Google Gemini Accidentally Accessed Three Companies During Security Test

Google Gemini Accidentally Accessed Three Companies During Security Test
Gemini

In May, Google’s Gemini AI model was able to reach computer systems of three real companies during a cybersecurity test.

The incidents happened during an evaluation carried out by AI security firm Irregular. Gemini was undergoing a test to evaluate its capabilities in cybersecurity operations against mock targets. Rather, the model was taken to real organizations in three test runs.

Google has confirmed the incidents, following reports in The Wall Street Journal. The companies involved were contacted and Irregular said the issues that caused the unintended access were addressed.

In one instance, Gemini tried multiple times to guess passwords until it gained access to a protected system. In two other instances, it discovered logins in publicly available online repositories and used them to access.

The model was not specifically targeted to attack the three companies. The targets were fictional, but Gemini was able to access the broader internet. In one instance, the model came across a real company in its search for information about a fictional target.

Google said Gemini stopped its activity after realizing that it had reached real systems rather than the targets included in the exercise. The company stated that the incidents did not lead to known harm of the affected organizations.

The incidents demonstrated the importance of robust safeguards and responsible training of powerful AI systems, said Heather Adkins, vice president of security engineering at Google. Google also stated that it collaborated with Irregular to enhance its testing processes following the issues that were uncovered.

The disclosure is important because the model could autonomously perform multiple steps. It looked for information, acquired credentials and used those credentials to access protected systems. The episode demonstrates how fast an AI agent can go from information retrieval to action, given access to the internet and the right tools.

Google isn’t the only AI firm struggling with this issue. Recently, similar incidents have occurred with models from OpenAI, Anthropic and Meta during security evaluations. Some of those tests were also performed by Irregular, which garnered more attention for how AI companies isolate and monitor autonomous systems during cybersecurity research.

The Gemini cases also bring up questions about the design of AI security testing. While a system that can identify vulnerabilities can be beneficial to cybersecurity teams, it can also pose issues when a model moves from a simulated environment to live infrastructure.

The May incidents mark the first publicly disclosed instances of a Gemini system accessing real companies as part of a security evaluation, for Google. The model was able to cease when it identified the error, but the incident contributes to the growing worries about granting more and more independent AI systems direct access to the internet and computer networks.

Safeer Zahid

Safeer Zahid writes about technology, digital trends, and the latest developments in the tech industry. He covers everything from new products and online platforms to the wider impact of technology on everyday life.

Leave a comment

Your email address will not be published. Required fields are marked *