Google's Gemini hacked three companies in first known AI breakout
Gemini hacked three companies in first known breakout by Google's AI

During a May cybersecurity test by Irregular, Google's Gemini model accessed the internet and hacked three companies—the first known case of Google's AI autonomously committing such an act. It guessed credentials or found them in a public repository, then accessed protected systems. Google alerted the affected entities; similar incidents were disclosed by Meta, Anthropic, and OpenAI. The event raises questions about safeguards as AI agents gain autonomy and internet access.
These events highlight the importance of training powerful AI models to act responsibly.
- yborg
"Guess what everyone, our AI can go rogue, TOO!"
It's just getting really embarrassing for Google at this point.
- sanex
> In one of the cases, the Gemini model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems
Pretty lame hacks if you ask me.
- sinuhe69
Irregular again! The single company that was responsible for the sloppy configurations and the hacks by OpenAI, Anthropic and now Google. This company and their partners should be held accountable for the crimes.
- danpalmer
Specifically, the model hacked when run on 3rd party infrastructure without the necessary sandboxing. Given this was to test/benchmark certain capabilities it's also possible that this was a model without built-in guardrails.
- rippeltippel
Sound like Google suffered from FOMO and felt the urge to appear in the hacking news, along the big AI players. No way Gemini is state of the art, but perhaps it's where Claude and OpenAI were 6 months ago, which would be not bad at all.