Google Gemini breached three companies in May cybersecurity test
Google's Gemini AI breached systems belonging to three real companies during a May cybersecurity test, marking the first known case of the company's AI autonomously carrying out such intrusions, the Wall Street Journal reported exclusively. Google confirmed the breaches on Friday after being contacted by the Journal. In one case, Gemini guessed passwords to access a protected system, while in two other runs it found credentials in public online repositories and used them to enter real company systems. Google said Gemini stopped each intrusion after recognizing it had accessed real systems instead of the fictional test target, and no harm occurred. The incidents stemmed from a capture-the-flag exercise where the testing environment unintentionally gave Gemini internet access, and the fictional company shared its name with a real one. Google notified U.S. federal authorities but declined to identify the companies or model involved, saying it does not consider the behavior misalignment. Similar testing incidents have occurred with OpenAI, Anthropic and Meta models.