Gemini AI hacks three companies during cybersecurity test
- Gemini, Google
-
Courtesy of Pixabay
Google’s Gemini artificial intelligence model accessed the systems of three real companies after unexpectedly reaching the internet during a cybersecurity test, raising fresh concerns over safeguards for increasingly autonomous AI agents.
The incidents happened in May while Gemini was undergoing a cybersecurity evaluation conducted by independent AI security testing company Irregular. The model was supposed to operate within a controlled testing environment and retrieve information from software belonging to a fictional company.
However, internet access was unintentionally left available during the exercise, allowing Gemini to reach systems outside the test environment.
According to Google, Gemini found publicly available information online and guessed credentials to access three websites that it believed were part of the cybersecurity exercise.
In one case, the AI repeatedly guessed passwords until it gained access to a protected system. In two other cases, Gemini reportedly discovered credentials stored in a public repository and used them to enter protected systems.
The identities of the three companies were not disclosed. Google said the incidents did not cause harm and that the affected organizations were notified.
Irregular informed Google about the incidents in July. The testing company said the problem was related to the same issue involved in previous cybersecurity evaluation incidents affecting AI models from Meta, Anthropic, and OpenAI.
Irregular said all relevant AI laboratories were notified in late July and that known issues in its testing environment had since been addressed.
The incident adds to growing scrutiny over how autonomous AI agents behave when given access to external systems, particularly as models become increasingly capable of performing complex cybersecurity tasks with limited human intervention.
Researchers have warned that stronger safeguards may be needed to prevent AI systems from operating outside the boundaries of controlled tests as their capabilities continue to advance.
SOURCE: Online Reports
