Cyber Security

DeepSeek iOS App Sending Data Unencrypted to ByteDance Controlled Server

Critical vulnerabilities have been disclosed in the DeepSeek iOS app, raising concerns over privacy and national security risks. 

The app, which has been the top iOS download since January 25, 2025, transmits sensitive user data unencrypted to servers controlled by ByteDance, the Chinese company behind TikTok

Notably, this discovery has prompted swift bans from governments and organizations worldwide.

DeepSeek iOS App Sends Unencrypted Data

The NowSecure report highlights several alarming flaws in the DeepSeek iOS app:

Unencrypted Data Transmission: Sensitive user and device data are sent over insecure channels, exposing them to interception and manipulation.  This flaw is exacerbated by the app’s global disabling of iOS’s App Transport Security (ATS), a built-in protection designed to enforce encrypted communications.

Weak Encryption Practices: The app employs outdated Triple DES (3DES) encryption with hardcoded keys and reused initialization vectors (IVs). These practices violate modern security standards, making encrypted data vulnerable to decryption by attackers.

Insecure Data Storage: Critical information such as usernames, passwords, and encryption keys is stored insecurely on devices, increasing the risk of credential theft.

Extensive Data Collection and Fingerprinting: The app collects detailed user and device data, including device names, operating systems, and network configurations. This data can be aggregated to de-anonymize users and facilitate tracking.

Data Sent to China: User data is transmitted to ByteDance’s Volcengine servers, governed by Chinese laws that may compel disclosure to the government. This raises significant compliance and surveillance concerns for enterprises and governments using the app.

During their analysis, researchers uncovered specific technical flaws:

Unencrypted Network Requests: Requests to endpoints such as http://fp-it.fengkongcloud.com/v3/cloudconf send identifiable user data without encryption, making it susceptible to man-in-the-middle (MITM) attacks.

Hardcoded Encryption Keys: Using tools like Frida and radare2, researchers identified hardcoded keys within the app’s codebase. 

Output of using Frida

Username, Password, and Encryption Keys Stored Insecurely: The device’s cache database contained sensitive information that was recovered. An attacker may recover and use this data under specific circumstances, most notably if they have physical access to an unlocked device.

Sensitive data recovered from the mobile app

Implications for Enterprises and Governments

The vulnerabilities identified in the DeepSeek iOS app pose serious risks:

  • Data Exposure: Sensitive information such as intellectual property, strategic plans, and confidential communications could be intercepted or compromised.
  • Surveillance Risks: Extensive fingerprinting capabilities increase the likelihood of surveillance through data aggregation.
  • Regulatory Non-Compliance: Organizations operating under strict data protection laws face compliance challenges due to the app’s data storage in China.
DeepSeek’s Privacy Policy and Terms of Service

Several countries have already taken action against DeepSeek. South Korea, Australia, Taiwan, and various U.S. government agencies have banned its use on official devices.

The U.S. military has also prohibited its installation to safeguard national security.

Recommended Actions

NowSecure strongly advises organizations to take immediate steps:

  • Prohibit its use in managed and BYOD environments.
  • Consider self-hosted or secure AI platforms like Microsoft-hosted versions of DeepSeek.
  • Regularly assess third-party apps for emerging risks.

Organizations must conduct independent security assessments of all mobile apps deployed within their environments. The DeepSeek case underscores the importance of prioritizing cybersecurity in an increasingly interconnected digital landscape.

PCI DSS 4.0 & Supply Chain Attack Prevention – Free Webinar

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

7 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago