A Taiwanese cybersecurity firm called TeamT5 has found something worth paying attention to: Chinese state-backed hacking groups have more than doubled their attack volume since they started using AI for the boring parts of hacking, like scanning for weak spots and writing malicious code.
Their tool of choice is DeepSeek. Not because it is the best AI model available, but because it is cheap and barely resists requests to do harmful things. TeamT5's chief analyst put it plainly: DeepSeek is popular with hackers because it is powerful but has very low safety limits, while Western AI models are harder to trick into misbehaving.
The examples are specific. One hacking group used DeepSeek to write exploit code that breaks into systems. Another used it to attack a Taiwanese company's email system. A third used it to scan the internet and map which company networks might be worth targeting. Separately, a different security firm found hackers using OpenAI's ChatGPT to help unlock encrypted data from a messaging app database.
Here is the part that should worry every business, not just governments: this is not limited to DeepSeek. Anthropic disclosed its own incident in late 2025, where a Chinese state-linked group hijacked its Claude Code tool to run a spying operation against about 30 organizations, including banks, chemical makers, and tech companies. AI handled most of the work, researching targets, writing attack code, and moving through hacked systems, with a human stepping in only at a few critical moments. Anthropic caught it and shut down the accounts. That is the advantage of a company-controlled AI tool: it can be switched off the moment abuse is spotted.
DeepSeek cannot be switched off the same way. It is free to download and run on your own computer, so once it is out in the world, its safety limits can be stripped out permanently and nobody can take it back. A UK government AI safety lab recently found that free, downloadable AI models are closing the gap with the best commercial models on hacking skill faster than expected, moving from roughly six to ten months behind down to four to seven months behind.
There is a real caveat. Independent researchers looking at one detailed case found that an AI system left to hack entirely on its own did not actually manage to break into anything. Every successful breach in that case still came from a person doing the work by hand. Claims of AI running entire hacking operations solo are still ahead of reality in most cases.
What has genuinely changed is speed and cost. Work that once required a skilled team and days of effort can now be done by one person pointing an AI tool at a list of targets. The pool of attackers capable of hitting a mid-sized company, not just a government ministry or a large multinational, has gotten much bigger.
This is already showing up in numbers that matter to ordinary businesses. Insurance analysts expect cyber insurance premiums to rise between 15 and 20 percent in 2026, largely because AI-driven attacks are pushing claim costs higher. Phishing emails written with AI now read fluently, without the typos and awkward phrasing that used to be the easiest way to spot a scam.
The practical response is not complicated. Patch known software holes quickly, since AI-assisted scanning finds exposed systems faster than before. Verify unusual payment or data requests by phone rather than trusting an email on its wording alone. The tools attacking your business got cheaper. The habits that protect it have not changed, they just matter more now.