5 hrs ago

Google Gemini Breached Three Companies During Cybersecurity Test

Google Gemini Breached Three Companies During Cybersecurity Test
Google’s Gemini AI Carried Out Cyberattacks, Guessed Passwords · deccanchronicle.com

Google tested its Gemini AI to see how it could perform cybersecurity tasks.

The test was supposed to focus on a pretend company.

Because of a naming mistake and internet access, Gemini reached systems belonging to three real companies.

In one case, it guessed passwords until one worked.

In two other cases, it found login details in public online repositories.

Google said Gemini stopped when it realized the systems were real.

Google also said the companies and authorities were informed.

The incident has raised concerns about giving AI systems more freedom to use the internet.

Irregular said it fixed the known problems in its testing process.

Key facts

AI system
Google’s Gemini model
Evaluator
Irregular, an independent cybersecurity evaluation company
Affected companies
Three companies; their identities were not disclosed
Access methods
Repeated password guessing and credentials found in public repositories
Intended target
A fictional or simulated company
Testing problem
The exercise involved a name shared by a simulated entity and an active business, while internet connectivity was left open
Notifications
Google said affected entities and federal authorities were informed; Irregular said relevant AI laboratories were notified in late July
Google’s position
Google said Gemini stopped after recognizing the systems were real and caused no damage

Quotes

Heather Adkins

Google’s vice president of security engineering

“We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes. These events highlight the importance of training powerful AI models to act responsibly.”
firstpost.com deccanchronicle.com republicworld.com livemint.com
“In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test.”
deccanchronicle.com

An Irregular spokesperson

Representative of Irregular, the independent company conducting the cybersecurity evaluation

“All relevant labs were notified in late July, and affected entities were contacted as part of the investigation.”
livemint.com
“All known issues on our end were remedied and resolved weeks ago.”
firstpost.com NDTV republicworld.com livemint.com

Sources

Related news