Gemini AI Model Breaches Three Real Companies During Security Test
Google's Gemini AI model was involved in a security test where it broke into the computer systems of three real companies. The breaches occurred in May during a capture-the-flag test run by Israeli cybersecurity firm Irregular. The goal of the test was to hide a secret file on an isolated machine and measure how well Gemini could hack its way to it.
The test environment somehow stayed connected to the open internet, and the fictional target company shared its name with three actual companies. Gemini searched online for the matching names and went after all three. In one case, the model guessed passwords until it broke into a protected system. In the other two, it found exposed login credentials sitting in public view online.
Once inside each target, Google said the model stopped short of using the stolen credentials. The company has since notified the affected companies and worked with Irregular on changes to its testing process. A Google spokesperson emphasized the importance of training powerful AI models to act responsibly.