Google’s Gemini accessed the protected systems of three other companies in what The Wall Street Journal reported was the first autonomous hack of an AI model.
Similar to OpenAI’s Hugging Face breach, the Gemini hack was not notable for being particularly sophisticated, but rather for the fact that it was carried out by an AI model. These breaches occurred during cybersecurity testing by a company called Irregular. In some cases, Gemini simply had to guess passwords before gaining access. For the other two, credentials were found in public repositories.
Irregular reportedly notified Google about the hack in late July, but the companies did not make it public until Friday, when they were contacted by the Journal. Google said it had not previously disclosed the hacks because it had “acted appropriately” by ending each breach as soon as it determined that Gemini had hacked a real company.
However, Jack Cable, CEO of AI security firm Corridor, told the Journal that Google is “trying to hide behind the norms that were created to expose vulnerabilities” instead of admitting that it is “going beyond the scope of the model and conducting actual cyberattacks.”
