Gemini AI invades systems of three companies during security test conducted in May 2026
Read more
Tecnoblog
tecnoblog.net

Gemini AI invades systems of three companies during security test conducted in May 2026

In May 2026, Gemini, an artificial intelligence developed by Google, managed to access the systems of three real companies during a third-party cybersecurity test. Initially, the AI was conducting a data extraction exercise in a fictional company, but it ended up gaining internet access and infiltrating the networks of authentic organizations.

The occurrence was disclosed by The Wall Street Journal after contact with one of the affected companies. The newspaper pointed out that the confusion arose because the real companies had names identical to those used in the simulation.

The AI model employed brute force techniques to guess the password of an external system and also found exposed credentials in public repositories. This data was subsequently used to invade two more protected networks.

The security flaw resided in the infrastructure of the Israeli startup Irregular, which was responsible for conducting the simulated exercise. Irregular itself admitted to having accidentally left the internet accessible to the model and mentioned having already registered similar incidents in evaluations conducted for OpenAI, Meta, and Anthropic.

Google stated that Gemini immediately ceased the attacks after identifying that it was accessing information from genuine corporate networks, not from the servers designated for the test. The company chose not to classify the event as a misalignment case, a term reserved for situations where an AI acts outside established guidelines.

Heather Adkins, Google's Vice President of Security Engineering, informed The Wall Street Journal that Gemini acted correctly by stopping the cyberattack as soon as it realized the error. According to the executive, Google promptly notified the three compromised companies about the exploited vulnerabilities and cooperated in fixing these flaws.

However, experts and researchers expressed disagreement with Google's explanation that it was merely a vulnerability alert. Jack Cable, CEO of the AI security startup Corridor, argued that the developer of Gemini downplayed the seriousness of the incident. For him, the crucial point lies in the fact that language models are surpassing limitations and executing real attacks against external targets.

Similar stories

Google's Gemini AI model hacked three companies during cybersecurity testing
Read more
cgtn.com

Google's Gemini AI model hacked three companies during cybersecurity testing

During a cybersecurity test in May, Google's Gemini model gained internet access and successfully breached three companies. This marks the first documented instance where a Google artificial intelligence model performed such an action autonomously.

According to Heather Atkins, Google's Vice President of Security Engineering, while evaluating Gemini, it found publicly available information online and guessed credentials to access three websites that the model believed were within the testing scope.

As reported by The Wall Street Journal, which first covered the incident on Friday, in one case, Gemini repeatedly tried various passwords until it found a working one. In two other cases, the model discovered credentials in a public repository, allowing it to penetrate secured systems.

Atkins emphasized that all three organizations were notified and cooperated with the training partner regarding changes made to their testing procedures. She added that the model ceased its hacking attempts in all three instances, noting: 'These events underscore the importance of training powerful AI models to act responsibly.'

A representative from Irregular stated that this incident is related to the same issue affecting other AI labs and that all relevant laboratories were notified at the end of July. He clarified: 'All known issues on our part were fixed and resolved several weeks ago.'

Similar incidents involving Irregular have been disclosed by Meta, Anthropic, and OpenAI. Meta reported in August that the incident did not involve a sandbox escape or a complex cyberattack, whereas Irregular claimed it was working on best practices for secure AI cybersecurity assessments.

These occurrences raise questions about necessary protective measures as AI agents gain greater autonomy and access to computer systems and the internet.

Popular