A single vendor’s incident data, not a government tally or an industry consensus, sits behind the week’s most alarming cybersecurity claim out of Asia. Taiwanese security firm TeamT5 told Bloomberg that Chinese state-backed hacking groups it tracks have roughly doubled their attack volume since folding AI models into routine reconnaissance and malware work.

The company’s chief analyst, Charles Li, said hackers gravitate toward DeepSeek “because it’s relatively powerful with very low cyber guardrails.” That framing matters. TeamT5 is describing what it observed inside its own telemetry, not a measurement any government agency or independent researcher has verified.

TeamT5’s named findings are specific and worth stating precisely, because vague summaries of threat-actor tooling tend to calcify into industry lore that outlives the evidence behind it. The firm attributes exploit-code generation to a cluster it calls Grimfengxi, which it says used DeepSeek directly. A separate group, Huapi, is said to have leaned on a Chinese-made model that TeamT5 believes, but stops short of confirming, is also DeepSeek. A third cluster, Teleboyi, reportedly turned the same platform toward reconnaissance: pulling IP addresses and charting domain infrastructure. TeamT5 additionally ties a group it names Slime22 to Anthropic’s coding tool, Claude Code, which the firm says was used to move laterally inside a Taiwanese company’s network once the attackers were already in.

A fourth model enters the account through a different investigator entirely. CyCraft, a separate Taiwanese security firm, said it found evidence that hackers built a decryption module for a Signal database using ChatGPT. That finding did not come from TeamT5’s telemetry and should not be folded into the doubling figure Li described; keep the two firms, and the two data sets, apart.

The report also draws on a UK AI Safety Institute study, which found that open-weight models’ offensive cyber capabilities have climbed sharply over a short span. Even so, the institute’s researchers concluded that fully autonomous attack execution by open models still trails Western frontier systems, Claude Mythos among them, by several months. Individual tasks like exploit drafting are getting faster. Running a full intrusion end to end without a human operator is not.

What TeamT5’s account actually demonstrates is narrower than the doubling headline implies, and arguably more useful to defenders. The variable worth tracking is not which specific chatbot a given group happened to open on a given day. It is that a low-guardrail open-weight model has become a default utility sitting next to more conventional intrusion tools, the way a scripting language or a network scanner would. DeepSeek’s appeal here is not novelty; it is availability, a capable model carrying few of the refusal behaviors that slow exploit generation down on more heavily restricted systems.

That distinction should change how security teams model this threat going forward. Rather than chasing which lab’s model shows up in the next attribution report, defenders should assume any well-resourced state-linked group now keeps a rotating bench of open-weight models chosen specifically for weak safety filtering, and should build detection around behavior patterns (automated reconnaissance, exploit-code generation) instead of around a single vendor’s brand. Organizations operating in Taiwan, or anywhere Chinese state-backed groups have a documented history of interest, should treat TeamT5’s telemetry as an early signal worth independent verification, not as a settled industry count.

Reported by Matthias Bastian for The Decoder on August 25, 2026, citing TeamT5’s findings as relayed by Bloomberg, with the ChatGPT finding attributed separately to CyCraft.