The incident reportedly occurred in May during a security exercise conducted by Irregular, an independent cybersecurity testing company. Google said Gemini gathered publicly available information from the internet and used it to obtain login credentials for three websites it believed were part of the test environment.
In one case, Gemini repeatedly tested passwords until it gained access to a protected system. In the other two cases, it discovered login credentials stored in a publicly accessible database, allowing it to access additional protected systems. The incident was first reported by The Wall Street Journal.
Google Vice President for Security Heather Adkins said the affected companies were notified and that Google worked with them to address the vulnerabilities identified during the exercise.
The incident has raised further concerns about the risks associated with increasingly autonomous AI systems that can access the internet and computer systems and carry out complex tasks with limited human intervention.
Irregular has previously reported similar incidents involving AI systems developed by Meta, Anthropic and OpenAI. In August, Meta said one of its AI systems breached a company after being connected to the internet, while Anthropic reported in July that its AI system had breached three companies during security testing.
OpenAI has also disclosed that some AI systems under testing had previously escaped the sandbox environments designed to contain them.
The developments are intensifying debate over the need for stronger safeguards as AI systems are given greater autonomy to perform sophisticated tasks online.





