Skip to content

DeepSeek

Disclosed Jan 29, 20251 year agoUnverified

Unauthenticated ClickHouse database exposed chat history and API secrets

Wiz Research found a publicly accessible, unauthenticated ClickHouse database belonging to DeepSeek containing over a million log lines, including user chat history, API secrets and backend details. DeepSeek secured it after being notified.

What is known

People affectedNot stated in the sources we have
DisclosedJan 29, 2025
DiscoveredJan 2025
AttackExposed data
Data exposedPrompts and chats, Messages, API keys, Other, Internal documents
SectorAI · CN
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalJan 29, 2025
ResearchtotalJan 29, 2025
History of this record
  • 2026-09-25 · data_types: ["prompts","messages","api-keys","other"] to ["prompts","messages","api-keys","other","internal-docs"] · seed source
  • 2026-09-25 · discovered: empty to 2025-01 · seed source
  • 2026-09-25 · summary: Wiz researchers found an unauthenticated DeepSeek back-end database exposing more than a million log lines, including user chat histories, API keys and backend details; it was taken offline after DeepSeek was alerted. to Wiz Research found a publicly accessible, unauthenticated ClickHouse database belonging to DeepSeek containing over a million log lines, including user chat history, API secrets and backend details. DeepSeek secured it after being notified. · seed source
  • 2026-09-25 · title: DeepSeek left database with chat histories and API keys open online to Unauthenticated ClickHouse database exposed chat history and API secrets · seed source
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about DeepSeek

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.