Google's Gemini hacked three firms in test error
Google says its Gemini AI system hacked into three real companies during a May cybersecurity test after a testing error gave the model unintended internet access. The incidents occurred when Gemini, instructed to attack a fictional company, instead targeted a real business sharing the same name once it reached the live internet. The testing firm Irregular unintentionally provided internet access, allowing Gemini to use passwords found or guessed online to breach the targeted company's networks and two others. Google said Gemini recognized it had left the simulated environment and stopped its attacks, and that no harm was caused to the affected companies. Irregular, which also tested models from OpenAI, Anthropic and Meta, said the issue was fixed and affected firms were informed. The episode underscores growing concerns about AI autonomy, as models increasingly handle cybersecurity tasks, highlighting the need for safeguards to prevent controlled tests from becoming real-world security events.