• en
ON NOW

Gemini Hacked Three Companies In First Known Breakout By Google’s AI

Google’s Gemini model accessed protected systems at three companies after finding or guessing credentials during a cybersecurity test.

Google’s Gemini artificial intelligence model accessed and hacked three companies during a cybersecurity test, marking the first known case of the company’s AI autonomously carrying out such activity.

The incidents occurred in May during a cybersecurity evaluation conducted by Irregular, an independent company that assesses AI systems.

Google Vice President of Security Engineering Heather Adkins said Gemini found publicly available information online and used guessed credentials to access three websites it believed were within the scope of the test.

“We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes,” Adkins said.

“These events highlight the importance of training powerful AI models to act responsibly,” she added.

According to The Wall Street Journal, which first reported the incidents on Friday, Gemini guessed passwords until it gained access to a protected system in one case.

In the other two cases, the model found credentials in a public repository and used them to access protected systems.

Adkins said Gemini stopped its hacking activity in all three cases.

An Irregular spokesperson said the incident involved the same issue that affected other AI companies and that all relevant companies were notified in late July.

“All known issues on our end were remedied and resolved weeks ago,” the spokesperson said.

Similar incidents linked to Irregular have also been disclosed by Meta, Anthropic and OpenAI.

Meta said in August that its incident did not involve a sandbox escape or a sophisticated cyberattack. Irregular said it was working on best practices for conducting AI cybersecurity evaluations securely.

The incidents have raised concerns about safeguards as AI agents become increasingly capable of operating autonomously and accessing the internet and computer systems.

Google’s disclosure highlights the potential for AI systems being tested for defensive cybersecurity capabilities to take actions beyond their intended boundaries when given access to real-world systems and information.

Faridah Abdulkadiri

Follow us on:

ON NOW