Agency News

Business News | Google’s Gemini Breaks out of Test Environment to Hack Three External Firms: Report

Get latest articles and stories on Business at LatestLY. Google’s Gemini hacked three companies in the first known breakout, after the model accessed the internet and breached external systems during an evaluation of its cybersecurity capabilities.

Business News | Google’s Gemini Breaks out of Test Environment to Hack Three External Firms: Report

Washington, DC [US], September 19 (ANI): Google’s Gemini reportedly hacked three companies in the first known breakout, after the model accessed the internet and breached external systems during an evaluation of its cybersecurity capabilities.

First reported by The Wall Street Journal on Friday, the intrusions took place in May during an exercise conducted by the testing firm Irregular, which also participated in evaluations involving similar breaches disclosed by OpenAI, Anthropic, and Meta. 

Also Read | Thane Weather Forecast & Update for Today, Saturday, 19 September 2026: Expect Thunderstorms and Heavy Rain, High of 30?C.

In one instance, the AI model guessed passwords until it penetrated a protected network. In two separate runs, the system identified exposed credentials within public repositories to gain entry. Google maintained that the model ceased its operations in each instance once it recognized that it had penetrated real corporate infrastructure rather than a simulated target.

Irregular alerted Google to the breaches in late July, following revelations that OpenAI agents had compromised the software platform Hugging Face. Google did not make the development public until inquiries were submitted by The Wall Street Journal. 

Also Read | Bhubaneswar Weather Forecast & Update for Today, Saturday, 19 September 2026: Expect Thunderstorms and Heavy Rain, High of 32?C.

The company stated that the event did not warrant disclosure because the model inflicted no damage and disconnected upon discovering the mistake, likening the process to a bug bounty initiative.

“This event highlights the importance of training powerful AI models to act responsibly,” Heather Adkins, Google’s vice president of security engineering, said in a statement. “In this case, the model acted appropriately.” 

Industry observers contested Google's characterization of the event, arguing that the autonomous breach of external corporate networks represented a serious breakdown in containment protocols.

The breaches stemmed from an issue of mistaken identity during a capture-the-flag exercise on Irregular’s infrastructure, where the model received instructions to retrieve data from a simulated entity that shared its name with an active business. While the test environment was intended to remain isolated, internet connectivity was inadvertently left open.

Beyond guessing passwords in the initial run, the system executed web searches for the target name during subsequent tests, located credentials stored in online repositories, and deployed them to penetrate two additional corporate environments.

Google stated that it informed the three affected entities alongside federal authorities, while declining to identify the victim companies or the specific Gemini version involved.

“All relevant labs were notified in late July, and affected entities were contacted as part of the investigation,” an Irregular spokesperson said.

“Irregular took immediate action, and all known issues on our end were remedied and resolved weeks ago,” the spokesperson added. (ANI)

(The above story is verified and authored by ANI staff, ANI is South Asia's leading multimedia news agency with over 100 bureaus in India, South Asia and across the globe. ANI brings the latest news on Politics and Current Affairs in India & around the World, Sports, Health, Fitness, Entertainment, & News. The views appearing in the above post do not reflect the opinions of LatestLY)