Google’s Gemini Breached Three Companies During Security Tests, Raising Alarms Over AI Hacking Capabilities
Google confirmed that its Gemini AI model, during red‑team exercises run by security firm Irregular, autonomously breached the protected systems of three companies, including one case where it gained access by guessing a set of leaked credentials.
An internal security exercise has shown Google’s Gemini model can act as an autonomous intruder, breaching several companies’ systems during controlled tests.
Google has confirmed that in red‑team trials carried out with cybersecurity firm Irregular, Gemini successfully broke into the protected environments of three companies. Red‑teaming is a form of authorized stress‑testing in which specialists probe an organization’s defences, looking for weaknesses before real attackers find them.
In one of the reported cases, Gemini obtained unauthorized access simply by guessing a set of leaked credentials, without humans specifying each move. That detail stands out because Gemini is marketed primarily as a general‑purpose AI for tasks like coding and content generation, not as a specialized hacking toolkit.
Public information so far doesn’t name the companies involved, describe their sectors, or say what kind of data Gemini might have reached under real‑world conditions. There is no indication from the available reporting that personal or customer data were actually taken during the tests. Irregular notified the affected firms of the vulnerabilities it had uncovered.
The episode underlines how large models can be turned toward offensive as well as defensive cybersecurity roles. The same capabilities that let them scan codebases for bugs or analyze configuration files for missteps can, in testing environments, be directed at finding ways in.
For employees and customers of big organizations, the risk is indirect but real: as models like Gemini improve, mistakes such as reused passwords or misconfigured databases become easier to spot and exploit at scale.
Regulators and policymakers have so far focused more on AI misuse in areas such as disinformation and discrimination. These red‑team findings bring forward questions about when it is acceptable to deploy models with clear offensive potential, even in controlled conditions, and what safeguards should exist to keep those capabilities from escaping test labs or being copied by malicious actors.
The tests also intersect with national security debates, as intelligence and defence agencies weigh using AI for both cyber defence and cyber operations.
Key developments to watch now include whether Google publishes a detailed technical breakdown of what Gemini did during the trials, how other major AI developers handle similar offensive security experiments, and whether cybersecurity or data‑protection authorities start drafting specific guidance for models capable of autonomous intrusion during testing.
Sources
- OSINT