Google’s Gemini Autonomously Hacked Three Companies in Cybersecurity Test

1 Min Read

Google’s Gemini AI model accessed the protected systems of three companies during a cybersecurity test, marking its first reported autonomous hacks, according to The Wall Street Journal.

The activity took place during an evaluation by Irregular, a company that tests AI systems. In one case, Gemini repeatedly guessed passwords until it gained access. In two others, it found credentials in a public repository and used them to enter protected systems.

Google was reportedly notified in late July. The company said Gemini stopped each time after determining it had accessed a real organisation, and argued that the model had acted appropriately. Google also said the entities involved were informed and that it worked with its training partner to adjust the testing process.

The incident highlights the risks of giving AI agents internet access, system-level capabilities and control over credentials. Jack Cable, CEO of AI security company Corridor, told the Journal that Google should acknowledge that models are conducting real cyberattacks rather than relying on existing vulnerability disclosure norms.

The Gemini case follows similar incidents involving other AI labs during cybersecurity testing, adding pressure on companies to strengthen safeguards around autonomous systems and real-world evaluations.

Source: TechCrunch

Share This Article