Axios Codebook

January 28, 2025
Happy Tuesday! Welcome back to Codebook.
- 📬 Have thoughts, feedback or scoops to share? [email protected].
Today's newsletter is 1,409 words, a 5.5-minute read.
1 big thing: DeepSeek sparks concern about U.S. data
Silicon Valley's overnight obsession with DeepSeek has renewed questions about whether it's safe for U.S. companies to even interact with China-linked technology.
Why it matters: Security concerns alone are enough for the biggest U.S. companies to pump the brakes on using DeepSeek's models right now.
- Prompt Security CEO Itamar Golan told Axios that his U.S. customers, many of which are Fortune 500 companies, have been writing in recent days to find out how to keep their proprietary data safe from DeepSeek.
- But corporate anxieties won't stop employees from downloading the app on their own to explore its usefulness — just look at how corporate ChatGPT bans have gone.
Driving the news: DeepSeek overtook OpenAI's ChatGPT as the most downloaded free app in Apple's App Store on Sunday.
- Interest in DeepSeek skyrocketed over the last week after the company released its open-source reasoning model, R1, which rivals Open AI's o1.
The big picture: The U.S. often doesn't take too kindly to companies from adversarial nations gaining popularity on its home field — but DeepSeek's free, open-source options and advanced capabilities could make it too appealing for U.S. companies to completely ignore.
What they're saying: "It's another tool owned by a Chinese entity that will get plenty of the U.S. data," Golan told Axios.
- "People talk with AI about everything, what they like, what they do, what they plan — all will be incorporated in the back end of this model, which is huge."
The intrigue: DeepSeek's open-source approach makes the security concerns around it a bit different from those surrounding TikTok, Huawei or even Russian cybersecurity company Kaspersky, Golan said.
- Typically, the U.S. worries about the potential for a backdoor in these companies' products that would let adversaries collect sensitive data about Americans. China-linked companies also face a litany of laws that could force them to hand over key information to Beijing.
- But anyone can inspect R1's model weights, along with the training code from DeepSeek's V3 model, which R1 is trained on and came out last month.
- Large companies could also use this open-source information to build their own DeepSeek-based apps that are walled off from DeepSeek's servers, Levi Gundert, chief security officer at cyber firm Recorded Future, told Axios.
Zoom in: DeepSeek's links to China also raise a few other unique cybersecurity challenges, experts say.
- Unless they're using a walled version of the product, inquiries sent to DeepSeek are processed on the company's servers in China, according to its privacy policy.
- That would subject the data collected to local Chinese data privacy laws — one of the main concerns for Washington's China hawks.
DeepSeek could face more threats from malicious actors looking to either taint its model data or render its services unusable because its code is so public, Mike McNerney, senior vice president of security at cyber risk company Resilience, told Axios.
- DeepSeek trained its new reasoning model using so-called reinforced learning, where it learns through interacting with its environment.
- "If you deny the access to the environment through a denial-of-service attack, it could actually hurt [DeepSeek's] ability to do the analysis they need to do," McNerney said.
Open source is a double-edged sword — the benefits the good guys experience are also shared with cybercriminals, Gundert said.
- Cybercriminals have built their own malicious GPT models that help them carry out online fraud and write malware, but they didn't have free access to the most advanced generative AI capabilities until DeepSeek, he added.
Yes, but: China is already capable of lurking inside U.S. companies, even without a clear backdoor.
- They've hacked the Treasury Department and several major U.S. telcos just in the last year. Officials have also warned that they're lurking in water systems, ports and other critical infrastructure.
- U.S. AI companies have also been on watch for employees who could leak information to Chinese companies.
What we're watching: Whether DeepSeek gets the TikTok or Huawei treatment depends on how many companies actually choose to ditch U.S. AI companies.
- President Trump said yesterday that DeepSeek is a "positive" and that the company's advancements are a "wake-up call for our industries that we need to be laser-focused on competing to win."
2. Major data breaches exposed millions last year


The number of notices sent to people whose data was exposed or stolen in a data breach, leak or exposure quadrupled in 2024, according to data from the Identity Theft Resource Center released today.
Why it matters: Most of these exposures came from incidents at a small number of companies that started from basic cybersecurity issues, such as not turning on multifactor authentication or misconfiguring a third-party vendor's tool.
By the numbers: More than 1.7 billion notices were sent to people in 2024 that their data had been exposed in an incident, according to the report.
- Yet the total number of data compromises remained about flat year over year, with the center tracking 3,158 incidents last year.
- "It's impossible to know how many individuals are actually represented in that billion-plus notice count — but back-of-the-envelope math tells us that's an average of six alerts for every adult in the country," James E. Lee, the center's president, writes in the report.
Zoom in: Breaches at Ticketmaster, Advance Auto Parts and UnitedHealth's Change Healthcare impacted the most people, according to the report.
- 560 million people had their data stolen from the Ticketmaster breach alone, which was part of a run of incidents where hackers exploited Snowflake customers who didn't have multifactor authentication turned on.
- A ransomware attack on Change Healthcare, which affected 190 million people, started after hackers found one server that also didn't have multifactor authentication.
The bottom line: Hackers still don't have to do much to make off with a plethora of sensitive U.S. data.
3. Democrats fired from privacy oversight board
The White House fired the three Democratic members of a top independent intelligence review board, according to a statement from the agency yesterday.
Why it matters: The firings leave the board with just one Republican member and without a quorum as it prepares to advise Congress on an upcoming debate over whether to keep a controversial surveillance program intact.
Catch up quick: The administration sent a letter to the three Democratic members of the Privacy and Civil Liberties Oversight Board (PCLOB) last week, telling them to resign by last Thursday or face termination.
- One of the fired board member's term wasn't supposed to end for several more years.
What they're saying: "The White House terminated Chair Sharon Bradford Franklin, and Members Ed Felten and Travis LeBlanc from their positions as of 5 p.m. last Thursday," PCLOB spokesman Alan Silverleib said in a statement.
- "The agency, however, has significant ability to continue functioning with its full staff and remaining Member Beth Williams to continue the Board's important mission, including its advice and oversight functions, and its current projects," per the statement.
- "The Board looks forward to moving ahead on additional projects formally following the nomination, confirmation, and appointment of new Members."
The other side: Kia Hamadanchy, senior policy counsel at the American Civil Liberties Union, said the move "not only contradicts President Trump's supposed commitment to addressing surveillance abuses, but is a direct attack on accountability and independent oversight."
What we're watching: Nominating new members to the PCLOB — each of whom would require Senate confirmation — is typically low on any new administration's list.
4. Catch up quick
@ D.C.
🫡 Kristi Noem was officially sworn in as homeland security secretary over the weekend. (Fox News)
💰 Immigration and Customs Enforcement and the Citizenship and Immigration Services have spent $7.8 billion since 2020 on technologies to investigate immigration cases, including ankle monitors to track asylum seekers and databases filled with sensitive data like fingerprints. (New York Times)
🛑 The State Department's broad freeze on foreign aid also applies to projects at its cyber diplomacy bureau. (The Record)
@ Industry
👨🏻⚖️ MGM Resorts agreed to pay $45 million to resolve a consolidated class-action lawsuit over data breaches in 2019 and 2023. (Wall Street Journal)
✒️ Perplexity AI revised its TikTok merger proposal, which would allow the U.S. government to take a 50% stake of the new company once it started trading on public markets. (CNBC)
@ Hackers and hacks
👀 DeepSeek limited new user registration as it responded to "large-scale malicious attacks" on its servers. (Axios)
⚠️ A Texas county issued a disaster declaration as it responds to a cyberattack on its internal systems. (The Bay City Tribune)
5. 1 fun thing
🫠 It's not just you: AI-generated newsletters posing as actual local outlets keep landing in everyone's inboxes, it seems.
☀️ See y'all Friday!
Thanks to Megan Morrone for editing and Khalid Adad for copy editing this newsletter.
If you like Axios Codebook, spread the word.


/2025/01/28/1738024306862.gif?w=3840)