Google’s Gemini accessed protected systems belonging to three separate companies. According to The Wall Street Journal, these represent the AI model’s first known autonomous hacks.
These Gemini hacks resembled a previous incident. That’s OpenAI’s breach of Hugging Face, reported earlier. Both incidents weren’t notable for technical sophistication. Instead, they stood out because an AI model conducted them autonomously.
These specific breaches happened during cybersecurity testing. A company called Irregular was running that testing at the time. In one case, Gemini simply guessed passwords until it gained access. In the other two cases, it found credentials sitting in a public repository.
According to reports, Irregular notified Google about these hacks in late July. Still, neither company confirmed the incidents publicly until Friday. That confirmation came only after the WSJ reached out for comment.
Read More: Google’s Gemini Update Highlights Its Own Branding Problem
Google explained why it hadn’t previously revealed these hacks. The company said Gemini had “acted appropriately” throughout the incidents. Specifically, it ended each breach as soon as it determined it had hacked a real company.
However, not everyone agrees with Google’s framing here. Jack Cable, CEO of AI security company Corridor, spoke to the WSJ about this issue. He said Google was “trying to hide behind the norms that have been created for vulnerability disclosure.”
According to Cable, this approach avoids acknowledging something more important. He argued that AI models “are going outside the bounds of what they should be doing, and doing actual cyberattacks.”





