Google’s Gemini AI Carried Out Cyberattacks, Guessed Passwords
Google has confirmed that its Gemini AI model accessed three real companies’ systems during a cybersecurity test in May, including one case where it guessed passwords to gain entry.
Google has confirmed that its Gemini artificial intelligence model accessed the systems of three real companies during a cybersecurity evaluation in May, after mistakenly identifying them as part of the testing environment.
The company disclosed the incidents on Friday after they were first reported by the Wall Street Journal, saying the affected organisations were notified and changes had been made to the testing process.
According to Google’s Vice-President of Security Engineering, Heather Adkins, Gemini found publicly available information online and used credentials it discovered or guessed to access websites it believed were within the scope of the test.
In one case, the model reportedly guessed passwords until it gained access to a protected system. In two other cases, it found login credentials in public repositories and used them to access the systems.
The incidents occurred during a cybersecurity evaluation conducted by Irregular, an independent company that tests artificial intelligence systems. Gemini had been instructed to retrieve information from software operated by a fictional company within the test environment.
The testing error occurred after the AI was unintentionally given internet access, while the fictional company shared a name with a real organisation. This allowed Gemini to interact with systems outside the intended testing environment.
Google said the model stopped its activity in all three cases after recognising that it had accessed real companies’ systems. The company declined to identify the affected organisations but said they had all been informed.
Google also said the incidents did not involve its newest Gemini model and that federal authorities had been notified.
The incidents have renewed concerns about the risks associated with giving increasingly autonomous AI systems access to the internet and computer systems.
Similar cases involving AI models from other technology companies have also been reported in recent months, prompting discussions within the industry about stronger safeguards for cybersecurity testing and the behaviour of autonomous AI systems.
Related stories
News
Keyamo Criticises Atiku for Referring to Tinubu as Bola
Aviation Minister Festus Keyamo has criticised former Vice-President Atiku Abubakar for repeatedly referring to President Bola Tinubu as “Bola” during a press conference, describing the reference as disrespectful to the office of the President.
News
Great Nigerian Assembly Graduates Pioneer Class of Certified Citizen Reporters in Ile-Ife
The Great Nigerian Assembly (GNA) has graduated the pioneer cohort of its Certified Citizen Reporter (CCR) programme at a ceremony in Ile-Ife, Osun State. Held under the theme “Credible Reports. Stronger Communities. Better Nigeria,” the event marked the transition of 30 trained citizens into community-based reporting and accountability roles.
News
Shettima Hails NAHCON Over 2026 Hajj Operations
Vice-President Kashim Shettima has commended NAHCON for the improved coordination of the 2026 Hajj, attributing the successful operation to the commission’s management and President Bola Tinubu’s support.
News
Parents of Miners Who Died in NSCDC Custody Demand Compensation
Parents of miners who died in NSCDC custody in Niger State have demanded compensation for the bereaved families, alongside a thorough investigation into the circumstances surrounding the deaths.
Comments (0)
Leave a comment
All comments are moderated before publishing. Your email is never published.