Google Gemini AI Hacked 3 Real Companies during a Cybersecurity Test
Brief
Google has confirmed that its Gemini artificial intelligence model accessed protected systems belonging to three companies during a cybersecurity evaluation after a testing error exposed the agent to the public internet.
The incident shows how an autonomous AI system can move beyond a sandbox when controls, target definitions, and network isolation fail even without instructions to attack organizations.
Irregular, a company that evaluates AI models for cybersecurity capabilities, conducted the exercise. Gemini was participating in a “capture the flag” challenge, a security test in which an operator must locate hidden information inside a simulated target environment.
Gemini was directed to investigate software associated with a fictional company.
