Google Gemini Accesses Real Systems During Security Test

Quite the mix-up.
Elizabeth Rigsby
Contributing Writer
Futuristic robot illuminated by blue, pink and red neon lighting against a dark background.
stock.adobe.com - Worrapol

Google’s Gemini gained unauthorized access to systems at three real companies during a cybersecurity test after an issue with the evaluation allowed the model to reach the open internet.

The incidents happened in May during a “capture the flag” exercise run by AI security company Irregular. Gemini was supposed to retrieve information connected to a fictional company, but the name used in the test unknowingly matched a real domain.

That mistake sent Gemini toward actual company systems, where it guessed its way into one and used credentials exposed in public repositories to access two others. The model stopped after recognizing that the systems were real, and Google said no damage was reported.

Why It Matters: As AI agents continue to take on more work across the enterprise, the line between what they are asked to do and what they are actually able to do becomes more important. Gemini followed its task into systems that were never supposed to be within reach. That puts more weight on how agent access is designed, where permissions end and how quickly unexpected activity can be caught.

  • A Test Error Sent Gemini Outside the Sandbox: Irregular’s exercise was designed to keep the model inside a controlled environment, but unintended internet connectivity gave Gemini access to external infrastructure. The naming collision then provided a real destination that appeared to match its assigned target. Irregular said the model interacted with the unintended domain only a limited number of times.
  • Common Security Weaknesses Were Enough to Get In: Access did not depend on a new vulnerability or sophisticated exploit. One protected system was reached after Gemini tried different passwords until one worked. For the other two, publicly exposed login credentials provided a direct route inside. The model was able to find those weaknesses and act on them without someone directing each step.
  • Safeguards Kicked In After Access Had Already Occurred: Gemini stopped in all three cases once it realized the systems belonged to real companies. Google said it does not consider the behavior model misalignment because the safeguards worked once the mistake became clear. Irregular also said the activity was not a sophisticated cyber operation, although some AI safety researchers have questioned whether the incidents should be dismissed so easily.
  • Months Passed Before Google Learned About the Incidents: Although the unauthorized access occurred in May, Google was not notified until late July, when Irregular reviewed earlier evaluations following disclosures involving other AI models. Google investigated, made sure the three affected organizations were informed and notified federal authorities. Irregular has since changed its testing processes and said the known issues have been resolved.
  • The Testing Problem Reached Several Major AI Labs: Similar evaluation issues affected models from OpenAI, Anthropic and Meta, according to Irregular. Those companies have separately reported incidents involving agents reaching unintended systems or taking unauthorized actions during cybersecurity testing. Google has not disclosed which Gemini model was involved, and the incident marks the first known case it has reported of one of its AI models autonomously gaining unauthorized access to third-party systems.

Go Deeper -> Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up – The Hacker News

Google’s Gemini hacked three real companies during security test – cybernews

Google’s Gemini becomes latest AI model to break out and hack computer systems – CNBC

Google says its AI model gained unauthorized access to three outside systems – NBC News

Cybersecurity updates, executive insights, and the stories shaping the enterprise.

Browse past editions of TNCR newsletters. 

Technology news, cybersecurity, & executive insights.

×
You have free article(s) left this month courtesy of the CIO Professional Network.

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Would You Like To Save Articles?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Thanks for subscribing!

We’re excited to have you on board. Stay tuned for the latest technology news delivered straight to your inbox.

Save My Spot For TNCR LIVE!

Thursday April 18th

9 AM Pacific / 11 PM Central / 12 PM Eastern

Register for Unlimited Access

Already a member?

Digital Monthly

$12.00/ month

Billed Monthly

Digital Annual

$10.00/ month

Billed Annually

Would You Like To Save Books?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Log In To Access Premium Features

Sign Up For A Free Account

Name
Newsletters