Google’s Gemini AI model hacked three companies during cybersecurity test
SAN FRANCISCO: Google’s Gemini artificial intelligence model gained access to three websites by using publicly available information during a cybersecurity test, in what has been described as the first known instance of a Google AI system autonomously carrying out such activity.
The incident occurred in May during an assessment conducted by the independent cybersecurity firm Irregular, according to a report.
During the test, Gemini searched information available online and used credentials it had inferred to gain access to three websites that it determined were within the scope of the exercise.
Google Vice President of Security Engineering Heather Adkins said the three organizations had been notified of the incident and that changes had been made to the testing methodology in collaboration with the training partner.
Adkins said the incident highlighted the importance of training powerful AI models to operate responsibly.
An Irregular spokesperson said the issue was similar to problems encountered by other AI laboratories. The affected organizations were notified by the end of July, the spokesperson said.
According to Irregular, all of the issues it identified had been resolved several weeks ago.
