Technology

Bloomberg Report Ties a Jump in Chinese Cyberattacks to DeepSeek

• From trending topic: Chinese Hackers Double Attacks Using DeepSeek AI Tools

Bloomberg Report Ties a Jump in Chinese Cyberattacks to DeepSeek

Summary

A Bloomberg report circulating widely this week said Chinese state-affiliated hackers have more than doubled their attacks after folding DeepSeek and other open-source AI models into their work. Posts summarizing the piece attributed the finding to Taiwanese researchers and said those operators have made DeepSeek their “AI of choice,” citing low cost and relatively weak cyber guardrails.

That claim, not a newly disclosed intrusion against a named company, is what pushed the story onto X. The social posts are secondhand accounts of a news article, not the underlying study. They do not spell out how attacks were counted, over what period, what share succeeded, or how activity was tied to Chinese state-affiliated groups. Those are the details that separate a sharp operational shift from a rise in noisy, low-cost probing.

DeepSeek, the Hangzhou firm whose models undercut much more expensive Western systems, ships capable open-weight software that can be run privately. That combination—price, local control, and thinner refusal behavior than many closed U.S. products—would appeal to any operator who wants scale without sending prompts through an American lab. Bloomberg’s account, as relayed online, treats that mix as a practical reason the models showed up in Chinese intrusion workflows, not as proof that the company directed the campaigns.

What remains unsettled is the size and meaning of the jump. “More than doubled” is a vivid figure with no public methodology attached in the material driving the trend. It is also unclear whether other governments or vendors have published matching tallies, or whether DeepSeek or Beijing have offered a detailed reply.

Common Perspectives

A hard warning about Chinese state capacity

Officials and analysts in Taiwan, the United States, and allied governments tend to read the report as confirmation of a known pattern: Beijing-linked groups already run large cyber programs, and cheaper models let them do more with the same people. The appeal is straightforward. It fits years of public attributions and argues for tighter controls on Chinese AI, cloud access, and government procurement. The assumption is that the attribution and the doubling are solid enough to drive policy. The trade-off is speed over precision. Acting on a media summary can justify export rules, bans, and military spending that outrun what the research actually measured.

A guardrail problem that is not uniquely Chinese

AI safety researchers and some Western lab staff treat DeepSeek as the visible brand on a generic failure. Any strong, cheap, locally run model with weak abuse filters can draft phishing, sort stolen data, or speed routine intrusion work. This view appeals to people who have watched open weights spread faster than safety evaluations. It keeps the focus on product design rather than nationality. The trade-off is political. The same argument is easily used to restrict open models altogether, which would favor a few closed U.S. vendors and still leave determined actors with other tools.

The number may be doing too much work

Incident responders, academic attribution specialists, and reporters who cover threat-intel marketing often start with the metric. “Attacks” can mean scans, phishing volume, or confirmed breaches. AI makes the first two cheap, so a doubling can appear without a matching rise in damage. Taiwanese researchers have a legitimate reason to track Chinese operations and also an obvious strategic interest in highlighting them; Bloomberg has an interest in a clean headline. This skepticism is useful because cyber claims are hard to audit from the outside. Its weakness is that it can slide into dismissing the whole report before the methods are public.

A convenient target after DeepSeek’s shock

Chinese officials, nationalist commentators, and some observers outside the U.S. alliance see a successful Chinese lab being recast as a hacking brand. In this reading, cost and open weights are ordinary product choices, “state-affiliated” is a flexible label, and the timing fits a broader effort to contain Chinese AI after export controls failed to prevent a competitive model. The view resonates where Western cyber reporting is already seen as selective. The cost is obvious: real abuse of Chinese models, if documented, gets waved away as information warfare.

A Different View

The conversation is stuck on which country’s hackers and which company’s model. A more awkward possibility is that “attacks doubled” is what the offense market looks like once drafting, translation, and code variation cost almost nothing. Volume then stops being a good proxy for power. The neglected comparison is not DeepSeek versus GPT. It is whether successful compromises, time-to-access, and dwell time changed—and whether the same organizations now facing more mail and more probes gave their defenders an equivalent productivity boost. If they did not, the story is less a Chinese leap than a lopsided adoption curve. Naming one already-controversial model makes that imbalance easier to sell and easier to miss.

Conclusion

The next useful facts are methodological, not rhetorical: the time window, the definition of an attack, the attribution standard, and whether any government or vendor has released a matching dataset. Watch also for whether DeepSeek changes its filters or licensing and whether Western agencies describe a rise in completed intrusions or only in attempt volume. Until those pieces appear, the doubling remains a reported finding, not a settled measure of Chinese cyber power.