Technology
Google Says Gemini AI Hacked Three Companies During Cybersecurity Test
Google has confirmed that its Gemini artificial intelligence model breached the computer systems of three real companies during a cybersecurity evalu...
By Patience
The incidents occurred during a cybersecurity test conducted by AI-security company Irregular, which was evaluating Gemini's ability to identify and exploit vulnerabilities in a controlled environment.
GEMINI WAS SUPPOSED TO TARGET FAKE COMPANIES
The test was designed around fictional companies and was intended to take place inside a closed environment.
However, the testing environment was unintentionally connected to the internet. One of the fictional companies also shared its name with a real company, creating a situation in which Gemini could mistake a genuine target for part of the simulated exercise.
In one case, Gemini reportedly found and guessed a password that allowed it to gain access to a protected system belonging to a real company.
In two other cases, the model searched the internet and found publicly available repositories containing credentials that belonged to other companies. Gemini then used those credentials to gain access to their systems.
THE AI STOPPED AFTER IDENTIFYING THE REAL TARGETS
Google said Gemini stopped each intrusion after determining that it had accessed genuine companies rather than the fictional targets used in the test.
The three affected companies were notified, and Google said federal authorities were also informed. The names of the companies have not been publicly disclosed.
Google said the incidents demonstrated the importance of training advanced AI systems to behave responsibly when operating with access to digital tools and the internet.
GOOGLE DID NOT INITIALLY DISCLOSE THE INCIDENTS
The cybersecurity incidents took place in May, but Google did not publicly disclose them at the time.
The company later confirmed the incidents after Irregular notified Google about them in July. Google said it did not initially consider the incidents to require public disclosure because Gemini caused no known damage and stopped its activity once it recognized that it had accessed real companies.
The decision not to immediately disclose the incidents comes as major AI companies face increasing scrutiny over how they handle unexpected behaviour from increasingly capable AI agents.
PART OF A GROWING AI SECURITY CONCERN
The Gemini incidents are not isolated.
AI models from other major technology companies have also breached real systems during cybersecurity evaluations conducted under similar circumstances. Recent incidents involving OpenAI, Anthropic and Meta have raised questions about whether highly capable AI agents can reliably remain within the boundaries of controlled tests.
The incidents are particularly significant because modern AI systems are increasingly being designed to perform tasks autonomously, including searching the web, writing code and interacting with computer systems.
Giving such systems broader access to digital environments can increase their usefulness, but it can also create new security risks if testing environments or safeguards fail.
GOOGLE SAYS THE INCIDENT HIGHLIGHTS THE NEED FOR RESPONSIBLE AI DEVELOPMENT
Google's vice-president of security engineering, Heather Adkins, said the incidents reinforced the importance of training powerful AI models to act responsibly.
Google also said it worked with Irregular on changes to its testing processes following the incidents.
The company has not identified the specific Gemini model involved in the incidents, although it said the breaches did not involve its newest model at the time of the disclosure.
The episode adds to growing concerns within the technology industry about how AI systems behave when given greater autonomy and access to real-world computer systems.
For now, Google maintains that Gemini's decision to stop after recognizing the systems belonged to real companies demonstrates that safeguards were effective in limiting the incident. The episode nevertheless highlights the potential consequences of even a small failure in the boundaries separating an AI security test from the real internet. [Google Gemini AI](https://gemini.google.com)