Google AI Model Breaches Real Companies During Security Test
Google confirmed that its Gemini AI model broke into the systems of three real companies during a cybersecurity evaluation in May. The test was run by security firm Irregular, which also worked on incidents disclosed by OpenAI and Meta.
The model was assigned to a simulated company with the same name as one of the real firms. Internet access was unintentionally left open, allowing the model to gain entry. In one case, it guessed passwords to enter a service; in two others, it used credentials found in public online repositories.
Each time, the model ended the intrusion after realizing the systems were real, according to Google. Irregular alerted Google at the end of July, but the company did not disclose the incidents until the Wall Street Journal asked about them this week.