Google has confirmed that its AI model, Gemini, breached the security of three other companies in May. This marks a first for Google and occurred during a cybersecurity evaluation conducted by the Israel-based AI-security firm, Irregular.
The hacks took place within a closed testing environment with fake companies, which was not intended to have internet access. However, internet access was unintentionally made available, according to the Wall Street Journal. Once connected, the models unexpectedly accessed real firms.
In one instance, Gemini correctly guessed the password and breached a real company's service after being prompted to obtain information from a fake company with the same name. In two other tests, the model found public repositories with credentials and used them to access real companies. Google stated that the model stopped once it identified it had accessed real companies.
Irregular disclosed the hacks to Google at the end of July. Google confirmed the incidents but did not publicly disclose them, stating the models did not damage the companies. Heather Adkins, Google's vice-president of security engineering, said the model found public information online and guessed credentials to access websites it believed were part of the test.