly accessible ClickHouse database belonging to DeepSeek was discovered which allowed full control over its database operations. Additionally, the exposure is also said to contain a large volume of sensitive information including chat history, secret keys, log times, and backend details. It is unclear whether the firm reported the matter to the Chinese AI firm, and if the exposed dataset has been taken down.

DeepSeek's Dataset Might Have Suffered a Breach

In a blog post, cybersecurity firm Wiz Research revealed that it found a completely open and unauthenticated dataset that contained highly sensitive information about the DeepSeek platform. The exposed information is said to pose a potential risk to both the AI firm as well as the end users.

Advertisement

The cybersecurity firm claimed that it intended to assess DeepSeek's external security to identify any potential vulnerabilities, given the rising popularity of the AI platform. The researchers started by mapping any Internet-facing subdomains but did not find anything that could suggest a high-risk exposure.

However, after implementing new techniques, the researchers were able to detect two open ports (8123 and 9000) associated with multiple public hosts. Wiz Research claimed that these ports led them to a publicly exposed ClickHouse database which could be accessed without any authentication.

Advertisement

Notably, ClickHouse is an open-source, columnar database management system developed by Yandex. It is used for fast analytical queries and is often used by ethical hackers to scan the dark web for exposed data.

A log stream table in the dataset is claimed to contain more than one million log entries including timestamps with logs from January 6, references to multiple internal DeepSeek application programming interface (API) endpoints, as well as chat history, API Keys, backend details, and operational metadata in plain-text.

Advertisement

The researchers claimed that with this level of information, a bad actor could potentially exfiltrate passwords, local files, and proprietary information directly from the server. At the time of writing this, there was no update on whether this data exposure can be contained and whether the dataset can be taken offline.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. New OTT Releases of the Week: Drishyam 3, Thukra ke Mera Pyar S2, and More
  2. Here's Why CMF Says It Won't Launch a New Phone This Year
  3. WhatsApp Could Soon Bring These Two Useful Features to Its Android App
  4. Nothing Is Now Teasing the Launch of a Mysterious "b" Product Series
  5. Samsung Galaxy M47 5G India Launch Teased, Will Go on Sale via Amazon
  6. Redmi Turbo 5 With 7,540mAh Battery Goes on Sale in India: Price, Offers
  7. Haier Launches HQLED P7 Pro Series With Google TV, Dolby Atmos
  8. Jio AI Call Agent Explained: What It Is, How It Works, Features and More
  1. Ginny Wedss Sunny 2 Out on OTT: Where to Stream This Romantic Comedy Drama Online
  2. Redmi K90 Ultra Roundup: Launch Date, Expected Price, Specifications
  3. JWST Watches HD 80606 bExoplanet Heat Up by 1,100 Degrees in Hours
  4. Reliance's Jio Platforms Files for Record $4 Billion IPO
  5. Nothing Teases Launch of Mysterious New “b” Product Series in India
  6. WhatsApp Begins Testing Online Indicator, New Feature to Manage Chat Backups on Android
  7. Rockstar Games Shares New Look at Vice City on GTA 6 Website, Removes Release Date Mentions
  8. UAE Reportedly Cracks Down on Social Media Use for Children Under 15, Mandates Age Verification
  9. Malta Seeks to Bring DAOs Under New DeFi Rules Aligned With MiCA
  10. Unpatchable Hardware Vulnerability Leaves Owners of Older iPhone XS, iPhone XR and iPhone 11 Models at Risk
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.