Gemini Hacks 3 Companies
What was supposed to be a cybersecurity test has turned into a warning about how far artificial intelligence can go when it gets access to the real internet.
Google’s Gemini AI model accessed the computer systems of three real companies during a cybersecurity evaluation conducted in May, in what has been described as the first known incident of a Google AI system carrying out such intrusions.
The test was conducted by AI security firm Irregular and was designed to assess Gemini’s cybersecurity capabilities in a controlled environment. However, the model was able to access the internet and reached systems belonging to real companies.
According to Google, Gemini found information online and used credentials to gain access. In one case, the model reportedly guessed passwords, while in two others it found credentials in publicly accessible repositories. The three companies were not publicly identified.
Google said Gemini stopped its actions in all three cases after determining that it had accessed real companies rather than the fictional targets it was supposed to test. The affected organisations were subsequently notified.
The incidents were reported to Google by Irregular in July, but the company did not publicly disclose them at the time. Google said it did not consider the incidents to require disclosure because Gemini stopped after recognising the systems were real and did not cause harm. The revelations emerged after The Wall Street Journal asked Google about the incidents.
The disclosure comes amid growing scrutiny of AI agents that can independently perform tasks online. Similar incidents involving AI systems from other major companies have also raised questions about whether existing safeguards are sufficient as AI models become increasingly capable of carrying out cybersecurity operations.
The bigger question now is not simply whether AI can hack , but what happens when an AI agent is given the tools to act beyond the boundaries of the test designed to contain it.