Gemini hacked three companies in first known breakout by Google's AI, WSJ reports

FILE PHOTO: Gemini app icon in this illustration taken June 5, 2026.

FILE PHOTO: Gemini app icon in this illustration taken June 5, 2026. (REUTERS/Dado Ruvic/Illustration//File Photo)


1 photo
Save Story

Estimated read time: 1-2 minutes

Sept 18 — Google's Gemini model accessed the internet and hacked other ​companies during a test of its cybersecurity capabilities, the first known example of the company's AI systems ‌autonomously committing such an act, the Wall Street Journal reported on Friday.

The ⁠hacks occurred in May ​during a cybersecurity test ⁠conducted by Irregular, an independent company that conducts cybersecurity ‌evaluations, according to ‌the report.

An Irregular spokesperson said the incident involved ⁠the same issue that affected ⁠other AI labs and that all relevant labs were notified in late July. "All known issues on our end were remedied and resolved weeks ago," the spokesperson said.

Google did not immediately respond to Reuters request ‌for comment.

Similar incidents linked to Irregular ​were disclosed by Meta, Anthropic and OpenAI. Meta said in August the incident did not involve a sandbox escape or sophisticated cyberattack, while Irregular said it was working on best practices for securely conducting AI cybersecurity evaluations.

The incidents have raised questions about the safeguards ​needed as AI agents gain greater autonomy and access ‌to the internet ‌and ⁠computer systems.

In one of the cases, the Gemini model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials ‌in a public repository ​that allowed it to then ‌access protected systems, ⁠the WSJ ​report said.

(Reporting by Harshita Mary Varghese in Bengaluru; Editing by ​Arun Koyyur)

Photos

Most recent Business stories

Related topics

Reuters
    KSL.com Beyond Series
    KSL.com Beyond Business

    KSL Weather Forecast

    KSL Weather Forecast
    Play button