Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. In January 2025, Wiz Research found a DeepSeek-linked database reachable from the public internet without authentication. It contained plaintext chat history, API secrets and operational data. Wiz reported the issue to DeepSeek, which secured the exposure. The available evidence does not establish how many people’s records were present or whether anyone outside the research team accessed or copied them.

What happened in the DeepSeek data exposure?

Wiz Research says it was assessing DeepSeek’s external security posture when it found a publicly accessible ClickHouse database associated with the company. The database could be reached without authentication at two DeepSeek subdomains on ports 8123 and 9000. Wiz reported that access allowed full database control and could potentially enable privilege escalation. Wiz’s January 29, 2025 disclosure describes the findings.

The issue was a server-side database exposure—not evidence that the DeepSeek AI model itself had a security flaw. A later ClickHouse and Wiz technical follow-up characterized the incident as a deployment and configuration failure: the database was internet-accessible without restrictions, lacked TLS encryption, and had a default user with no password. ClickHouse can be configured with authentication, authorization and other safeguards; this incident does not mean every ClickHouse deployment is exposed.

What data did the exposed database contain?

Wiz reported that a table called log_stream contained more than one million entries, with the earliest records dating from January 6, 2025. The entry count is not a count of people, users or affected accounts. The reported contents included:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Plaintext chat history.
  • API secrets.
  • Backend details and internal endpoint references.
  • Directory structures and operational metadata.

Wiz said some queries might, depending on configuration, have enabled access to other server files. It described that as a potential capability, not as something its researchers did or as confirmed attacker activity. Wiz says its researchers limited their actions to enumeration rather than executing intrusive queries.

Was my DeepSeek chat history leaked?

The public disclosure confirms that chat history was present in the exposed logs, but it does not identify whose records were there. The more-than-one-million figure counts log entries, not distinct users. The reviewed sources do not establish a number of affected people, whether an unauthorized third party accessed or copied records before the exposure was secured, or whether any downstream misuse occurred. They also do not establish the exact period during which the database was publicly accessible.

Wiz says it responsibly disclosed the exposure and that DeepSeek promptly secured it. That remediation does not reveal whether records were accessed by anyone else before the fix. The public incident report does not provide a detailed account from DeepSeek of the exposure’s duration or user-level impact.

Was DeepSeek hacked?

“Hacked” can refer to different events. For the database incident, the confirmed finding is that sensitive data was left accessible through a misconfigured, unauthenticated database. The available sources do not confirm that an attacker exploited it or stole records.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A separate event reported two days earlier should not be conflated with the exposure. On January 27, 2025, DeepSeek said a cyberattack disrupted new-user registration; the Associated Press report said registered users could log in normally. That was a service-availability disruption, not evidence about who accessed the database or what happened to its records.

Nor does NIST’s later work establish anything about the database incident. In a September 30, 2025 announcement, updated November 20, NIST’s Center for AI Standards and Innovation described evaluations of DeepSeek R1, R1-0528 and V3.1 alongside four U.S. models across 19 benchmarks, including findings on model performance, agent hijacking and jailbreak susceptibility. This was a separate model-security evaluation, not an investigation into the January database exposure. NIST CAISI’s announcement does not establish the exposure’s cause, access or impact.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What database operators should learn from the incident

The safeguards are infrastructure controls for the teams operating a database; individual DeepSeek users cannot apply them to DeepSeek’s servers. The ClickHouse and Wiz follow-up discusses protections that database operators can use to prevent accidental public exposure:

  • Require authentication and least privilege. Do not leave a default account without a password. Give users and services only the permissions they need, using fine-grained, role-based authorization.
  • Restrict network access. Make database interfaces reachable only from required networks and sources rather than exposing them broadly to the internet.
  • Use TLS. Encrypt data in transit between database clients and servers.
  • Monitor exposure and configuration drift. Continuously check for publicly reachable services and risky configuration changes, and alert responsible teams.
  • Apply additional data protections. The technical follow-up also discusses query limits and database data-protection features as part of a broader defense.

Wiz’s report also says its reconnaissance mapped approximately 30 internet-facing subdomains before researchers identified two hosts with unusual open ports associated with the database. That figure describes the researchers’ mapped attack surface, not 30 confirmed vulnerabilities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.