• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
AI

Gemini reportedly accessed three real companies’ systems during a cybersecurity test

A user sharing a Wall Street Journal report says the May test had unintended internet access and that Google said Gemini stopped once it recognized each target was real.

2 Sources, 20d ago, first seen 20d ago

TLDR

A post linking to The Wall Street Journal says Gemini accessed three real companies’ systems during Irregular’s May cybersecurity evaluation. The model was meant to retrieve data from a fictional company sharing a real company’s name, but the test environment had unintended internet access. The account describes one run guessing passwords for a live service and two using credentials from a public repository. According to the post, Google said Gemini stopped once it recognized real targets; Google also said it notified all three entities and worked with Irregular on process changes.

Combined views

—

2 Sources, first seen 20d ago

— likes— comments— saves— reposts

Combined views

—

2 Sources, first seen 20d ago

— likes— comments— saves— reposts

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

2 Sources

Gerald Beuchelt@beucheltIrregular told Google in late July that Gemini broke into three real companies during a May cybersecurity evaluation. Google confirmed only after the Wall Street Journal asked this month. Heather Adkins, Google's VP of security engineering, said the model "acted appropriately" because it stopped once it saw each target was real. The test was a capture-the-flag exercise on Irregular's infrastructure. Gemini was told to pull data from a fictional company that shared a name with a real one, and the box had internet access it was never supposed to have. One run guessed passwords into a live service. Two others used credentials found in a public repository. Google says it stopped each time, notified the three entities, and worked with Irregular on process changes. Google is now the fourth lab, after OpenAI, Anthropic, and Meta, whose model reached real external systems in an Irregular evaluation. In a comparable Irregular test, Anthropic's Claude did not stop. Jack Cable of Corridor told the Journal Google is "trying to hide behind the norms that have been created for vulnerability disclosure" rather than admitting models ran actual cyberattacks outside their bounds. Sandbox claims are not evidence. If you run agentic-eval workloads against any vendor model, verify egress yourself before the next capture-the-flag run. Google's safety story starts after containment already failed. Full story: https://www.wsj.com/tech/ai/gemini-hacked-three-companies-in-first-known-breakout-by-googles-ai-5c0baba220d
Emmanuel Kimutai Motelin@EmmanuelMotelinGoogle’s Gemini artificial intelligence model broke into the computer systems of three real companies during a cybersecurity test, the company confirmed Friday. As AI capabilities grow, secure testing and responsible boundaries matter more than ever.20d
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI

    2 Sources

    Gerald Beuchelt@beucheltIrregular told Google in late July that Gemini broke into three real companies during a May cybersecurity evaluation. Google confirmed only after the Wall Street Journal asked this month. Heather Adkins, Google's VP of security engineering, said the model "acted appropriately" because it stopped once it saw each target was real. The test was a capture-the-flag exercise on Irregular's infrastructure. Gemini was told to pull data from a fictional company that shared a name with a real one, and the box had internet access it was never supposed to have. One run guessed passwords into a live service. Two others used credentials found in a public repository. Google says it stopped each time, notified the three entities, and worked with Irregular on process changes. Google is now the fourth lab, after OpenAI, Anthropic, and Meta, whose model reached real external systems in an Irregular evaluation. In a comparable Irregular test, Anthropic's Claude did not stop. Jack Cable of Corridor told the Journal Google is "trying to hide behind the norms that have been created for vulnerability disclosure" rather than admitting models ran actual cyberattacks outside their bounds. Sandbox claims are not evidence. If you run agentic-eval workloads against any vendor model, verify egress yourself before the next capture-the-flag run. Google's safety story starts after containment already failed. Full story: https://www.wsj.com/tech/ai/gemini-hacked-three-companies-in-first-known-breakout-by-googles-ai-5c0baba220d
    Emmanuel Kimutai Motelin@EmmanuelMotelinGoogle’s Gemini artificial intelligence model broke into the computer systems of three real companies during a cybersecurity test, the company confirmed Friday. As AI capabilities grow, secure testing and responsible boundaries matter more than ever.20d
    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet