Google Gemini autonomously hacked three companies during cybersecurity test

636     0
Google Gemini autonomously hacked three companies during cybersecurity test
Google Gemini autonomously hacked three companies during cybersecurity test

Google’s Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the company’s AI systems autonomously committing such an act.

The hacks occurred in May during a cybersecurity test conducted by Irregular, an independent company that conducts cybersecurity evaluations.

During a standard testing evaluation, Gemini found public information online and guessed credentials to access three websites it thought were within the scope of its test, Heather Adkins, Google’s vice president of security engineering, said in a statement.

“We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes,” Adkins said. “These events highlight the importance of training powerful AI models to act responsibly.”

An Irregular spokesperson said the incident involved the same issue that affected other AI labs and that all relevant labs were notified in late July. “All known issues on our end were remedied and resolved weeks ago,” the spokesperson said.

Similar incidents linked to Irregular were disclosed by Meta, Anthropic and OpenAI. Meta said in August the incident did not involve a sandbox escape or sophisticated cyberattack, while Irregular said it was working on best practices for securely conducting AI cybersecurity evaluations.

The incidents have raised questions about the safeguards needed as AI agents gain greater autonomy and access to the internet and computer systems.

In one of the cases, the Gemini model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems, according to the Wall Street Journal, which first reported the news on Friday.

Adkins said that in all three instances, the model ceased its hacking.

Editorial Team

Emma Davis

Deputy Editor

OpenAI, Anthropic, Meta, Hacking, Cyberattacks, Cybersecurity, AI, Artificial Intelligence, Alphabet

Read more similar news:

16.02.2023, 12:46 • Crime
'I was sent creepy Airdrop requests on a train - simple fix isn't the answer'
19.03.2023, 01:44 • News
Urgent phishing warning issued to anybody who uses Gmail or Microsoft Outlook
04.04.2023, 17:00 • Politics
UK far-right launch wave of transgender web hate in wake of Nashville shootings
18.04.2023, 23:01 • Crime
Russian hackers 'trying to black out Britain' by targeting power stations
07.06.2023, 10:09 • Crime
Russian hackers in ultimatum to Brits working at Boots, BBC and British Airways
18.07.2023, 14:23 • Crime
Hang up the phone immediately if you hear these 4 clues, security expert says
13.08.2023, 08:00 • Tech
Parents share top 10 rules they set to make sure their child is safe online
02.09.2023, 20:09 • World
Russia linked hackers hit UK Ministry of Defence as security secrets leaked
16.09.2023, 12:47 • News
Major cyber attacks on Las Vegas casinos making slot and ATM machines unusable
02.10.2023, 13:51 • Tech
Top 30 technical terms that leave over-65s baffled - including smishing and URL