Google’s Gemini AI Unintentionally Hacks Three Companies During Cybersecurity Tests
Google's artificial intelligence model, Gemini, unintentionally hacked the systems of three companies during cybersecurity tests conducted in May. This marks the latest incident in a series of breaches carried out by AI agents, raising concerns among security experts and technology developers alike.
The breaches occurred during tests conducted by "Irregular," a company specializing in AI security. These were the same tests that resulted in previously disclosed hacks by OpenAI, Anthropic, and Meta Platforms.
Irregular confirmed on Friday that all these breaches stemmed from the same underlying issue, noting that it had notified the relevant AI model developers about them in late July.
Gemini Hacks Company Systems During Tests
One of the Google breaches occurred when Gemini was tasked with searching for information about a fictitious company that happened to share the exact name as a real one. Google confirmed the incident after it was earlier reported by The Wall Street Journal. The AI model managed to guess a password and access a service belonging to the real company. A Google spokesperson stated that the company has reported the incident to the authorities.
(Related News: OpenAI reveals its models unintentionally hacked Hugging Face system)
The recent series of hacks executed by AI agents has ignited a global debate about the growing risks of this technology and how to mitigate them. Dario Amodei, CEO of Anthropic, called for a sector-wide slowdown in the pace of AI development—a proposal supported by OpenAI CEO Sam Altman, Elon Musk, and others.
Debate Over Slowing Down AI Development
In contrast, US President Donald Trump, Nvidia CEO Jensen Huang, and Meta CEO Mark Zuckerberg have opposed imposing new regulatory restrictions on AI, arguing, among other points, that companies should be able to self-regulate. Some AI startups have also warned that increased restrictions could make it difficult for them to compete with larger tech corporations.
Heather Adkins, Vice President of Security Engineering at Google, stated that the Gemini breaches "highlight the importance of training powerful AI models to behave responsibly."
(Related News: Meta's AI model executes external breach during security test)
As for the other breaches carried out by Gemini, they occurred when the model searched the internet using the company's name. Adkins explained that these searches led the model to public online repositories containing login credentials belonging to other companies, which it then used to access additional systems.
"In all three cases, the model paused," Adkins added, noting that it was ensured all three entities were duly notified of the breaches.
Joseph Lauer, a spokesperson for Irregular, said that the company "acted immediately, addressing and resolving all known issues on our end weeks ago."
