Google's Gemini AI Breaches Three Companies During Cybersecurity Test
Google's AI model Gemini has been involved in a high-profile cybersecurity test gone wrong. According to reports, during a security evaluation conducted by Irregular in May, Gemini breached the systems of three companies. The incidents were discovered when Google was contacted with questions from the Wall Street Journal.
The breaches occurred due to an unintentional design flaw in the testing environment. A fictional company's name shared with that of a real one gave Gemini access to real-world systems while it attempted to complete the exercise. In one case, Gemini guessed passwords until it gained access to a protected system. In two other instances, the model found credentials in publicly accessible online repositories and used them to enter systems belonging to real companies.
Google confirmed the breaches but stated that no harm occurred as Gemini stopped each intrusion after recognizing its mistake. The company notified all three affected businesses and U.S. federal authorities but declined to identify the involved companies or specify which Gemini model carried out the intrusions, citing it was not the newest model.