Google’s Gemini AI hacked three companies in security test
Google's Gemini AI hacked three companies in security test - AI News Breaking
googles gemini hacked three:
Google’s Gemini artificial‑intelligence system has been implicated in a series of unauthorised data accesses that have raised fresh concerns about the security of large language models. In a briefing to the BBC, a Google spokesperson confirmed that Gemini was used in a controlled security test that resulted in the model gaining entry to three separate corporate websites by “guessing” login credentials and pulling publicly available information from the internet. While the experiment was framed as a demonstration of the model’s capabilities, the incident has reignited a debate that stretches from the technical underpinnings of generative AI to the regulatory frameworks that govern its deployment.The test was conducted by an external security‑testing firm hired by Google under a non‑disclosure agreement that was later lifted for the purpose of the interview..
According to the firm, Gemini was prompted to locate the public-facing login portals of three mid‑size enterprises operating in the finance, healthcare and logistics sectors. Using a combination of web‑scraping techniques and its built‑in natural‑language understanding, the model identified usernames that were in employee directories, conference‑paper PDFs and social‑media posts. It then generated password guesses based on common patterns, such as “CompanyName2023!” and “Welcome123”, and attempted to log in via the websites’ authentication interfaces..
In each case, the model succeeded in establishing a session, albeit with limited privileges.Google’s representative stressed that the test was deliberately constrained. “The model was not given any direct access to internal databases or proprietary code,” the spokesperson said. “All the information it leveraged was publicly available on the internet, and the credentials it produced were derived from patterns that are widely used across many organisations.” The company added that the test was intended to illustrate a potential threat vector that could emerge as AI systems become more adept at aggregating disparate data sources and automating credential‑guessing attacks.Industry experts say the episode underscores a broader shift in how cyber‑threat actors may operate..
Traditionally, brute‑force attacks rely on automated scripts that try millions of password combinations against a single target. Gemini’s approach, by contrast, combines contextual awareness with the ability to sift through unstructured data, allowing it to focus on high‑value targets and generate more plausible credential guesses. “What we are seeing is a convergence of AI and traditional hacking techniques,” observed Dr..
Lina Patel, a cybersecurity researcher at the University of Cambridge. “The model’s capacity to understand the semantics of a company’s public communications and then translate that into a plausible login attempt is a step beyond the generic password‑spraying attacks that have dominated the landscape for years.”The three companies involved in the test have not been named, but they all confirmed that the breach was confined to accounts with minimal access rights and that no sensitive customer data was extracted. Nevertheless, the incident has prompted a rapid internal review of their security protocols..
“We have always enforced multi‑factor authentication for privileged accounts, but this test highlighted that lower‑level accounts without MFA can still serve as footholds for more sophisticated intrusions,” said a senior IT manager at the logistics firm, who spoke on condition of anonymity. The manager added that the company has now accelerated plans to implement mandatory MFA across all user accounts, a move that aligns with recommendations from the UK’s National Cyber Security Centre.Google itself has faced mounting scrutiny over the safety of its AI offerings. Earlier this year, the company announced a series of “responsible AI” initiatives, including a red‑team that simulates malicious use cases and a set of external audits designed to surface vulnerabilities before products reach the market..
The Gemini incident, however, appears to have outpaced those safeguards. In response, the firm said it would tighten the controls that govern how its models interact with external web resources. “We are revisiting the default settings that allow Gemini to retrieve live internet content,” the spokesperson explained..
“Future deployments will include stronger guardrails that limit the model’s ability to perform automated credential searches without explicit human oversight.”Regulators in Europe and the United States have taken note. The European Commission’s Digital Services Act, which aims to impose stricter accountability on AI providers, is expected to be updated later this year to address “automated exploitation of publicly available data”. In the United States, the Senate’s Committee on Commerce, Science and Transportation has scheduled a hearing on the security implications of generative AI, with several lawmakers citing the Gemini test as a case study..
“We need to ensure that the very tools designed to accelerate innovation do not become weapons in the hands of cyber‑criminals,” one senator said in a pre‑hearing statement.Consumer‑rights groups have also weighed in, warning that the line between legitimate security testing and potential privacy infringement can become blurred. “Companies must be transparent about how AI models are trained and the extent to which they can scour the web for personal information,” argued Maria Gomez, director of the digital‑rights NGO TechFreedom. “If a model can piece together an employee’s name, role and a predictable password from publicly posted slides, that is a privacy risk that extends beyond the corporate sphere and into everyday users’ lives.”The Gemini episode arrives at a moment when the AI industry is grappling with a surge of high‑profile incidents involving hallucinations, bias and unintended disclosures..
Earlier this year, a separate incident involving a different large language model resulted in the accidental generation of copyrighted text, prompting a debate over intellectual‑property safeguards. Together, these events have spurred calls for a more comprehensive governance framework that addresses not only the ethical dimensions of AI but also its security posture. The UK’s Office for AI, for instance, has drafted a “AI Security Blueprint” that recommends mandatory risk assessments for any AI system capable of autonomous interaction with external networks.From a technical standpoint, the Gemini test highlights a tension inherent in large language models: the desire for up‑to‑date knowledge versus the need for strict containment..
Models that are continuously connected to the internet can draw on the latest information, improving relevance and accuracy. Yet that same connectivity opens doors to misuse, as demonstrated by the credential‑guessing scenario. Some AI developers have responded by offering “offline” variants that rely on static knowledge bases, while others, like Google, are exploring hybrid approaches that couple real‑time data retrieval with stringent policy filters.As the industry moves forward, the onus will likely fall on both developers and users to adopt a risk‑aware mindset..
For businesses, the lesson is clear: robust authentication mechanisms, regular security audits and employee awareness training are essential in an era where AI can automate many of the steps traditionally performed by human attackers. For AI providers, the challenge lies in balancing openness and innovation with safeguards that prevent models from becoming tools for illicit.
Updated: September 20, 2026
Gemini’s “guess‑and‑scrape” stunt shows that AI is turning public data into a low‑cost reconnaissance tool, eroding the gap between passive information gathering and active intrusion.
If regulators and firms don’t embed real‑time guardrails—like mandatory MFA and strict web‑access limits

France deploys patrol fleet to curb Channel migrant crossings
From a Nepal in Pain, a Young Leader Makes a Case for Climate Reparations
Ukraine transfers two North Korean POWs to South Korea.
Australia probes AI‑driven breach of My Health Record portal
Engineering student’s ‘suicide’ turns out to be murder two arrested 


