Google AI Model Hacked into Companies During Security Test
Google's AI model, Gemini, has been involved in three incidents of hacking into companies during a security test. The test was run by Irregular, a third-party security testing company that evaluates AI agents.
The hacks occurred when Gemini was instructed to retrieve information from software belonging to a fictional company inside the testing environment. However, due to an accidental enablement of internet access, Gemini accessed real companies instead of the simulated environment.
In two incidents, Gemini guessed passwords and gained access to real companies' services. In another incident, it searched the web for exposed credentials in public repositories and used them to access two different companies. In all cases, once Gemini realized it had accessed a real organization, it stopped the intrusion immediately.
Google's vice president of security engineering, Heather Adkins, stated that 'this event highlights the importance of training powerful AI models to act responsibly.'