China's artificial intelligence (AI) startup DeepSeek said on Tuesday that it had been hit with large-scale malicious cyberattacks, while a Chinese cybersecurity specialist noted that the IP addresses associated with the attacks all show their geographic locations in the United States.
An analysis report from Chinese cybersecurity company QAX restored the entire timeline of the cyberattacks. According to the data, the attacks began on Jan 3 and the number of attacks surged on Monday and Tuesday.
The brute-force attacks have become the primary strategy lately, which differ from the distributed denial-of-service (DDoS) attacks previously used by the attackers, according to Wang Hui, a cybersecurity specialist from QAX.
"They are actually two types of attacks. The DDoS attack primarily consumes the server's resources or occupies its bandwidth, making it impossible for users to access the system. The brute-force attack, on the other hand, targets DeepSeek users' password. The attacker steals the user's password, and once they have it, they can access the user's account and perform actions like asking questions or searching. They can also view the user's activities on DeepSeek and potentially access the user's private information. We can monitor the traffic from these brute-force attacks. Each IP address has a geographic location, and the IP addresses associated with the attacks all show geographic locations in the United States," he said.
Wang added that several Chinese leading companies had been attacked for economic gains or political reasons.
"At least based on the incidents we've observed so far, it seems that major Chinese companies which lead their respective fields, such as the one which produces the Black Myth: Wukong and now DeepSeek, had been targeted for economic gains or political reasons," said the specialist.
In January 2025, DeepSeek released its latest model, DeepSeek-R1, which has attracted significant attention for its advanced reasoning capabilities. The model is said to have achieved performance comparable to leading AI systems, such as OpenAI's ChatGPT, but at a fraction of the development cost.
Chinese AI startup hit by large-scale malicious cyberattacks
