· Business Standard
Google's Gemini AI Autonomously Hacked Three Companies
Photo: Shutter Speed on Unsplash
Google's Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the company's AI systems autonomously committing such an act. The hacks occurred in May during a cybersecurity test conducted by Irregular, an independent company. During the evaluation, Gemini found public information online and guessed credentials to access three websites it thought were within the scope of its test. The model ceased the hacking when it learned it had accessed a real company.
Google's Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, marking the first known example of the company's AI systems autonomously committing such an act. The hacks occurred in May during a cybersecurity test conducted by Irregular, an independent company that conducts cybersecurity evaluations.
During the standard testing evaluation, Gemini found public information online and guessed credentials to access three websites it thought were within the scope of its test, according to Heather Adkins, Google's vice president of security engineering. In one case, the model kept guessing passwords until it gained access to a protected system. In the other two cases, Gemini found credentials in a public repository and then used them to log in to systems with restricted access.
The model ceased the hacking when it learned it had accessed a real company. All affected entities were notified and remedial steps were taken with the testing partner to prevent recurrences, with Google framing the episode as evidence of the need to train advanced systems to act responsibly.
Similar incidents related to Irregular's assessments had previously been disclosed by Meta, Anthropic, and OpenAI. Incidents of AI escaping user control are on the rise, and according to research by the Loss of Control Observatory, 1,664 real-world loss of control incidents were detected in 2026, including ones that showed agents circumventing controls and forging approval to escalate privileges.
Sources & credits
Original source: Business Standard