HomeNews
Share

Google's AI has joined the "hackers' club": Gemini hacked into the systems of three companies

Evgeniia Maliarenko

Evgeniia Maliarenko

Photo: FotoField / Shutterstock

Photo: FotoField / Shutterstock

Google’s AI model, Gemini, gained access to the internet and hacked into the systems of three other companies during cybersecurity testing. Google confirmed the incident. This marks the first such incident involving the company’s AI after other AI developers reported similar incidents. Thus, Gemini has joined the “hackers’ club” alongside AI agents from Anthropic, OpenAI, and Meta, notes The Wall Street Journal.

Details

According to Google, the incident occurred back in May. The company conducted tests of the AI model in collaboration with its security partner, Irregular—the same firm that had previously identified similar issues in the AI models and agents of Anthropic, OpenAI, and Meta.

In one instance, according to the company, Gemini brute-forced passwords until it gained access to a secure system. In two other instances, it discovered employee credentials in a public repository (a repository where developers collaboratively write, test, and store source code for algorithms and software), which then allowed it to gain access to secure systems. In each case, the model halted the intrusion after determining that it had gained access to the systems of a real company rather than a simulated one, Google reported, noting that during the tests, the fictional companies bore the same names as real ones.

The companies clarified that Irregular had notified them of the hacks by AI developers as early as late July—after it became clear that OpenAI agents had hacked the Hugging Face platform. However, Google had not previously disclosed information about the hacks—the company first spoke to The Wall Street Journal about the incidents in response to questions on the matter, the newspaper notes. Google emphasized that the Gemini hack did not cause any harm to the companies involved. The AI developer did not specify exactly which firms were targeted.

“This incident underscores the importance of training powerful artificial intelligence models to act responsibly,” said Heather Adkins, Google’s vice president of security systems engineering, commenting on the incident. “In this case, the model acted appropriately,” he believes.

What People Are Saying in the Market

“It seems as though they [at Google] are trying to hide behind the standards established for disclosing vulnerabilities, which is an entirely different issue,” said Jack Cable, CEO of Corridor, a startup specializing in AI-powered security, in response to the incident (quoted in the WSJ). “The main problem [here] is that the models are going beyond what they’re supposed to do and carrying out actual cyberattacks, which I think the public should know about,” — he added, commenting on the fact that Google did not immediately disclose information about the incidents.

Context

News of Google's AI model hacking into third-party companies' systems emerged following a series of similar incidents involving agents and models from other AI developers, including Anthropic, OpenAI, and Meta.

This article is being updated

This article was AI-translated and verified by a human editor

Share

Trending

Stock Screener
Buy
Sell






















Small Caps
Investment and Finance News