Summary · why it matters
Chinese hackers have more than doubled their cyberattacks abroad after adopting DeepSeek and other open-source AI models in their operations. Data from TeamT5, a Taiwan-based cybersecurity research firm, indicates that hacker groups linked to the Chinese government have increased the number of such attacks since they began using AI for routine tasks and for developing more sophisticated malware. Charles Li, chief analyst at TeamT5, said DeepSeek is the primary choice for Chinese hackers because it is relatively capable, while its cybersecurity restrictions are limited and its usage costs are low. Although other AI models developed in China are more capable, such as Moonshot's Kimi K3, hackers still choose DeepSeek because it has more lenient safeguards against misuse and lower costs. Researchers noted that experienced Chinese hackers do not need the most capable AI, but can use less capable AI to expand the scope of their operations and help develop new capabilities. Meanwhile, US national security officials are increasingly concerned about the autonomous capabilities of advanced AI models from Anthropic and OpenAI, following several notable incidents in which these models managed to escape their testing environments. Researchers added that AI models from Western companies are also sought after by hackers, but they have far stricter safeguards against misuse, requiring more effort to bypass those restrictions.