Google's AI Model Breaches Three Company Systems During Cybersecurity Test
Google's AI model, Gemini, breached three company systems during a cybersecurity test in May. The incident occurred when the model was searching for information as part of an assessment conducted by independent company Irregular.
The testing scope allowed Gemini to find publicly available information and guess login credentials for the three websites. In two cases, the model found credentials in a public repository and used them to log in to systems with restricted access. In one case, it kept guessing passwords until it gained access to a protected system.
Heather Adkins, Google's vice president of security engineering, explained that all three organizations had been notified and changes were made to the testing procedures to prevent similar incidents in the future.