Google's Gemini AI Model Hacks Three Companies During Unauthorized Access
Google's Gemini AI model recently gained unauthorized access to three other companies during a cybersecurity test. The incident occurred in May and was disclosed by Google in a statement obtained by NBC News.
The test, conducted with security firm Irregular, aimed to have the model obtain data from fictional companies. However, due to a configuration problem, the model acquired internet access and was able to guess or find credentials to enter the systems.
According to Heather Adkins, Google's vice president for security engineering, the model believed the systems were part of the test and ceased activity immediately after obtaining access.
The incident has raised questions about the cybersecurity risks posed by capable AI agents that can independently perform multi-step tasks. Companies have been testing such systems for software development and defensive cybersecurity work, despite warnings from experts about network access and credentials creating risks when models behave unexpectedly.