Industry Odisha Bureau, Sept 19: In a latest update, Google has confirmed that its Gemini AI model hacked the systems of three real companies during a cybersecurity test back in May. However, it also mentioned that the activity was stopped after they recognised that the targets were real.
Notably, the incidents occurred during a “capture the flag” exercise conducted by AI security testing company Irregular. Gemini was instructed to retrieve information from software belonging to a fictional company. However, the fictional company shared a name with a real business. The testing environment also unintentionally allowed Gemini to access the internet.
In one of the cases, Gemini reportedly guessed passwords until it gained access to a protected system. In the other two cases, it found credentials in publicly available online repositories and used them to access the systems of real companies. Google said the model stopped in all three cases after determining that it had reached real companies rather than simulated targets
Google also said that the affected companies were notified and that no harm was caused. It also worked with Irregular to improve testing procedures. The identities of the companies have not been disclosed.
Meanwhile, Irregular said that the incident resulted from the same testing issues that were linked to similar cases involving AI models from OpenAI, Anthropic and Meta. The company said relevant AI labs were notified in July and that the known issues had since been resolved.

