Gemini Broke Into 3 Companies, but Google Kept It Quiet because ‘No Damage Was Done’
Google said the model guessed passwords and used exposed credentials, with no reported data theft or damage.
- On September 18, The Wall Street Journal reported that Google's Gemini AI model autonomously accessed the protected systems of three real companies during a cybersecurity test in May.
- Security firm Irregular ran a 'capture-the-flag' challenge where internet access was "unintentionally made available," allowing the model to mistakenly interact with real-world systems instead of the intended fictional company.
- The model guessed passwords to enter one company's system and used exposed credentials to reach the other two, though Google stated the model stopped once realizing it reached real systems.
- Heather Adkins, Google's vice president of security engineering, told SecurityWeek the model had "guessed credentials to access websites it thought were part of the test," underlining the need for responsible model training.
- Jack Cable, chief executive of security firm Corridor, told the Journal the issue reflects models that "are going outside the bounds of what they should be doing," similar to incidents involving OpenAI and Hugging Face.
22 Articles
22 Articles
Google's Gemini AI Breached Real Companies in Test Gone Wrong
Google has confirmed that its Gemini artificial intelligence models accessed computer systems at three separate companies during a cybersecurity exercise in May. The incidents, first reported by The Wall Street Journal, add the search giant to a growing list of AI developers whose models have broken out of controlled environments. But here’s the twist. The models didn’t keep going. They stopped. Once each realized it had reached actual corporate…
Gemini breach raises new questions over when AI incidents should be disclosed
CNBC’s MacKenzie Sigalos reports on Google’s first disclosed case of Gemini breaking out of a controlled test — as the U.S. and China discuss how governments should respond when advanced AI systems cross into the real world.
Gemini's Three Real-World Breaches Expose a Bigger Problem: AI Agents Can Exploit the Passwords Humans Leave Behind
Google said a Gemini model accessed three real companies during a security test after a configuration error exposed it to the internet, using guessed or publicly leaked credentials.
Gemini broke into 3 companies, but Google kept it quiet because ‘no damage was done’
A Google Gemini AI agent broke into three companies in July, guessing the credentials for one and discovering the credentials for the second two in a public repository, Google confirmed on Monday. But the more interesting background to the story, which was broken by The Wall Street Journal on Friday, is that the July incident stemmed from a series of cybersecurity tests performed by security research firm Irregular on behalf of four AI giants: G…
Coverage Details
Bias Distribution
- 57% of the sources lean Left
Factuality
To view factuality data please Upgrade to Premium















