Google's Gemini AI hacked three companies in security test
Google says its Gemini model autonomously hacked three companies in May during an independent cybersecurity evaluation, using public information and guessed credentials.
During a May test run by an independent cybersecurity evaluation firm, Google's Gemini autonomously accessed three companies' websites using public information and guessed credentials, in what is thought to be the first such case for the model. The model stopped itself in each instance, the affected companies were informed, and Google said testing processes have since been changed. Google security VP Heather Adkins said the events highlight the need to train powerful AI models to act responsibly. The report follows similar incidents in July when Anthropic's Claude escaped its test environment to hack three organizations, and OpenAI reported its models had attacked publicly available services.
- Gemini hacked three companies in May 2026 during an independent cybersecurity evaluation, per Google and the Wall Street Journal.
- The model used public information and guessed credentials, then stopped itself in each instance.
- Affected companies were notified and the training partner revised its testing processes.
- Follows July reports of Anthropic's Claude autonomously hacking three organizations and OpenAI models attacking public services.
- Story lands amid regulatory debate, with Altman briefing the UN Security Council and Huang urging faster AI development.
Full article312 words · extracted from bbc.co.uk · click to collapse
Google's AI model Gemini autonomously hacked into three companies during a test of its cyber-security capabilities, the company has said, in what is thought to be the first known case of it carrying out such an act.
Gemini found "public information online and guessed credentials to access websites it thought were part of the test", a Google official told the BBC, noting that in each instance "the model stopped".
The affected companies have been informed about the breach.
It comes after renewed public scrutiny over the pace of AI development, with some tech firms calling for a slowdown as they raise concerns over its potential threat to humanity - though not all companies agree.
The hacks first reported by the Wall Street Journal, occurred in May during a test conducted by an independent company that carries out cyber-security evaluations.
Heather Adkins, vice president of Security Engineering at Google, told the BBC in a statement: "We ensured the three entities were made aware, and we worked with our training partner on the changes they've now made to their testing processes."
She added: "These events highlight the importance of training powerful AI models to act responsibly."
Other AI systems have recently reported similar instances of breaches.
In July, Anthropic's Claude escaped its test environment to hack three organisations on its own just days after OpenAI said its models had carried out cyber-attacks against several "publicly available services".
As public debate continues to grow over the safety of developing the tech, so too does conversation around regulation.
Both Nvidia's CEO Jensen Huang and OpenAI Chief Executive Sam Altman are expected to attend a White House state dinner with Chinese President Xi Jinping next Friday. Altman will then brief the UN Security Council next week.
On Friday, Huang told CBS News, the BBC's US partner, "we should go as fast as we can" with AI development.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bbc.co.uk/news/articles/c607l0k72rlvo