{"id":9558,"date":"2026-09-22T01:02:19","date_gmt":"2026-09-22T01:02:19","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9558"},"modified":"2026-09-22T01:02:19","modified_gmt":"2026-09-22T01:02:19","slug":"gemini-broke-into-3-companies-but-google-kept-it-quiet-because-no-damage-was-done","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9558","title":{"rendered":"Gemini broke into 3 companies, but Google kept it quiet because \u2018no damage was done\u2019"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">A Google Gemini AI agent broke into three companies in May, guessing the credentials for one and discovering the credentials for the second two in a public repository, Google confirmed on Monday.<\/p>\n<p class=\"wp-block-paragraph\">But the more interesting background to the story, which was <a href=\"https:\/\/www.wsj.com\/tech\/ai\/gemini-hacked-three-companies-in-first-known-breakout-by-googles-ai-5c0baba2?st=2MGqTc\" target=\"_blank\" rel=\"noopener\">broken by The Wall Street Journal<\/a> on Friday, is that the May incident stemmed from a series of cybersecurity tests performed by security research firm Irregular on behalf of four AI giants: Google, Anthropic, OpenAI and Meta. All four companies experienced agent misbehavior resulting in cybersecurity incidents, but of the four, only Google never publicly disclosed its agent\u2019s activities. Indeed, it didn\u2019t reveal the breaches at all until contacted by a WSJ reporter.<\/p>\n<p class=\"wp-block-paragraph\">Irregular <a href=\"https:\/\/www.irregular.com\/research\/addressing-recent-incidents-ongoing-findings-and-path-forward\" target=\"_blank\" rel=\"noopener\">described the incident<\/a> in August, around the same time as <a href=\"https:\/\/www.csoonline.com\/article\/4206116\/meta-joins-openai-anthropic-in-latest-ai-test-breach.html\" target=\"_blank\" rel=\"noopener\">Meta published<\/a> its version and <a href=\"https:\/\/www.csoonline.com\/article\/4205612\/openai-anthropic-ai-agents-resorted-to-deception-in-new-cybersecurity-incidents.html\" target=\"_blank\" rel=\"noopener\">Anthropic and OpenAI revealed theirs<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The Journal story noted, \u201cthe hacks occurred while the model was participating in a capture the flag exercise conducted on infrastructure belonging to Irregular to test the model\u2019s cybersecurity capabilities. It was tasked with retrieving information from software operated by a fictional company inside the testing environment. The fictional company shared the same name as a real company. Although the model wasn\u2019t intended to be able to get online, internet access was unintentionally made available, according to Irregular.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The three small companies whose systems were violated had, according to one source familiar with the testing, \u201calmost no [cybersecurity] infrastructure.\u201d In short, none of the three was in a position to put up much of a fight when the Gemini agent successfully broke in.<\/p>\n<p class=\"wp-block-paragraph\">According to a Google official, who asked to not be identified, the name of the public repository was similar to the name of the fake company. And within that repository were the names and credentials of the other two companies.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Most analysts and consultants focused not on the hacks themselves, but on the reasons Google gave for being silent on the successful attacks.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Google said that the agents stopped as soon as they realized the victim companies were real businesses. \u201cNo harm was caused,\u201d the Google source said. \u201cThere was not an issue of model misalignment.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The source confirmed the Wall Street Journal story, which said, \u201cGoogle compared the episode to a \u2018bug bounty\u2019 program in which hackers are rewarded for finding and reporting security vulnerabilities to their owners\u201d and then quoted Heather Adkins, Google\u2019s vice president of security engineering, saying, \u201cIn this case, the model acted appropriately.\u201d<\/p>\n<h2 class=\"wp-block-heading\"> Define \u2018harm\u2019<\/h2>\n<p class=\"wp-block-paragraph\">Analysts generally disagreed.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhat does Google define as harm? Is it the same as the target company? Downtime, unauthorized access, and exfiltration of data may not result in immediate harm, but could have lasting impacts,\u201d said <a href=\"https:\/\/my.idc.com\/getdoc.jsp?containerId=PRF005059\" target=\"_blank\" rel=\"noopener\">Ryan O\u2019Leary<\/a>, an IDC research director. \u201cThe comparison to a bug bounty program is tenuous at best. If I broke into Google HQ and took nothing and caused no harm, it is likely I would still be prosecuted for trespassing.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.gartner.com\/en\/experts\/nader-henein\" target=\"_blank\" rel=\"noopener\">Nader Henein<\/a>, a Gartner VP analyst, had a similar take on the situation.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf a member of my neighborhood watch broke into my house, walked around a little bit and then left, I\u2019m fairly certain the authorities would not classify it as an act of civic engagement,\u201d he said. \u201cIn this case, if the impacted sites had bug bounty programs and Google had programmed the agents to discover bugs, the rebuttal might make sense, otherwise it is quite a weak argument.\u201d<\/p>\n<p class=\"wp-block-paragraph\">That said, he added, \u201cGoogle does make an excellent point when they underlined \u2018the importance of training powerful AI models to act responsibly\u2019 and I look forward to seeing how Google plans to ensure that this doesn\u2019t happen again.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Inappropriate behavior<\/h2>\n<p class=\"wp-block-paragraph\">But <a href=\"https:\/\/www.forrester.com\/analyst-bio\/jeff-pollard\/BIO10584\" target=\"_blank\" rel=\"noopener\">Jeff Pollard<\/a>, VP\/principal analyst at Forrester, took exception to Google\u2019s assertion that the Gemini model had behaved appropriately.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe model pursued an authorized objective through an unauthorized path, crossed from a simulated environment into real companies and gained access without consent,\u201d he said. \u201cThis is another area where regulations haven\u2019t kept up with the pace of technology change. There are two sides to this: regulations with respect to the agentic escape and intrusion, and then the regulatory issues for the victim companies in terms of their requirements for disclosure. Google is only responsible for one half of that equation.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.infotech.com\/profiles\/erik-avakian\" target=\"_blank\" rel=\"noopener\">Erik Avakian<\/a>, technical counselor at Info-Tech Research Group, also noted that it\u2019s critical that companies have rules about when to disclose unexpected and problematic model behaviors.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cI don\u2019t think every unexpected thing an AI model does needs to become a public incident. But there should be a clear line once an autonomous system crosses an authorization or trust boundary,\u201d he said. \u201cIf an AI system leaves a controlled environment, accesses a real third-party production system, uses credentials, retrieves data, escalates privileges, or takes some other action that was never authorized, that should, at minimum, trigger disclosure to the affected organization along with a formal incident investigation.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Even if there was no damage from the intrusion, Avakian said, public disclosure should happen \u201cif the incident exposed a larger or repeatable problem with the controls around the model.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Independent technology consultant <a href=\"https:\/\/www.fisher-mns.com\/about\/\" target=\"_blank\" rel=\"noopener\">Steven Eric Fisher<\/a> also stressed that companies need to be strict and consistent about disclosing agent mishaps.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhat I find most puzzling about these incidents is not simply that an AI system crossed a boundary,\u201d he said. \u201cIt is the emerging posture around culpability once it does. Stopping after an authorization boundary has already been crossed is not the same thing as preventing the boundary from being crossed in the first place. I do not think \u2018the AI did it\u2019 can become an accountability boundary.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Control failure<\/h2>\n<p class=\"wp-block-paragraph\">And, argued <a href=\"https:\/\/acceligence.com\/talent\/profiles\/justin-greis\/\" target=\"_blank\" rel=\"noopener\">Justin Greis<\/a>, CEO of consulting firm Acceligence, the absence of harm and absence of significance are not necessarily the same thing.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cAn event can be consequential because of what it demonstrates about a system\u2019s capabilities or controls, even when everyone gets lucky and nobody is damaged,\u201d Greis said. \u201cGemini stopping itself after recognizing that it was inside a real company\u2019s environment is a positive safety signal. Gemini being able to get there in the first place is a control failure. Both things can be true at the same time.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/frankdickson\/\" target=\"_blank\" rel=\"noopener\">Frank Dickson<\/a>, principal analyst at Dickson Research, articulated the harshest criticism of Google.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe model\u2019s behavior is the least interesting part of this story. Google\u2019s conduct afterward is the most damning part,\u201d he said. \u201cThis isn\u2019t a story about Gemini going rogue. It\u2019s a story about one shared testing vendor\u2019s infrastructure mistake hitting four AI labs at once, and about Google being the slowest and least forthcoming of the four in telling anyone about its own copy of that failure.\u201d<\/p>\n<p class=\"wp-block-paragraph\">He pointed out, \u201cIrregular notified all four labs in late July. Google didn\u2019t go public until September 18, seven weeks later, and only after the Journal called for comment. Let\u2019s face it: that\u2019s not a company that judged that the incident didn\u2019t warrant disclosure. That\u2019s a company that watched three competitors take the reputational hit for the same underlying failure and waited to see if it could avoid its turn. It couldn\u2019t, and the only reason we know any of this is that a reporter asked.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A Google Gemini AI agent broke into three companies in May, guessing the credentials for one and discovering the credentials for the second two in a public repository, Google confirmed on Monday. But the more interesting background to the story, which was broken by The Wall Street Journal on Friday, is that the May incident [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9549,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9558","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9558"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9558"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9558\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9549"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9558"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9558"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9558"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}