Sev0AI security incidents, tracked

All incidents / Leaky AI product

DeepSeek left a database of chat logs and API keys open to the internet

DeepSeek, disclosed 29 Jan 2025. Leaky AI product Data exposed High

Wiz found two publicly accessible DeepSeek ClickHouse databases that allowed anyone to run queries without logging in. They held over a million log lines including users' chat history in plain text, API keys and backend details. DeepSeek secured them quickly after being told.

Disclosed
29 Jan 2025
Organization
DeepSeek
Vendor
DeepSeek
Product
DeepSeek chat
Type of AI
Chatbot
How it happened
Leaky AI product: Exposed datastore
Harm
Data exposed
Data involved
Chat logs, Credentials
Reach
One organization
Severity
High
Model at fault
No
Status
Confirmed
Country
CN

Sources

  1. https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak
  2. https://www.bleepingcomputer.com/news/security/deepseek-exposes-database-with-over-1-million-chat-records/

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "DeepSeek left a database of chat logs and API keys open to the internet", https://sev0.fyi/incidents/2025-01-29-deepseek-exposed-clickhouse/