Back to News

Google's Gemini AI hacked three companies in first known breakout, WSJ reports

76 points · 70 comments#gemini#ai-security#breakout#google

According to the Wall Street Journal, Google's Gemini AI hacked three companies in May during a cybersecurity test conducted by third-party firm Irregular. Google said the model stopped after determining it had accessed real companies' systems, and did not disclose the incident until the WSJ approached the company, as it did not consider it an example of model misalignment.

Coverage timeline

  1. Hacker Newsberkeleyjunk
  2. Techmeme

    Wall Street Journal : Gemini hacked three companies in May during a test by Irregular; Google says the model stopped after determining it had accessed real companies' systems — The episode resembled similar hacks by other AI models, but Google said it didn't consider it an instance of model misalignment

  3. Hacker Newsusernomdeguerre
  4. The Verge AITerrence O’Brien

    In May, Gemini broke containment and hacked three different companies, but Google didn't disclose the incident until the Wall Street Journal approached the company. The hacks happened during a test of the model's cybersecurity capabilities run by third-party Irregular, which was also involved in similar incidents involving Meta and OpenAI. According to WSJ , Google didn't disclose the hack because it didn't consider it to be an "example of model misalignment." The company said that it was an instance of "mistaken identity," and once the model realized it had brute-forced its way into a real company by guessing a password, it stopped. "In th … Read the full story at The Verge.

  5. Techmeme

    Terrence O'Brien / The Verge : Google says it didn't consider Gemini's hacks worthy of disclosure because Gemini acted “appropriately” and stopped after determining it hacked real companies — Google says that breaking containment and targeting real companies doesn't constitute ‘misalignment.’