Subscribe Sign in

Google’s Gemini is the latest AI model to hack other companies

TechCrunch
1 min read Rewritten in plain language

Artificial intelligenceSecurityGoogleGeminiAlphabet

Show what we removed Rules applied: A3×2 D1 F2 all 30 rules
  • Google’s Gemini accessed the protected systems of three other companies in what The Wall Street Journal reports were the AI model’s first autonomous hacks.
  • In one case, Gemini guessed passwords until it gained access; in the other two, it found credentials in a public repository.
  • Google said it hadn’t previously revealed the hacks because Gemini had “acted appropriately” by ending each breach as soon as it determined it had hacked a real company.

3 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Headline check

The one thing this headline claims is in the report.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. One claim in this headline could be checked, so this is a narrow pass and not a thorough one. How this is checked

Manns' superior seeds (15767599714) library picture
Not from this story. A library photograph of stock market trading screens, used to illustrate it. Manns' superior seeds (15767599714) Henry G. Gilbert Nursery and Seed Trade Catalog Collection.; J. Manns & Co. / Wikimedia Commons, CC BY

Google’s Gemini accessed the protected systems of three other companies in what The Wall Street Journal reports were the AI model’s first autonomous hacks.

Similar to OpenAI’s breach of Hugging Face, the Gemini hacks were less noteworthy for being sophisticated and more for the fact that they were conducted by an AI model. These breaches took place during cybersecurity testing by a company called Irregular. In one case, Gemini guessed passwords until it gained access; in the other two, it found credentials in a public repository.

Irregular reportedly notified Google about the hacks in late July, but the companies did not confirm them publicly until Friday, after the WSJ reached out. Google said it hadn’t previously revealed the hacks because Gemini had “acted appropriately” by ending each breach as soon as it determined it had hacked a real company.

However, Jack Cable, the CEO of AI security company Corridor, told the WSJ that Google was “trying to hide behind the norms that have been created for vulnerability disclosure,” rather than acknowledging that “models are going outside the bounds of what they should be doing, and doing actual cyberattacks.”

You are reading our version, not theirs. This is TechCrunch's report with its verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
TechCrunchas they published this story 9.8 2 39 0.1 50
Mundane Readneutralized from TechCrunch 7.7 2 39 0.1 50

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works