Skip to content
Tech News
← Back to articles

Gemini hacked multiple companies in cybersecurity test gone awry

read original more articles
Why This Matters

This incident highlights how increasingly autonomous AI models can cause real-world security breaches even without malicious intent, simply due to misconfigured testing environments. It underscores the growing risks companies face as they deploy powerful AI agents capable of independently searching for credentials and infiltrating systems, raising urgent questions about oversight and safety protocols in AI development.

Key Takeaways

Adamya Sharma / Android Authority

Add Android Authority on Google: Preferred Source Google Discover

TL;DR Google has confirmed that Gemini gained unauthorized access to three separate companies’ data earlier this summer.

The breaches were the result of a third-party cybersecurity test that was apparently improperly configured.

Gemini reportedly didn’t retrieve any information from the systems it breached.

On the heels of provocative disclosures from competitors OpenAI and Anthropic this summer, Google’s now the latest tech giant to confirm that its AI has hacked other companies.

As reported by Ars Technica, Google has confirmed details in a Wall Street Journal report from last week that spelled out how Gemini models being tested by third-party cybersecurity firm Irregular erroneously made their way onto the open web and hacked into three companies’ servers in May.

Per the reporting, Irregular set out to conduct a capture-the-flag test in which Gemini models were instructed to retrieve specific information from a fake company. The tests were meant to be in a closed environment, isolated to Irregular’s own severs. Irregular somehow misconfigured the testing, however, allowing the models to access the internet. Further complicating things, Irregular’s nonexistent tester company was also assigned a name that’s used by a real company.

All this led Gemini to attempt to retrieve information from the actual, real-life company. In trying to do that, the AI combed public software repositories to find login credentials for two of the companies whose systems it ended up accessing. In the case of the third, it brute-forced its way in by guessing passwords until it stumbled onto the right one.

Google hadn’t previously publicly disclosed the incident because, as the company’s vice president of security engineering Heather Adkins put it in a statement, “the model acted appropriately”: In all three cases, Gemini reportedly never actually retrieved any information from the companies it breached, apparently having determined that it had accessed the wrong systems.

... continue reading