Google confirms Gemini AI hacked three companies in May test
Google has confirmed its Gemini AI model breached the security of three other companies during a May cybersecurity evaluation, marking the first public acknowledgment of the incidents. The hacks occurred in a closed testing environment that was unintentionally connected to the internet. The breaches were discovered by Irregular, an Israel-based AI-security firm, which disclosed them to Google at the end of July. In one case, Gemini guessed credentials for a real company sharing a name with a fake test entity, while in two others it found public repositories with login details. Google stated the model stopped once it realized the targets were real, and it did not disclose the hacks publicly because no damage occurred. The incidents follow similar breaches by OpenAI and Anthropic, which voluntarily disclosed their hacks, prompting Senator Bernie Sanders to demand a pause in AI development. Google instead ensured the affected companies were informed, with security chief Heather Adkins emphasizing the need to train powerful AI models to act responsibly.