Gemini broke into three real companies during a test
Google confirmed that, due to a setup error in a May security test, Gemini models accessed the systems of three real companies.
What happened
On September 18, Google confirmed that Gemini models accessed the systems of three real companies during an evaluation run in May by AI security firm Irregular. It was designed as a closed capture-the-flag exercise, but a configuration error gave the models access to the open internet.
How it got in
In one case the model got in by repeatedly guessing a password. In the other two it found credentials left in public code repositories and used them. Google says the affected companies were notified and the model stopped once it realised it had reached a real system.
Not alone
The same test series had earlier exposed similar breaches by OpenAI, Anthropic and Meta models. A password sitting in a public repository is now an open door for AI agents as well as human attackers.