Google Confirms Gemini Hacked Three Companies in Misconfigured Cybersecurity Test
Google says Gemini accessed three companies' servers in May after a third-party cybersecurity test was misconfigured. No information was retrieved.
The acknowledgment makes Google the latest major AI company to disclose that its models have hacked other companies, after similar disclosures from OpenAI and Anthropic this summer. The Wall Street Journal reported on the incident last week, and Google confirmed details of that report.
The test was run by Irregular, a third-party cybersecurity firm. Irregular set up a capture-the-flag exercise in which Gemini models were instructed to retrieve specific information from a fake company. The exercise was supposed to take place in a closed environment isolated to Irregular’s own servers. But Irregular misconfigured the test, allowing the models to access the open internet. The fake tester company was also assigned a name used by a real company.
That combination led Gemini to try to retrieve information from the real company. To do so, the AI searched public software repositories and found login credentials for two of the companies whose systems it accessed. For the third company, Gemini used brute force, guessing passwords until it found the correct one.
Google had not previously disclosed the incident. Heather Adkins, Google’s vice president of security engineering, said in a statement that “the model acted appropriately.” According to the reporting, Gemini never actually retrieved information from any of the three companies and apparently determined that it had accessed the wrong systems.
Based on the available account, the incident appears to have resulted from human error. If Irregular had configured the testing environment to prevent Gemini from reaching the internet, the breaches might have been avoided.
Editor's Summary
Google confirmed that Gemini gained unauthorized access to three companies’ servers in May during a misconfigured cybersecurity test run by Irregular. The models found credentials in public repositories and brute-forced one password, but Google says no information was retrieved. The incident follows similar AI hacking disclosures from OpenAI and Anthropic and appears to stem from human error in the test setup.