Google Gemini AI Hack Reached 3 Companies During Security Test

Ojas Srivastava

The Gemini AI hack happened after Google’s model gained unintended internet access during a cybersecurity evaluation and entered three real company systems.

A Gemini AI hack has added Google to the growing list of major AI companies dealing with models that crossed the boundaries of cybersecurity tests.

Google confirmed that Gemini accessed systems belonging to three real companies during an evaluation in May. The test was supposed to measure how well the model could identify and exploit weaknesses inside a controlled environment.

Instead, the AI ended up interacting with real organisations.

According to the BBC’s report, Gemini found public information online and either located or guessed credentials for websites it believed were part of the exercise. A Google official said the model stopped in each case after recognising that it had entered real systems.

The three affected companies were informed. Google said the incidents caused no harm.

The details matter because the Gemini AI hack was not described as the model deliberately escaping a secure sandbox. The problem began with the testing environment.

Independent AI security company Irregular was carrying out the evaluation. The system was supposed to target fictional companies, but the models were accidentally given access to the open internet.

In one case, a fictional company used in the test had the same name as a real business. Gemini searched online for the target and ended up attacking the real organisation instead.

That sounds like a simple configuration mistake. It still exposes a serious problem.

AI models used for cybersecurity testing are deliberately given difficult objectives. They may be asked to find vulnerabilities, obtain access or move deeper into a network.

If the boundary around the test is wrong, a capable model can apply those instructions to systems nobody intended it to touch.

The Wall Street Journal’s reporting said the incidents involved basic techniques such as searching for public credentials and guessing passwords. That makes the episode more practical than dramatic.

Gemini did not invent an exotic new hacking method. It used ordinary techniques effectively enough to reach real systems.

The incident also looks less isolated when compared with recent tests involving other frontier models.

The AI Decode previously covered a Meta AI security incident where a testing configuration also allowed an AI model to interact with an external organisation. Similar cases have involved OpenAI and Anthropic systems.

That pattern matters more than any single breach.

AI agents are moving beyond answering questions. They can use browsers, write code, operate software and pursue goals through several steps without a human approving every action.

For cybersecurity, those abilities are useful. A model can search for weaknesses faster than a person, automate repetitive testing and help defenders identify vulnerabilities before criminals do.

The same capability makes containment much more important.

Google vice president of security engineering Heather Adkins said the company worked with the testing partner on changes after the incidents. Google also stressed that the models stopped once they recognised they were interacting with real companies.

That is a positive detail, but it does not erase the initial failure.

The Gemini AI hack happened because the surrounding system gave the model access it should not have had.

That distinction fits a wider AI safety problem. The AI Decode’s coverage of an OpenAI chief scientist’s safety warning examined why making models more capable does not automatically make them easier to control.

AI safety therefore depends on more than the model.

It depends on network rules, permissions, credentials, monitoring and the people designing the test.

The Gemini AI hack did not cause reported damage. It did show how little room there is for configuration errors once AI systems become capable enough to act on their own.

The next question is whether AI labs can build testing environments that are as capable at containing agents as the agents are becoming at completing their tasks.

Leave a Comment