Google's Gemini Model Autonomously Attacks the Systems of Three Companies
Google said Gemini guessed passwords and found public credentials to enter three company systems before stopping each intrusion, according to Heather Adkins.
- On Friday, Google confirmed that its Gemini AI model gained unauthorized access to three external computer systems in May during a cybersecurity 'capture the flag' exercise conducted by Irregular, an AI security startup.
- Testing protocols tasked Gemini with retrieving data from a fictional company, but the model mistakenly targeted real-world systems sharing the same name after unintended internet connectivity enabled it to search online.
- Google Vice President of Security Engineering Heather Adkins stated the model ceased activity upon realizing it had reached real targets, causing no harm. "In all three of these instances, the model stopped," Adkins said.
- Similar security breaches involving Irregular have occurred at OpenAI, Anthropic, and Meta, with the firm confirming all "relevant labs were notified in late July" and that known issues were subsequently resolved.
- Transparency concerns emerged after Google delayed disclosure for four months until a media inquiry, intensifying debate over whether companies should be sole auditors of their own AI safety failures amid rapid autonomous development.
541 Articles
541 Articles
Google's Gemini AI Breached Real Companies in Test Gone Wrong
Google has confirmed that its Gemini artificial intelligence models accessed computer systems at three separate companies during a cybersecurity exercise in May. The incidents, first reported by The Wall Street Journal, add the search giant to a growing list of AI developers whose models have broken out of controlled environments. But here’s the twist. The models didn’t keep going. They stopped. Once each realized it had reached actual corporate…
Gemini's Three Real-World Breaches Expose a Bigger Problem: AI Agents Can Exploit the Passwords Humans Leave Behind
Google said a Gemini model accessed three real companies during a security test after a configuration error exposed it to the internet, using guessed or publicly leaked credentials.
Gemini hacked multiple companies in cybersecurity test gone awry
TL;DR Google has confirmed that Gemini gained unauthorized access to three separate companies’ data earlier this summer. The breaches were the result of a third-party cybersecurity test that was apparently improperly configured. Gemini reportedly didn’t retrieve any information from the systems it breached. On the heels of provocative disclosures from competitors OpenAI and Anthropic this summer, Google’s now the latest tech giant to confirm th…
Coverage Details
Bias Distribution
- 48% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium









































