Skip to main content
Back to overview
High

DeepSeek AI Suffers Data Leak Exposing Over One Million Sensitive Records

Stay up to date with Pomerium news and announcements.

Key points

  • Misconfigured cloud storage instance
  • Over 1 million sensitive records exposed
  • Included chat logs, system details, API secrets

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Malware, Hacking, Error activity

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Jan 29, 2025
Updated
Jul 22, 2026
Confidence
High
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Hacking, Error activity

Watch ransomware, endpoint compromise and business interruption exposure.

  • Source type: supplier or third-party involvement

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

DeepseekData DisclosureExposing Over One Million SensitivePomeriumYouAccordingIdentity Theft Resource CenterWithCompiledJanuary. Source

Quick context

Questions about this signal

What happened in this signal?

Stay up to date with Pomerium news and announcements. You have successfully joined our subscriber list. According to the 2024 Annual Data Breach Report by the Identity Theft Resource Center, there were more than 1.7 million victim notices, “a measure of the scale of events and impacts on individuals,” last year, a number that was triple that of 2023. With 3,158 total compromises recorded in 2024, it’s no surprise that this past January 2025 was also full of data breaches. Compiled on February 3, the following list is composed of data breach headlines that were published (if not occurred) during the month of January. Source articles have been organized by industry (finance, government, healthcare, hospitality, infrastructure, legal, retail, and tech) in reverse chronological order. Security Breaches Reported in January 2025 850,000 people exposed in massive insurance data breach — full names, dates of birth and SSNs | Tom’s Guide As reported by BleepingComputer, Globe Life is now saying that an additional 850,000 people may be affected by the June breach. Back in June of 2024, the insurance company Globe Life suffered a data breach that allegedly accessed policyholder data. The company initiated an investigation that revealed some information back in October of last year which claimed that at least 5,000 people were potentially affected. The October release revealed that a small-scale breach was discovered in a subsidiary company, American Income Life Insurance Company Hackers steal $85 million worth of cryptocurrency from Phemex | Bleeping Computer The Phemex crypto exchange suffered a massive security breach on Thursday where threat actors stole over $85 million worth of cryptocurrency. "On January 23, 2025, at 11:30 UTC, we detected unusual activity in our hot wallet," reads the announcement on Phemex's website. Phemex CEO Variola mentioned on X that the threat actor and the attack were "sophisticated" but omitted any specifics that could provide pointers for attribution. NoOnes Suffers Major Security Breach Resulting In $8 Million Loss | Binance On January 26, the peer-to-peer cryptocurrency trading platform NoOnes disclosed a significant security breach earlier this month, resulting in the loss of approximately $8 million in crypto assets. The incident was confirmed by CEO Ray Youssef after blockchain investigator ZachXBT revealed the hack on his Telegram channel. Youssef, who previously served as CEO of rival peer-to-peer crypto platform Paxful, explained that the breach occurred on January 1 due to an exploitation of their Solana bridge. In response, NoOnes promptly disabled the compromised bridge. PayPal to pay $2 million settlement over 2022 data breach | Bleeping Computer New York State has announced a $2,000,000 settlement with PayPal over charges it failed to comply with the state's cybersecurity regulations, leading to a 2022 data breach. The Department of Financial Services (DFS) action says that threat actors took advantage of security gaps in PayPal's systems to conduct credential stuffing attacks that provided access to sensitive customer information. In 2023, PayPal disclosed that threat actors conducted a large-scale credentials stuffing attack between December 6th and December 8th, 2022, where 35,000 accounts were breached. Conduent Confirms Cyberattack After Government Agencies Report Outages | SecurityWeek The Wisconsin Department of Children and Families revealed that organizations in four states had been impacted by a “global network issue” at Conduent, noting that the vendor had been working on “rebuilding” its server. The Department of Children and Families in Wisconsin said on January 18 that the incident impacted payments. While the little information that is available suggests that Conduent may have been targeted in a ransomware attack, no known ransomware group has taken credit for the attack by the time of writing. Breach exposes FBI data links | Digital Watch Observatory A major data breach involving telecom provider AT&T has compromised sensitive information about FBI agents’ call and text logs. The incident, which occurred last year, exposed phone numbers and contact details, though not the content of communications. FBI officials warn that the breach may risk revealing the identities of confidential informants. AT&T reported in July that hackers had stolen records linked to 109 million customer accounts. Valley residents who receive public assistance warned of HHS data breach | KRGV The Texas Health and Human Services Commission says at least 61,000 food stamp recipients may have had their personal information improperly accessed by state employees. The state says money from accounts may have been stolen. UN aviation agency confirms nearly 12,000 affected by data breach | Tech Monitor Inside the DeepSeek Cyber Attack Timeline and the Data Leak Fallout: Is Your Data Safe? Updated on Jul 25, 2025 | 12 min read | 3.19K+ views

When was this signal reported?

Shadow Tier lists Jan 29, 2025 as the signal date.

Which organization is connected to this signal?

Deepseek is the organization connected to this public signal.

Explore Deepseek
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence