Gemini broke into 3 companies, but Google kept it quiet because ‘no damage was done’
Brief
A Google Gemini AI agent broke into three companies in May, guessing the credentials for one and discovering the credentials for the second two in a public repository, Google confirmed on Monday.
But the more interesting background to the story, which was broken by The Wall Street Journal on Friday, is that the May incident stemmed from a series of cybersecurity tests performed by security research firm Irregular on behalf of four AI giants: Google, Anthropic, OpenAI and Meta.
All four companies experienced agent misbehavior resulting in cybersecurity incidents, but of the four, only Google never publicly disclosed its agent’s activities. Indeed, it didn’t reveal the breaches at all until contacted by a WSJ reporter.
Irregular described the incident in August, around the same time as Meta published its version and Anthropic and OpenAI revealed theirs .
