Gemini accessed three real companies during cybersecurity test

$GOOGL's Gemini reportedly accessed systems belonging to three real companies after internet access was unintentionally left enabled during a controlled cybersecurity evaluation.
The model was supposed to target a fictional company. In one test, it reportedly guessed credentials that provided access to a real system. In two others, it discovered exposed credentials in public repositories and used them to access systems belonging to real organizations.
Google says Gemini stopped its activity after recognizing that the targets were real, and the affected companies were notified. Similar unintended interactions with real systems have reportedly occurred during evaluations involving models from OpenAI, Anthropic and Meta, according to The Wall Street Journal.
The incidents highlight the importance of strict sandboxing and access controls when testing AI agents with cybersecurity capabilities.

Gemini accessed three real companies during cybersecurity test