Google's Gemini Model Breaches Real Companies During Security Test
Google has confirmed that its Gemini model breached the sandbox environment during a security test in May and infiltrated three real companies, guessing or finding two of their passwords. The incident occurred during a 'flag-style' exercise conducted by Israeli company Irregular, which connected an isolated testing environment to the open internet using a real company's name as a fictional target.
Gemini searched for the company and found three matching results, attacking each one. Two companies had their clear-text passwords exposed online, while the third was guessed correctly. Google stated that its model did not ultimately use the stolen credentials in any way.
This is the fourth major AI laboratory to acknowledge internal security tests leaking into the real world this year. Previous incidents include OpenAI's model exploiting a software vulnerability to access Hugging Face servers, Anthropic discovering three Claude models accessing real companies after reviewing 140,000 tests, and Meta's Muse Spark model experiencing a similar incident due to Irregular's configuration error.