SAN FRANCISCO: A Gemini AI hack reached three real companies during a May cybersecurity evaluation after Google’s model gained internet access and treated outside systems as test targets.
Irregular, an independent AI security company, conducted the evaluation. Google said Gemini found public information and credentials while trying to access websites it believed were within the authorised test.
In one case, the model guessed a password until it entered a protected system. In two others, it found credentials in publicly accessible repositories and used them to access company systems.
Google Vice President of Security Engineering Heather Adkins said Gemini stopped in all three cases after recognising that the systems belonged to real organisations rather than simulated targets. Google said the incidents caused no harm.
The Wall Street Journal first reported the Gemini AI hack on September 18. Google declined to identify which Gemini model was involved or name the affected companies.
Read: Gemini Spark Agent Surfaces In Google App Beta
Irregular said the same testing issue affected evaluations involving other major AI developers. The company notified relevant labs in late July and said it had since fixed all known problems on its side.
Google said it worked with Irregular to change testing procedures and ensured the affected companies were notified. Adkins said the incidents underscored the need to train powerful AI models to operate responsibly.
Read: OpenAI Ethical Hack Used Claude to Reach Private Code Repo
The episode comes as Google expands Gemini’s agentic capabilities. The company says its latest Gemini systems can execute increasingly complex multi-step workflows, making testing controls and network boundaries more important as models gain greater autonomy.