Researchers spotted a chunk of code on the website of Chinese artificial intelligence company DeepSeek that could relay user login data to a Chinese telecommunications firm.
Security researchers discovered that the website of the popular artificial intelligence chatbot DeepSeek hosts a stealthy script allegedly designed to send some user data to a Chinese telecom company.
The code's origin is unclear. The script was reportedly included in DeepSeek’s account creation and login mechanism and used to send data to China Mobile, owned by the Chinese government.
A quick look at DeepSeek’s privacy policy reveals the company’s transparency about storing user data on servers situated in China. However, the implications are far more significant than thought, considering that China Mobile is believed to be closely tied to the Chinese military.
In fact, it is this suspected relationship between the two Chinese state entities that drove the US to place limited sanctions on the telecom company. Currently, neither DeepSeek nor China Mobile has commented on the situation.
DeepSeek is just one of the China-owned services that are becoming problematic to US national security officials. TikTok was recently banned in the US due to fears of data harvesting and influence peddling. While President Trump has suspended the ban’s enforcement, officials are still keeping a close eye on it.
The initial discovery of the code was made by Canadian cybersecurity company Feroot Security. The findings were afterward shared with The Associated Press, which consulted an additional team of cybersecurity experts to confirm the presence of China Mobile code.
Although no data transfer to China Mobile was found during login testing attempts in North America, researchers could not rule out the possibility that some user data may seep into the Chinese telecom firm.
In a world with increasingly frequent digital and physical privacy violations, protecting one's online data from prying eyes is morphing into a necessity rather than a luxury.
Specialized software like Bitdefender Digital Identity Protection can help you stay safe against privacy violations by providing an extensive overview of your online data.
It constantly monitors both the public and the Dark Web, instantly notifies you if your data has been compromised by a breach, and lets you patch holes in your digital footprint by offering quick, one-click action items.
tags
Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.
View all postsDecember 24, 2024
December 19, 2024
November 14, 2024