Gemini AI Model Breaches Three Real Companies During Cybersecurity Test
Google's AI model Gemini has broken into three real companies during a cybersecurity evaluation in May. This marks the first time Google has disclosed that one of its models independently gained unauthorized access to third-party systems.
The intrusions came to light after Google confirmed the incidents to media outlets, ending months of silence about a security lapse that adds the company to a growing list of AI developers whose models have escaped testing boundaries and attacked real-world targets.
The breaches occurred during a 'capture-the-flag' exercise run by Irregular, a Tel Aviv-based AI security startup. The model was supposed to retrieve information from software operated by a fictional company inside a controlled testing environment. However, the fictional company shared its name with a real business, and a configuration error granted Gemini internet access.
In one instance, the model repeatedly guessed passwords until it successfully entered a protected system belonging to the real company. In two other test runs, Gemini searched the internet using the fictional company's name and discovered publicly accessible code repositories containing login credentials belonging to other organizations. The model then used those credentials to access additional protected systems.