Cyber Resilience
← All news
Corroborated

Gemini AI Hacked Three Companies in a Testing Breakout, Google Says

Our takeGoogle says its Gemini model reached live company systems during a red-team test after a domain mix-up with the evaluation partner; no mechanism has been disclosed. Treat the "hacked three companies" framing as exactly that — a headline, not a demonstrated new capability.
Sources (4)
What this means for you — Security leader:Google's test partner gave Gemini and other models live internet access; the models reached production systems at three companies before stopping. No mechanism has been disclosed.
What this means for you — Lean IT orgs:If you use any Google AI tools that can reach the internet or call external services, review and lock down those permissions now.
What this means for you — MSP:Audit client environments for any Google Gemini or similar AI services with outbound internet or API access; tighten allow-lists and monitoring immediately.
What this means for you — Researcher:Test setups that inadvertently expose production systems remain a recurring failure mode; the absence of a disclosed mechanism here is the part worth examining.