Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Artificial Intelligence - Gemini crosses the line in cybersecurity test
Artificial Intelligence Emerging Threats Latest News News & Analysis Threat Intelligence Threats and Vulnerabilities

Gemini crosses the line in cybersecurity test

Kirsten DoyleBy Kirsten DoyleSeptember 22, 20267 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Gemini crosses the line
Share
Facebook Twitter LinkedIn Email Copy Link
TL;DR (AI Generated)

Google has confirmed that its Gemini AI accessed systems belonging to three companies during a cybersecurity evaluation after mistaking them for targets included in the test.

The Wall Street Journal reported that Gemini had unintended internet access during the exercise and went on to access systems belonging to three companies.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity at Suzu Labs, said: “Google just joined Anthropic, OpenAI, and Meta in admitting that a model it was running logged into other people's systems during a cybersecurity evaluation.

Basic summary
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Google has confirmed that its Gemini AI accessed systems belonging to three companies during a cybersecurity evaluation after mistaking them for targets included in the test.

The incidents happened in May while independent AI evaluator Irregular was testing Gemini’s cybersecurity capabilities. The Wall Street Journal reported that Gemini had unintended internet access during the exercise and went on to access systems belonging to three companies. In one case, it guessed credentials. In the other two, it found credentials in public repositories and used them to access protected systems.

Google said the incidents were a case of mistaken identity and that Gemini stopped after recognising it had reached real companies. The company said it did not consider the behaviour evidence of model misalignment and had notified the affected companies and federal authorities.

Google vice president of security engineering Heather Adkins also confirmed the incidents to Reuters, saying the company had made sure the three organisations were informed and had worked with its testing partner to change the evaluation process. “These events highlight the importance of training powerful AI models to act responsibly,” she said. Reuters also reported that Google said Gemini stopped its hacking behavior in all three cases.

The incidents follow similar cases involving OpenAI and Anthropic models during cybersecurity testing. In each case, an AI system carrying out an authorised security task reached systems that were not supposed to be part of the exercise.

A harder question

Neena Sharma, Cybersecurity Specialist at Filigran, said: “Every reported incident should now raise a harder question: how many more are happening right now, undetected? Security teams need collective analysis of these patterns to understand what might be coming their way. Organisations should stop assuming their defenses work and start to proactively test it, as a top priority.”

Filigran’s Senior Solution Engineering Manager Damian Skeeles added: “Google and Deepmind have been a bit busy to-date in solving real problems for humanity such as predicting the potential cause of genetic diseases for 9 billion mutations, but it’s good to know that they also occasionally suffer alignment problems that end up in them hacking someone.”

Is this becoming a marketing ploy?

John Strand, Owner of Black Hills Information Security, commented: “The more I see these breaches happen again and again, and the less I see organisations learning from each other’s mistakes, the more I’m convinced that some of this is becoming a marketing ploy. Frankly, I hope that’s what it is, because if these agents really are repeatedly escaping their controls, then we have much, much larger problems.

“That said, if you look at the attack paths being disclosed, these agents don’t appear to be inventing novel zero-days or entirely new categories of exploitation. They’re doing a lot of the same basic exploitation that a standard penetration testing team would do. So we’ll have to see how this develops.”

Strand keeps coming back to accountability. “Companies deploying autonomous agents need to be responsible for what those agents do. If an agent accesses systems it has no authorisation to access, we need to seriously examine liability under laws such as the Computer Fraud and Abuse Act. ‘The AI did it’ cannot become a shield from responsibility. If your company deploys the agent, your company should be accountable for its actions.”

The more access we give them, the more we need control

Ryan McCurdy, VP of Marketing at Liquibase, added: “Gemini tried to complete the task it received and ended up accessing systems its operators never intended it to reach. That problem gets much bigger as AI starts participating across the SDLC. Agents can write code, interact with repositories and infrastructure, initiate deployments, and make changes to production systems. The more access we give them, the more important it becomes to control what they can actually do.”

McCurdy said we can’t rely on an agent to recognize, after the fact, that it crossed a line. Organisations need to define what an agent can access, what it can change, and what policies it must meet before a change reaches production.

“We shouldn’t expect AI agents to make the right decision every time. We need to build the AI SDLC so a bad decision doesn’t automatically become a production problem.”

They will try keep the keys they find

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity at Suzu Labs, said: “Google just joined Anthropic, OpenAI, and Meta in admitting that a model it was running logged into other people’s systems during a cybersecurity evaluation. Claude hit three real companies. OpenAI’s agents reached Hugging Face. Gemini guessed a password and used leaked credentials against three more. For anyone outside these labs, that is a felony under the Computer Fraud and Abuse Act (CFAA).

“An agent given a name collision and a path to the internet treats the real company as the challenge. I have watched my own pentest agents pull Domain Name System (DNS) records, find similarly named domains, and decide those hosts belong in scope. They chase the objective. They will try the keys they find.”

Krell says the controls that hold sit outside the model’s reasoning. “Deny-by-default egress so a test host cannot reach production even when someone leaves a route open. An immutable scope file that blocks any host not on the list, including the real firm that happens to share the fake one’s name. A human in the loop system who signs off before a guessed password or a leaked credential is used. I run those hooks on my own offensive tooling because the agent will enlarge its own scope and reason around controls if you let it.”

The model is the tool, the operator is the defendant

“Executive Order 14409, signed June 2, told the Department of Justice (DOJ) to prioritize 18 U.S.C. 1030 cases against anyone who uses AI, including autonomous agents, to access a computer without authorization. The model is the tool. The operator is the defendant,” Krell explained.

“Google, Anthropic, OpenAI, and Meta get an evaluation-mishap press line. Everyone else gets the charging memo the White House asked DOJ to write. If my pentest agent guessed a password into a company that was never on the scope sheet, I would be hiring counsel that afternoon.

“They have already confessed in public. Nothing will happen. These firms have a stranglehold on the economy that no case against them is going to survive, making the double standards in the justice system excruciatingly obvious”

Intent-based scope controls are not enough

Vineeta Sangaraju, AI Research Engineer at Black Duck, added: “The AI model accessed systems outside its intended test scope because it could not reliably distinguish authorised targets from similar live infrastructure. As AI agents are deployed more widely in security tooling and automated workflows, policy-level scope instructions are not sufficient. Hard technical boundaries need to be enforced.

The practical question for any organisation is straightforward: what credentials or tokens associated with your systems are discoverable via public sources today? AI has lowered the cost of finding and exploiting that exposure at scale. The defenses of strong authentication, least privilege, etc., are vital. 

For AI providers, Sangaraju said the clearest takeaway is that intent-based scope controls are not enough. “Telling a model ‘stay within these boundaries’ is not equivalent to technically enforcing those boundaries. When a model is given agentic capabilities such as the ability to browse, query, authenticate, and act across systems, the architecture needs hard stops that do not rely on the model’s own judgment about what is in scope.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Texas utility CenterPoint confirms breach after attacker leaks customer data
  • Kirsten Doyle
    Rogue AI agents put trusted access under scrutiny
  • Kirsten Doyle
    Prophet Security research finds AI is cutting SOC investigation times, but nearly half of in-house builds fail to stick
  • Kirsten Doyle
    A reverse image search platform exposed more than 9 million facial images

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Rogue AI agents put trusted access under scrutiny

September 22, 20262 Mins Read

AI agents taking unsanctioned action during cyber testing

August 24, 20263 Mins Read

Walking the AI Security and ROI Tightrope

August 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}