FILE PHOTO: Gemini app icon in this illustration taken June 5, 2026. REUTERS/Dado Ruvic/Illustration//File Photo

Gemini hacked three companies in first known breakout by Google's AI

· CNA · Join

Read a summary of this article on FAST.
Get bite-sized news via a new
cards interface. Give it a try.
Click here to return to FAST Tap here to return to FAST
FAST

Sept 18 : Google's Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the company's AI systems autonomously committing such an act.

The hacks occurred in May during a cybersecurity test conducted by Irregular, an independent company that conducts cybersecurity evaluations.

During a standard testing evaluation, Gemini found public information online and guessed credentials to access three websites it thought were within the scope of its test, Heather Adkins, Google's vice president of security engineering, said in a statement.

"We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes," Adkins said. "These events highlight the importance of training powerful AI models to act responsibly."

CNA Games

Guess Word
Crack the word, one row at a time

Buzzword
Create words using the given letters

Mini Sudoku
Tiny puzzle, mighty brain teaser

Mini Crossword
Small grid, big challenge

Word Search
Spot as many words as you can
Show More
Show Less

An Irregular spokesperson said the incident involved the same issue that affected other AI labs and that all relevant labs were notified in late July. "All known issues on our end were remedied and resolved weeks ago," the spokesperson said.

Similar incidents linked to Irregular were disclosed by Meta, Anthropic and OpenAI. Meta said in August the incident did not involve a sandbox escape or sophisticated cyberattack, while Irregular said it was working on best practices for securely conducting AI cybersecurity evaluations.

The incidents have raised questions about the safeguards needed as AI agents gain greater autonomy and access to the internet and computer systems.

In one of the cases, the Gemini model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems, according to the Wall Street Journal, which first reported the news on Friday.

Adkins said that in all three instances, the model ceased its hacking.

Source: Reuters

Newsletter

Week in Review

Subscribe to our Chief Editor’s Week in Review

Our chief editor shares analysis and picks of the week's biggest news every Saturday.

Sign up for our newsletters

Get our pick of top stories and thought-provoking articles in your inbox

Subscribe here

Get the CNA app

Stay updated with notifications for breaking news and our best stories

Download here

Get WhatsApp alerts

Join our channel for the top reads for the day on your preferred chat app

Join here