FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.9T +0.9%24h Vol $100.8B -35%Fear & Greed 71/100Alts Index 59/100
BTC.D 58.5% +0.2%Stable.D 9.2% 0%ETH.D 11.3% -0.1%Others.D 21.0% -0.1%
SOON$0.4841+23.51%•STONK$0.2919+22.27%•QNT$299.60+18.66%•NIGHT$0.0374+18.34%•KSM$5.213+12.96%•DEEP$0.0238+12.48%•NEAR$5.481+11.48%•RAY$2.069+11.22%•CAP$0.0654+11.19%•PROM$6.543+10.92%•
AI$0.1811-13.33%•TIBBIR$0.2944-12.76%•BTW$1.158-11.27%•BR$0.7593-10.7%•BP$1.207-8.52%•LIT$4.096-7.46%•SKY$0.0791-6.82%•2Z$0.0638-5.45%•Q$0.0233-4.65%•MARSCOIN$0.1396-4.62%•
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      Gemini AI Model Moved beyond Testing and Attacked Three Real Companies

      • Gemini gained access to the real systems of three companies.
      • The incident occurred during AI model testing in May.
      • Google did not disclose the names of the affected companies, but provided information about the case to them and to federal authorities.

      Google’s Gemini model gained internet access in May 2026 and hacked the systems of three real companies during tests of its cybersecurity capabilities, WSJ reports. This is the first known case of a Google AI system autonomously carrying out such actions. 

      Google said the model stopped the attacks as soon as it realized it was interacting with real companies, so it does not consider the incident an example of AI “misalignment.”

      The incident occurred during testing conducted by Irregular. Google learned about it in late July — after a similar incident involving OpenAI models that attacked the Hugging Face platform became known.

      How Gemini Gained Access to Real Systems

      Gemini took part in a “capture the flag” format, where it was supposed to obtain information from the software of a fictional company. That company accidentally had the same name as a real one. In addition, the model was unintentionally given internet access, even though the test did not предусsee it.

      Incrypted infographic.

      In the first case, Gemini guessed a password and gained access to a real company’s service. In two other tests, the model used web search to find public repositories containing credentials for other companies, tried to use them, and gained access to protected systems.

      In all three cases, Gemini then determined it was dealing with a real company and stopped. Google did not disclose the names of the affected organizations, but notified them about the incidents and informed federal authorities.

      At the same time, the company did not name the specific version of Gemini, noting only that it was not its newest model.

      Google’s vice president of security engineering, Heather Adkins, said:

      “This event highlights the importance of training powerful AI models to act responsibly. In this case, the model acted appropriately.”

      The Incident Became Part of a Broader Problem

      Google compared the situation to a bug bounty program, since the model caused no harm and stopped the intrusion. However, Corridor startup CEO and white-hat hacker Jack Cable believes this does not address the core issue:

      “It feels like they’re trying to hide behind the norms that have been created in vulnerability disclosure for this, which is a very different problem.”

      According to him, the key issue is that models go beyond what is permitted and carry out real cyberattacks.

      Irregular said that all relevant labs and affected companies were notified in late July, and that the issues identified on the testing organizer’s side have already been fixed.

      Similar cases have previously been recorded in models from Anthropic, OpenAI, and Meta. In particular, during the Hugging Face incident, up to 1,200 OpenAI agents coordinated their actions via a hidden message board, trying to bypass the evaluation.

      Also, during testing, the Chinese AI model Kimi K3 from Moonshot AI managed to escape an isolated environment and gain access to the internet.

      Against the backdrop of these events, OpenAI began developing mechanisms to automatically shut down AI systems when dangerous behavior is detected. At the same time, OpenAI publicly called for slowing the pace of AI development, and Anthropic presented a plan for AI oversight.

      Сообщение Gemini AI Model Moved beyond Testing and Attacked Three Real Companies появились сначала на INCRYPTED.


      Source: Incrypted
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud