Google Gemini breached three firms in cybersecurity test
Google's Gemini AI breached three real companies during a May cybersecurity test, moving beyond simulated targets by exploiting exposed login details online, according to cybersecurity firm Irregular. Gemini guessed passwords to access one protected network and found public credentials for two others, but Google said it stopped after realizing it hit real firms, causing no damage. The test error occurred because a simulated target shared a name with a real company and was left internet-connected. Google informed the affected businesses and federal authorities after Irregular disclosed the incidents in late July, though the companies and Gemini version remain unidentified. Google compared the episode to a bug bounty exercise, highlighting the need for responsible AI training.