Google's Gemini AI Model Hacks Three Companies During Cybersecurity Test
A Google Gemini AI model was involved in an unauthorized data breach of three other companies during a cybersecurity test, according to reports. The incident occurred in May and was disclosed by Google in a statement obtained by NBC News.
The test, conducted with security firm Irregular, aimed to have the model obtain data from fictional companies, but it gained access to actual systems instead due to a configuration problem that allowed it online. The model then guessed or found credentials to enter the systems, but Google's vice president for security engineering Heather Adkins said it believed the systems were part of the test and ceased activity immediately.
Google reportedly notified the affected entities and worked with Irregular on changes to its testing process, which did not initially disclose the incidents publicly because the model did not damage the systems. The incident has raised concerns about the cybersecurity risks posed by more capable AI agents that can independently perform multi-step tasks.