Google did not publicly disclose the breach, claiming that no harm was caused to the target companies.
Google has not revealed which Gemini model was involved in the hack
Photo Credit: Google
Google Gemini AI model reportedly breached protected systems of three other companies in a cybersecurity test. The incidents reportedly occurred in May during an evaluation conducted by cybersecurity firm Irregular. Google reportedly confirmed the hacks last week. The incident is described as the first known breakout by the Gemini AI model. OpenAI and Anthropic also reported AI Security Incidents in recent months.
As reported by The Wall Street Journal, Google's Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities. The incident happened in May during cybersecurity testing by Irregular.
Google reportedly confirmed the hacks on Friday. The incidents occurred during a "capture the flag" exercise hosted on Irregular's infrastructure. Irregular reportedly notified Google about the hacks in late July, but the company did not confirm them publicly until last week.
The AI model reportedly guessed a password in one case to access the protected system and used found credentials in a public repository in two others. "In each case, the model ended the intrusion after determining it had accessed a real company's systems," Google said.
Google says it didn't consider publicly disclosing the hacks because the model caused no harm and immediately stopped once it realised it had breached real targets instead of simulated environments. The company framed the situation similarly to a bug bounty programme.
“This event highlights the importance of training powerful AI models to act responsibly,” Heather Adkins, Google's vice president of security engineering, reportedly said in a statement. “In this case, the model acted appropriately" he added.
Google has not revealed which Gemini model was involved in the hack. The company reportedly confirmed that the model was not its "newest Gemini release".
The Google incident follows reports of AI models from other companies hacking real systems. OpenAI previously disclosed an incident involving its agents and the developer platform Hugging Face. Similarly, Anthropic accessed a real company in the capture-the-flag testing.
Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.