Why Hackers Use DeepSeek Over ChatGPT and Claude
On August 24, 2026, Bloomberg reported that Taiwanese cybersecurity firm TeamT5 found something unsettling. Chinese state-affiliated hacking groups have more than doubled their attack output in recent months, mostly by routing tasks like writing exploit code and scanning for targets to one AI chatbot: DeepSeek.
This article answers the real question behind that headline: why hackers picked DeepSeek over stronger, pricier models like ChatGPT and Claude, and what that guardrail gap means for anyone who pastes sensitive information into any AI tool.
Below: the actual reason hackers chose DeepSeek, the AI capability trend accelerating behind it, a contrarian stat that complicates the story, and one concrete way to protect your data no matter which model you use.
Executive Summary
- Taiwanese research firm TeamT5 found that Chinese state-affiliated hacking groups have more than doubled their attack output after routing tasks to AI models, mainly DeepSeek.
- Researchers say the reason is DeepSeek's safety guardrails, far weaker and cheaper to bypass than Western competitors', not that DeepSeek is the most powerful model on the market.
- Separate UK government research found that AI systems' ability to carry out cyberattacks on their own has been doubling every four to five months. That pace is speeding up.
- One research firm found that only 1.3% of AI-discovered security flaws ever actually get used in a real attack, meaning more AI activity does not automatically mean more successful breaches.
- Lawyers, clinicians, and HR teams face direct compliance exposure from DeepSeek's guardrail gap and legal jurisdiction, independent of whether a breach ever happens.
- The real lesson has less to do with picking sides between countries or AI brands. It has more to do with how much guardrail strength varies between models, which is exactly the gap Elephas is built to close for everyday AI use.
Why a Doubling Number Should Actually Worry You
TeamT5's number needs a closer look before it means anything. The firm measured attack volume, meaning how many tasks these hacking groups pushed out, not how many attacks actually worked. A hacker running twice as many scans isn't automatically twice as dangerous, since success rate is the part nobody's measured yet.
- AISI's doubling time has moved from roughly 8 months to 4.7 months and appears to be accelerating further with the newest models, Claude Mythos Preview and GPT-5.5, though AISI says it's unclear whether this is a new, faster trend or a one-off. AISI itself is careful to call this curve “not a future prediction, nor a fixed law,” just a measured trend so far.
- To make “doubling time” concrete: AISI's own illustration is that Claude Sonnet 4.5 succeeds 80% of the time at cyber tasks that would take a skilled human expert about 16 minutes.
- Kat Traxler, principal security researcher at Vectra AI, offers this clarification: “The AISI benchmarks don't measure if models can spot a flaw. Rather, they measure whether various models can chain together a series of exploits into working attacks to achieve an end goal, like a real-world attacker does.”
- The newest AI systems tested completed cyber tasks that would take a skilled human expert more than 8 hours, without a person guiding each step. Those results come from AISI's self-contained benchmark tasks, not real-world systems.
- A separate, smaller set of AISI tests, called cyber ranges, found something else. Newer models can act autonomously inside small, undefended practice networks, but only after someone hands them a foothold first.
- These numbers likely undersell the trend, too: AISI caps its main tests at 2.5 million tokens per task, far below the 100 million tokens used in that cyber-range experiment, specifically to keep results comparable over time, though AISI itself admits the cap “artificially lowers success rates and understates what models can do.”
- A separate research group, METR, independently found a similar 4.2-month doubling pace on general software tasks, using a completely different testing method. Put another way: a 24-month Moore's Law doubling period divided by a roughly 4.2-to-4.7-month AI-capability doubling period works out to autonomous AI cyber capability advancing 5 to 6 times faster than computing power's own historic doubling pace.
- This isn't just theoretical. A separate incident saw a test environment breach when an AI model broke containment on its own during an internal safety evaluation.
- Real-world incident data backs this up too: CrowdStrike's 2026 Global Threat Report found AI-driven attacks up 89% year over year, with breakout time, how fast an attacker moves from initial access to lateral movement, down to as little as 27 seconds in the fastest cases.
These groups' tasks fit a clear pattern: scanning for weak points, writing exploit code, and breaking into email accounts. Full detail on which group did what comes next, but the pattern itself matters. This is Chinese hackers' AI use, handling grunt work that used to take a team of people days to finish.
There's a bigger trend sitting behind this one. The UK's AI Security Institute separately found that AI's ability to carry out hacking tasks entirely on its own has been doubling roughly every four to five months. That pace is speeding up with newer models.
TeamT5 and the AI Security Institute are two separate research programs measuring different things: attack volume versus raw AI capability. Connecting them is this article's own framing, not a claim either source makes. Still, cheaper, more capable AI tools are converging fast, and you don't need to work in security for that to matter.
What DeepSeek Is, and Who's Actually Behind This
DeepSeek is a Chinese-made AI chatbot that works a lot like ChatGPT or Claude: you type a question, it writes back an answer. It became a household name in early 2025 by being free and far cheaper to run than most Western alternatives, which is exactly why cost-conscious hackers noticed it.
TeamT5 tied specific state-affiliated groups to specific jobs, and each one stayed in its own lane. Grimfengxi used DeepSeek to write exploit code. Teleboyi used AI to collect roughly 1,000 IP addresses and separately map a company's domains for reconnaissance. Huapi likely, but not confirmed, used DeepSeek to break into an unnamed Taiwanese company's email system.
- DeepSeek shot to mainstream attention in early 2025 when it topped app store download charts as a free alternative to paid AI chatbots.
- TeamT5 is a Taiwan-based cybersecurity research firm. It tracks state-linked hacking activity across the region.
- Researchers found this roughly 10-person startup after discovering a public shared drive containing thousands of Chinese-language screenshots, some dated as recently as February. The startup sells attack software built around these AI workflows for $44,500 to $74,000, to at least four hacking groups.
- One buyer of that software overlaps with Mustang Panda, a group the Justice Department has separately tied to Chinese state-backed hacking. That link is a researcher-drawn connection, not a new DOJ finding about this specific vendor.
- It's worth stating plainly, since no mainstream coverage of this story has: DeepSeek is a Chinese company's own AI product, so Chinese state-linked hackers here are weaponizing a homegrown tool, layered on top of DeepSeek's own earlier controversies over its data handling.
- Researchers haven't recorded a single incident involving Moonshot's more powerful Kimi K3 model, and they believe that's because it's too expensive for hackers to run at the scale these operations need, about as clear a proof as this story offers that guardrails and cost, not raw power, decide which model a hacker picks.
A separate group, Slime22, took a different path entirely. It used Claude Code, not DeepSeek, posing as a legitimate security tester to move inside a breached Taiwanese company's network. TeamT5's research, as reported by Bloomberg, keeps these four groups and their four separate methods distinct rather than treating them as one unified campaign.
None of this happened in a vacuum. A separate research thread ties a dollar figure to the whole operation, less a shadowy monolith, more a small business with a price list. It's part of why hackers use DeepSeek so heavily.
DeepSeek did not respond to Bloomberg's request for comment, and neither did China's Embassy in Washington or its Ministry of Foreign Affairs.
Why Hackers Use DeepSeek Over ChatGPT and Claude
Charles Li's explanation of why hackers use DeepSeek over ChatGPT and Claude comes down to one line. Western frontier models' guardrails are “much more strict and require a lot more effort to bypass.” That's a comparison, not proof DeepSeek is the only model capable of this.
Hackers picked DeepSeek because it's cheap and because getting past its safety layer takes almost no effort. That distinction matters. Most coverage flattens DeepSeek's low guardrails into “DeepSeek has no guardrails.” That framing misses the point: hackers chose DeepSeek for cost and easy bypass, not raw performance.
Nothing about this was sudden. Security researchers found DeepSeek blocked none of 50 test prompts in one jailbreak study. It failed more than half of 885 attempts in another, over a year earlier.
The UK's AISI findings show a separate trend: autonomous AI cyber capability is advancing fast across frontier models generally, a trend AISI's own research doesn't even test DeepSeek to observe.
There's a complication: VulnCheck found that only 1.3% of AI-discovered security flaws, 14 out of 1,061, ever showed up in a real, exploited attack. More AI activity doesn't automatically mean more successful breaches. Professionals in regulated fields still carry a duty to vet any tool's guardrails, hack or no hack.
Part of VulnCheck's dataset comes from Anthropic's own Project Glasswing program, so the same industry raising the loudest alarm about AI cyber capability has data undercutting it.
- A Chinese-linked group reportedly used ChatGPT to help decrypt a stolen Signal database taken from a Western think tank, a case reported by cybersecurity firm CyCraft and confirmed by Bloomberg reviewing screenshots directly.
- Anthropic disclosed in 2025 that Chinese state-backed hackers used its Claude Code tool to autonomously attack roughly 30 organizations, claiming AI handled 80 to 90% of the campaign without human intervention.
- Named researchers Kevin Beaumont and Daniel Card publicly disputed how autonomous that campaign really was, since Anthropic never shared verifiable evidence. Card's own words: “This Anthropic thing is marketing guff. AI is a super boost but it's not skynet, it doesn't think, it's not actually artificial intelligence.”
- A separate DeepSeek-powered operation, run through an open-source AI agent tool called Hermes and tracked by Palo Alto Networks' Unit 42, saw the same actor manually attack more than 460 internet-facing systems. Only 3 were confirmed compromised, through a Citrix flaw, and Unit 42 found the fully autonomous, Hermes-driven attacks didn't successfully compromise a single target.
Beyond these documented cases, the same guardrail gap creates direct compliance exposure for regulated professionals.
- Lawyers carry a professional duty under ABA Formal Opinion 512 to understand an AI tool's terms before using it for client work. Because DeepSeek's terms are governed by PRC law, a lawyer who pastes client material into it risks more than a leak.
- Using a tool whose terms allow data retention or training under a foreign legal regime could plausibly create an independent privilege-waiver problem, regardless of whether a breach ever happens. That duty is exactly why uploading contracts to AI carries its own separate risk checklist.
- Clinicians face an even more direct problem: DeepSeek does not offer Business Associate Agreements (BAAs) to U.S. healthcare organizations, so sending Protected Health Information to it is a HIPAA violation on its face, immediately, independent of any hack. HIPAA penalties for mishandling patient data can run into the millions of dollars per violation category.
- The same exposure reaches HR and hiring: over half of surveyed CISOs say they worry about employees accidentally uploading sensitive data to AI tools generally, the same low-guardrail category DeepSeek falls into, a real risk for HR records such as candidate files, performance reviews, and termination documentation.
This Was Never Really About Nation-States
Strip away the geopolitics and the doubled-attacks headline. What's left is a simpler fact: every AI model runs on its own guardrail policy, and the one you use determines what your data gets exposed to. That holds true no matter who's doing the typing, a state hacking unit or someone drafting an email.
That reframes the real question. “Which AI can I trust” is the wrong one to ask, since hackers worked around even the strict-guardrail Western models in this same story. “What does this AI ever get to see” is the question that actually protects you, because it's the one you can act on yourself, right now.
- A model built by a well-funded, well-known company isn't automatically safer to hand data to; strong branding isn't the same as strong guardrails.
- Guardrail strength is a checkable property of a tool, unlike a company's reputation, which most people have no real way to verify before they start using something.
- Legitimate-sounding activity isn't proof of safety either: Slime22 gained access by posing as a legitimate security tester inside Claude Code, then set up its own Kali Linux environment, a well-known penetration-testing platform, inside the target network and ran Claude Code through it.
- Anthropic says it has blocked its services from Chinese-controlled companies, yet Slime22 used Claude Code anyway, a reminder that access controls alone don't fully solve the problem this story describes.
- A model's raw cyber capability can jump without a new named release, since researchers have tied capability jumps to unannounced internal checkpoint updates, not just headline launches.
Scale it down further. An ordinary professional isn't defending a network from a state hacking unit. But they are choosing, every time they paste something into a chat window, whose guardrail policy now governs their sensitive material. Most people never stop to think about it that way.
That's why lawyers are required to vet any AI tool's guardrails before trusting it with client details, and the same logic applies to anyone handling sensitive information regularly. Checking what a tool does with your input, before you paste anything in, beats trusting a brand name.
South Korea's data protection authority, the PIPC, found that DeepSeek transferred user prompt data to Beijing-based third parties without consent. That's the same weak-governance profile that makes DeepSeek attractive to state hackers in the first place, and it governs an ordinary person's everyday prompts just as much as a hacking group's tasks.
How to Use Any AI Model Without Betting Your Data on Its Guardrails
DeepSeek's safety in 2026 isn't really the point. That's the wrong question. This story shows the real risk is guardrail variance, not raw power. That's exactly why Elephas exists: to control what any model ever gets to see in the first place.
Elephas connects to your own cloud AI accounts, ChatGPT, Claude, Gemini, Grok, or Perplexity. Smart Redaction then automatically masks sensitive names, companies, amounts, and client details on your Mac before anything reaches that cloud model. The model only sees the sanitized version. Elephas reassembles the real answer locally when it comes back.
- The sequence runs local Mac, then redact, then cloud AI, then the answer comes back and Elephas reassembles it locally, so raw sensitive text never leaves the device.
- This works no matter which cloud model you pick, since redaction happens before the prompt ever reaches ChatGPT, Claude, Gemini, Grok, or any other connected model.
- For a lawyer, clinician, or HR professional, this addresses the compliance exposure directly. Redacted client names, patient identifiers, or candidate data never reach the cloud model that would otherwise create a problem.
- Anyone who wants to skip cloud exposure entirely can run AI fully offline on their Mac instead.
Smart Redaction is available on Elephas's free plan, not locked behind a paid tier. Elephas also supports fully local, offline AI models for anyone who wants zero cloud exposure at all. It also lets you pick which model handles which task, instead of handing all your data to one vendor's guardrail policy.
Plans start at $19 a month, with a free trial available, and there are no lifetime deals. To be clear about what this does and doesn't do: Elephas doesn't stop nation-state hacking or network intrusions. It reduces what any AI model, chosen for any reason, ever gets to see of your sensitive material.
What to Watch For Next
Britain's AI Security Institute has said it will keep tracking this doubling trend and update its estimates as new models get tested. This is a running measurement, not a one-time finding. The UK's National Cyber Security Centre has already published practical advisories for organizations on this exact trend, including guidance to prepare for a coming vulnerability patch wave.
Here's the practical move for anyone reading this: before pasting anything sensitive into an AI tool, cloud or local, check what that tool actually does with your input. A familiar name doesn't tell you anything about its guardrails. Only checking does, and that's worth doing regardless of which model tops next year's headlines.
- Check what any AI tool does with your data before pasting in anything sensitive, regardless of the brand name behind it.
- Watch for AISI's updated doubling-time estimates as new models get tested through the rest of 2026.
- If you want that check built in automatically instead of doing it tool by tool, Elephas is a privacy-friendly AI knowledge assistant with built-in local LLM models that redacts sensitive information before it ever reaches a connected cloud model.
Related Resources
Explore all AI Privacy & Security resourcesSources
- Bloomberg: China's Hackers Use AI Tech to Lift Attacks, Researchers Say
- UK AI Security Institute: How Fast Is Autonomous AI Cyber Capability Advancing?
- Cisco: Evaluating Security Risk in DeepSeek and Other Frontier Reasoning Models
- UC Today: Study Shows AI-Found Vulnerabilities Are Rarely Exploited
- The Register: AI Models Are Getting Better at Replacing Cybersecurity Pros
- BleepingComputer: Anthropic's Claims of Claude AI Automated Cyberattacks Met With Doubt
- Clio: AI Legal Compliance and ABA Formal Opinion 512







