{"id":30188,"date":"2026-09-19T09:09:07","date_gmt":"2026-09-19T06:09:07","guid":{"rendered":"https:\/\/ukrmedia.news\/?p=30188"},"modified":"2026-09-19T09:09:07","modified_gmt":"2026-09-19T06:09:07","slug":"gemini-accessed-three-company-systems","status":"publish","type":"post","link":"https:\/\/ukrmedia.news\/en\/science-tech\/gemini-accessed-three-company-systems\/","title":{"rendered":"Gemini went beyond the scope of the test and hacked three companies"},"content":{"rendered":"<p class=\"news-lead\">In May, during independent testing of its cybersecurity capabilities, Google\u2019s Gemini artificial intelligence gained access to the systems of three real-world companies. The test was conducted by Irregular. The model mistakenly identified third-party resources as part of the authorised environment and ceased further actions once it had gained access. Google notified the organisations affected by the incident and reviewed its testing procedures.<\/p>\n<div class=\"news-summary-box\">\n<p><strong>Briefly about the main points<\/strong><\/p>\n<ul>\n<li>During testing, Gemini inadvertently went beyond the boundaries of the test infrastructure.<\/li>\n<li>The model collected account details in a single instance.<\/li>\n<li>On two further occasions, she used keys from open repositories.<\/li>\n<li>After logging in, Gemini did not continue to interact with the live systems.<\/li>\n<li>Google and Irregular have changed their procedures for future audits.<\/li>\n<\/ul>\n<\/div>\n<h2>How the model got the task boundaries wrong<\/h2>\n<p>As part of a standard task, Gemini was required to search for vulnerabilities in the infrastructure it deemed permissible to test. The model had access to the internet, found information about real-world resources and incorporated them into the test environment.<\/p>\n<p>According to *The Wall Street Journal*, in one episode <a href=\"https:\/\/ukrmedia.news\/en\/science-tech\/gemini-studentam-ukrainy-bezkoshtovno\/\">Gemini<\/a> He tried various login credentials until he gained access to the restricted system. In the other two cases, he found login credentials in publicly accessible online repositories and used them to access secure resources.<\/p>\n<p>These actions were not a sophisticated cyberattack, but they demonstrated the model\u2019s ability to independently combine several steps to gain access. After gaining access in all instances, Gemini stopped; according to the WSJ, the model realised it was in a real system rather than a simulated one.<\/p>\n<h2>Google has confirmed the incident and reviewed its checks<\/h2>\n<p>Google\u2019s Vice President of Security Engineering <strong>Heather Adkins<\/strong> confirmed the incident. According to her, Gemini used publicly available information and attempted to access websites it believed to be part of an authorised test.<\/p>\n<p>Google notified the organisations affected by the error and, in collaboration with Irregular, amended the procedures for future audits. Reuters described this as the first known instance in which Google\u2019s AI system had autonomously exceeded the scope of a test involving third-party companies.<\/p>\n<h2>Similar issues were also identified during tests on other models<\/h2>\n<p>Irregular stated that similar situations had arisen during audits of other AI companies\u2019 systems. Meta, Anthropic and <a href=\"https:\/\/ukrmedia.news\/en\/science-tech\/shi-diyav-bez-dozvolu-openai\/\">OpenAI<\/a>, although these cases should not be confused with the Gemini incident.<\/p>\n<p>The company stated that, at the end of July, it had notified the laboratories that might have been affected by the issue and had rectified the known vulnerabilities in the testing process. Meta, commenting on one of its incidents in August, emphasised that this was neither a case of a model escaping from a secure sandbox environment nor a sophisticated, targeted cyberattack.<\/p>\n<h2>The risk of misinterpretation for autonomous AI agents<\/h2>\n<p>Modern models can be granted access to a browser, the command line, software tools and external systems so that they can carry out multi-step tasks. In such circumstances, the problem may lie not only in the deliberate use of AI for cyberattacks, but also in the system\u2019s misinterpretation of the limits of permissible action.<\/p>\n<p>According to Google, Gemini was not instructed to attack real companies, but misinterpreted the task it had been given. Adkins linked the findings from the incident to the need to train more powerful models responsibly, particularly when they are given access to the internet and real computer systems.<\/p>","protected":false},"excerpt":{"rendered":"<p>During a security test, Gemini gained access to the systems of three companies, mistakenly believing them to be part of the authorised environment.<\/p>","protected":false},"author":207433404,"featured_media":30187,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rank_math_description":"Gemini \u043f\u0456\u0434 \u0447\u0430\u0441 \u0442\u0435\u0441\u0442\u0443 \u0431\u0435\u0437\u043f\u0435\u043a\u0438 \u043e\u0442\u0440\u0438\u043c\u0430\u0432 \u0434\u043e\u0441\u0442\u0443\u043f \u0434\u043e \u0441\u0438\u0441\u0442\u0435\u043c \u0442\u0440\u044c\u043e\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0456\u0439, \u043f\u043e\u043c\u0438\u043b\u043a\u043e\u0432\u043e \u0432\u0432\u0430\u0436\u0430\u044e\u0447\u0438 \u0457\u0445 \u0447\u0430\u0441\u0442\u0438\u043d\u043e\u044e \u0434\u043e\u0437\u0432\u043e\u043b\u0435\u043d\u043e\u0433\u043e \u0441\u0435\u0440\u0435\u0434\u043e\u0432\u0438\u0449\u0430.","rank_math_title":"Gemini \u0437\u043b\u0430\u043c\u0430\u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0438 \u0442\u0440\u044c\u043e\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0456\u0439 \u043f\u0456\u0434 \u0447\u0430\u0441 \u0442\u0435\u0441\u0442\u0443","rank_math_focus_keyword":"Gemini","td_subtitle":"","subtitle":"","footnotes":""},"categories":[805620],"tags":[806764],"class_list":["post-30188","post","type-post","status-publish","format-standard","has-post-thumbnail","category-science-tech","tag-806764"],"_links":{"self":[{"href":"https:\/\/ukrmedia.news\/en\/wp-json\/wp\/v2\/posts\/30188","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ukrmedia.news\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ukrmedia.news\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ukrmedia.news\/en\/wp-json\/wp\/v2\/users\/207433404"}],"replies":[{"embeddable":true,"href":"https:\/\/ukrmedia.news\/en\/wp-json\/wp\/v2\/comments?post=30188"}],"version-history":[{"count":1,"href":"https:\/\/ukrmedia.news\/en\/wp-json\/wp\/v2\/posts\/30188\/revisions"}],"predecessor-version":[{"id":30189,"href":"https:\/\/ukrmedia.news\/en\/wp-json\/wp\/v2\/posts\/30188\/revisions\/30189"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ukrmedia.news\/en\/wp-json\/wp\/v2\/media\/30187"}],"wp:attachment":[{"href":"https:\/\/ukrmedia.news\/en\/wp-json\/wp\/v2\/media?parent=30188"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ukrmedia.news\/en\/wp-json\/wp\/v2\/categories?post=30188"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ukrmedia.news\/en\/wp-json\/wp\/v2\/tags?post=30188"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}