Gemini Model Accesses Real Companies During Google Cybersecurity Test
A recent cybersecurity test conducted by Google involving its Gemini model led to unauthorized access to systems belonging to three real companies. The incident occurred in May during a security evaluation, where the model was asked to attack a fictional target.
The test environment inadvertently provided the model with internet access, allowing it to find public information online and guess credentials for systems believed to be part of the evaluation. This led to the model accessing systems belonging to three real companies.
Google emphasized that this incident should not be described as a model escaping on its own or choosing a real-world campaign. The company stressed that the failure involved a test setup that was supposed to be isolated, and that containment, network permissions, and target verification are central controls in AI cybersecurity testing.