Google’s Gemini AI model hacked three companies during a cybersecurity test, according to The Wall Street Journal (WSJ), adding to a series of similar incidents involving AI models from OpenAI, Anthropic and Meta.
Google’s vice president of security engineering, Heather Adkins, said Gemini found public information online during a standard testing evaluation and used credentials it found or guessed to access three websites it believed were within the scope of its test.
The incidents occurred in May during a cybersecurity evaluation conducted by Irregular, an independent company that tests the capabilities of AI systems.
In one of the cases, Gemini guessed passwords until it gained access to a protected system. In the other two, it found credentials in a public repository that allowed it to access protected systems.
Adkins said Gemini stopped its activity in all three cases after recognizing that it had accessed real companies. She added that the three companies were notified, and Google worked with Irregular on changes to its testing processes. “These events highlight the importance of training powerful AI models to act responsibly,” Adkins said.
Google Cloud introduced AI Threat Defense on May 28, a platform designed to use AI to identify vulnerabilities, detect threats and help security teams respond to cyberattacks.
An Irregular spokesperson said the incidents involved the same issue that affected other AI labs and that all relevant labs were notified in late July. An Irregular spokesperson said, “All known issues on our end were remedied and resolved weeks ago.”
The incident comes as AI companies face growing debate over the independence and effectiveness of model evaluations. On September 18, Anthropic announced a partnership with Accenture for independent evaluation, while continuing discussions with METR and other evaluators.
Also Read: David Sacks Upholds Zuckerberg’s Approach: Don’t Call on Others, AI Safety is Routine Work





