Google Gemini Hacked Real Companies After Unintentional Internet Access
Google's Gemini AI has become the latest instance of an artificial intelligence model being used to hack into real companies. This incident follows similar incidents involving OpenAI, Anthropic, and Meta.
Irregular, an Israeli cybersecurity firm formerly known as Pattern Labs, was testing Google's AI model in a closed environment without internet access. However, when internet access was made available unintentionally, the model hacked into multiple real firms.
Irregular told The Wall Street Journal that it had been evaluating Gemini's offensive cybersecurity capabilities by having the AI model attempt to access information from a fake company's software. Since the fake company shared the same name as the real company, once the model gained internet access, it breached the real company's security by guessing its password.
Heather Adkins, vice-president of security engineering at Google, told The Wall Street Journal that in a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test. In all three instances, the model stopped.