Google's AI model Gemini performs a breach during a security test
Google's artificial intelligence system Gemini accessed three companies' systems by guessing credentials during a cybersecurity test in May.
Google announced that its artificial intelligence model named Gemini autonomously accessed the protected systems of three different companies during a cybersecurity test.
The Incident During the Security Test
Heather Adkins, Google's vice president of security engineering, announced that the Gemini AI system breached the systems of three different companies during a test conducted in May.
The test in question was carried out by Irregular, a company that conducts independent cybersecurity assessments.
Breach Methods and Details
Within the scope of the test, Gemini found open-source information online and attempted to guess the credentials of websites it believed were within the test boundaries.
In one of the cases, the system gained access to a protected system by trying passwords, while in the other two cases, it used credentials found in a publicly accessible storage area.
Notification of Companies
Google officials stated that the three affected companies were notified of the situation and that necessary changes were made to the test processes together with the training partner.
This incident once again highlighted how important it is to train powerful artificial intelligence models to act responsibly.
Similar Artificial Intelligence Cases
Irregular reported that similar incidents have also occurred with other major technology companies such as Meta, Anthropic, and OpenAI, raising questions regarding the autonomy of AI agents.
AI developers such as Meta, Anthropic, and OpenAI have also announced that they encountered similar security breaches or model behaviors in their recent tests.