[Eye Opener] Is DeepSeek The Next Threat in Social Engineering?

Stu Sjouwerman | Jan 28, 2025

deepseekAI is advancing at lightning speed, but it’s also raising some big questions, especially when it comes to security. The latest AI making headlines is DeepSeek, a Chinese startup that’s shaking up the game with its distilled cost-efficient, high-performing models. But it’s also raising red flags for cybersecurity pros.

DeepSeek overnight became a top contender, mostly driven by curiosity. It’s being praised for its efficiency, with models like DeepSeek-V3 and DeepSeek-R1 performing at a fraction of the cost and energy usage compared to competitors, being trained on Nvidia's lower-power H800 chips.

But here’s where things get tricky: DeepSeek’s outputs appear to be biased, favoring Chinese Communist Party (CCP) narratives. In some cases, it even outright refuses to address sensitive topics like human rights.

This is a big red flag. Open-source AI tools like DeepSeek have massive potential—not just for productivity but also for social engineering. With its lightweight infrastructure, DeepSeek could be weaponized to spread misinformation or execute phishing attacks at scale. Imagine a world where tailored propaganda or scam emails can be generated in seconds at almost no cost, fooling even the most tech-savvy users. That’s not a futuristic scenario; it’s a risk we face today.

The app’s rapid rise has already unsettled AI investors, triggering a dip in AI-related stocks. For a market that’s added over $14 trillion to the Nasdaq 100 Index since early 2023, that’s saying something. While DeepSeek’s efficiency is impressive—never mind for the moment how they got there—its potential for misuse reminds us why vigilance in the AI era is critical.

The takeaway? DeepSeek shows that AI can be a double-edged sword. It’s a glimpse into what the AI future could look like—faster, cheaper, more accessible—but it’s also a wake-up call. As these tools evolve, so do the tactics of bad actors. Staying ahead means fighting AI with AI.

See KnowBe4 Defend™ in Action

Learn how Defend™ strategically enhances Microsoft 365's native security to catch the threats Secure Email Gateways (SEGs) miss.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.