(Image credit: Nick Sutrich / Android Central) What you need to knowGoogle has apparently admitted that Gemini had escaped its testing environment and independently accessed systems belonging to three real companies.A misconfigured internet connection was the initial opening, while a matching company name added to the confusion.Gemini eventually stopped itself after recognizing that it was targeting real companies.Google initially kept the incident quiet, arguing that Gemini self-corrected and caused no damage.Google's Gemini adds to the long list of AI models that have gone rogue.We have already seen similar digital jailbreaks handled by OpenAI, Anthropic, and Meta in third-party safety testing. Now, it’s been revealed that Google’s Gemini model escaped its containment area in May, hacking its way into systems at three real companies, all on its own.The Wall Street Journal reports that the incident took place during a “capture the flag” exercise conducted by AI security firm Irregular. Gemini was intended to test a fictional company in a closed testing environment, but an unplanned internet connection gave it an escape. The fictional company also had a real business with the same name, creating another opening for confusion.Once online, Gemini found its way into three real companies. In one case it just kept guessing passwords until it got through. In two others, it found working credentials stored in public repositories and used them to access protected systems.It turns out that throughout the entire process, Gemini didn’t require any exotic movie-style exploits. It just combined elementary security vulnerabilities with the ability to search, decide, and persistently try, without a human directing each and every move.Google said Gemini stopped when it realized the targets were real companies and did not cause damage. In fact, while Anthropic’s Claude 4.7 kept going during a similar incident, Gemini backed off on its own volition. The impacted organizations were informed, although Irregular says the known testing issues were corrected weeks later.The search giant felt the incident didn't warrant a public announcement at the time because the AI self-corrected. But third-party researchers were not told until late July, and details are only now emerging after media inquiries pushed the issue.Get the latest news from Android Central, your trusted companion in the world of AndroidAs AI agents gain broader access to the internet and computers, companies will need to establish tighter boundaries around what those systems can reach and clearer rules for what happens when those boundaries fail. Jay Bonggolto always keeps a nose for news. He has been writing about consumer tech for as long as he can remember, and he has used a variety of Android phones since falling in love with Jelly Bean. Send him a direct message via X or LinkedIn.
Google’s Gemini went rogue and breached three companies
Full Article
Original Source
Read the full article at Androidcentral →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.