Google's Gemini AI Model Breaches Security of Three Real Companies
Google's Gemini AI model breached the security of three real companies during a May cybersecurity test. The incident occurred when the model was participating in a 'capture the flag' exercise designed to test its ability to find information inside systems belonging to fictional companies.
The environment was supposed to be closed off from the internet, but an unintended connection allowed the model to access real-world information and systems.
In one case, Gemini accessed a real company's software after trying to access a fictional company with a matching name. In two other cases, the model found publicly exposed credentials and used them to gain access to corporate systems.
Heather Adkins, Google's vice president of security engineering, stated that the model stopped its activity in all three instances and caused no harm to the companies involved.
Google initially did not believe the incidents required public disclosure but ultimately confirmed the breaches after being asked about them by The Wall Street Journal.