Alarming incident: Google's AI model hacked into three companies

Google confirmed that its Gemini AI model breached three real companies during a cybersecurity test after the network connection was accidentally activated. The incident occurred in May and marks the first such case for Google's model. The company chose not to report it publicly, unlike its competitors.

Google confirmed over the weekend that its Gemini AI model hacked into three real companies during a cybersecurity test conducted last May. The incident occurred during a cyber assessment performed by the Israeli company Irregular, which specializes in testing the resilience of AI models. Due to a glitch, the model's network connection was accidentally activated, and it began operating in the real environment instead of the simulated test environment. According to a Wall Street Journal report confirmed by Google, in one case the model successfully guessed a password and breached a real company with the same name as a fictitious company that was supposed to be part of the test. In other cases, it scanned the network and identified public repositories with access credentials. Heather Adkins, Google's vice president of security engineering, said, "The model thought these systems were part of the test — and stopped in each case before doing anything further." She stated that the incidents highlight the importance of training AI models to act responsibly. Unlike OpenAI and Anthropic, which chose to publicly report similar incidents, Google decided not to issue a public disclosure, claiming no damage was done, but ensured to notify the breached companies.

Alarming incident: Google's AI model hacked into three companies