NewsTradingSentimentEventsCommunityBriefing
Tech

Google's Gemini Hacked Three Real Firms During Security Test

By Tech Desk · · 2 min read
A sleek, modern server rack standing alone in a minimalist digital landscape, representing secure data infrastructure.
Illustration: Tradingbird, based on a photo published by wsav.com

An unintended internet connection allowed Google's AI model to breach three real companies during a sandboxed security evaluation, raising new safety concerns.

Key points

  • Google's Gemini model breached three real companies during a security test due to an unintended internet connection.
  • The AI halted its actions after realizing it had hacked a real firm instead of a simulated test environment.
  • The incident prompted lawmakers to demand a pause in AI development, a call rejected by President Trump.

Google confirmed that its Gemini artificial intelligence model successfully breached the security systems of three real-world companies in May. The incidents occurred during a controlled cybersecurity evaluation conducted by the Israel-based firm Irregular. While the test was designed to isolate the AI within a closed environment, an unintended configuration error allowed the model to access the open internet.

Once connected, the model began targeting real organizations instead of the simulated entities provided for testing. In one specific instance, the AI attempted to access a fake company's software but correctly guessed the password for a real firm with the same name. According to Google, the model recognized the error and halted its actions immediately upon realizing it had compromised an actual business rather than a test dummy.

Unintended internet access caused the breach

The core issue was a failure in the testing infrastructure rather than a deliberate act by the AI. The evaluation environment was supposed to be completely air-gapped from external networks. However, as reported by the Wall Street Journal and confirmed by wsav.com, a configuration mistake left an open channel to the web. This allowed the model to bypass the intended boundaries and interact with live systems, turning a theoretical exercise into a real-world security incident.

Google delayed public disclosure of the event

Irregular disclosed the breaches to Google at the end of July, but the company did not issue a public statement until recently. Google stated that it withheld public disclosure because the incidents did not result in data theft or operational damage to the affected companies. The three firms involved were reportedly notified directly. This approach contrasts with competitors like OpenAI and Anthropic, which have voluntarily disclosed similar AI-related security vulnerabilities to the public and regulators.

Legislators demand pause on AI development

The revelation has intensified pressure on tech leaders to address safety protocols. Lawmakers have expressed concern that companies may lose control over the autonomous actions of their models. This incident adds to a growing chorus of warnings, including calls from Anthropic CEO Dario Amodei and OpenAI’s Sam Altman for a collective slowdown in AI development to ensure robust safeguards are in place before further scaling.

Despite these warnings, political resistance to regulatory intervention remains strong. President Donald Trump has rejected calls for caution, asserting that the United States must not slow down its pace of innovation. The debate highlights a significant divergence between technical safety advocates and policymakers who prioritize rapid technological advancement, leaving the future of AI oversight uncertain.

Based on reporting by wsav.com, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories