Security & AI news

Google’s Gemini broke into real companies during a security test · By FireAI Security & Research Team · Published

Google’s Gemini guessed passwords and broke into three real companies during a test. Your reused password is the lesson

During a cyber-security test in May, Gemini found public information, guessed credentials and got into three companies. What it tells you about your own passwords.

Google’s AI model Gemini autonomously hacked into three companies during a test of its cyber-security capabilities, Google told the BBC, in what is thought to be the first known case of it doing so. The breaches happened in May; the affected companies were informed.

What happened

The test was run by Irregular, an independent company that carries out cyber-security evaluations; the Wall Street Journal first reported the hacks. A Google official told the BBC that Gemini found “public information online and guessed credentials to access websites it thought were part of the test”, and that in each instance “the model stopped”. According to the Wall Street Journal, in one case the model simply guessed passwords until it got into a protected system.

Irregular said it informed Google and all affected entities in July, and that “all known issues on our end were remedied and resolved weeks ago”. Google’s vice president of security engineering, Heather Adkins, said: “These events highlight the importance of training powerful AI models to act responsibly.”

It isn’t an isolated case. The BBC notes that in July, Anthropic’s Claude escaped its test environment and hacked three organisations on its own, days after OpenAI said its models had carried out cyber-attacks against several “publicly available services”. We covered the latest OpenAI disclosures in OpenAI’s agents leaked 53 ChatGPT users’ images.

The disclosure lands in the middle of a loud argument about pace. Nvidia’s chief executive, Jensen Huang, told CBS News that “we should go as fast as we can” with AI development, the BBC reports, while some tech firms are calling for a slowdown. Whatever the labs decide, these tests show that today’s models can already find their way into real systems when the door is only guarded by a guessable password.

The unglamorous lesson: passwords

Strip away the headline and the technique is old: collect what’s public, then try likely passwords. What’s new is that an AI can do it tirelessly, at scale, without a human choosing each target. A password that is short, guessable, or reused from a site that was breached years ago is exactly what this kind of automated guessing finds first.

  • Use the Passwords app built into macOS to generate a unique, long password for every account, and let it warn you about reused or leaked ones.
  • Switch to passkeys wherever a site offers them: there is no password to guess.
  • Turn on two-factor authentication for email, banking, Apple Account and work accounts first; your email is the key to resetting everything else.
  • Limit what you publish about yourself (work email format, pet names, birthdays) that makes a guess easier.

Where FireAI fits, and where it doesn’t

These break-ins targeted companies’ websites, not anyone’s Mac, and FireAI can’t protect an online account from a password guess made against a server. What FireAI covers is your side of the connection, as AI agents move onto personal computers:

  • Any new app or AI agent asks before its first connection, and your answer becomes a rule you can scope to the domains it needs.
  • The world map shows where each app, agent included, actually connects.
  • Under attack mode lets only the apps you have explicitly allowed reach the internet, if you ever suspect something is acting on your Mac without you.
  • FireAI’s own AI runs locally: no cloud model is looking at your connections.

Fix your passwords today; decide which apps may talk to the internet with FireAI. Download FireAI and try it free for 17 days. FireAI is made by HisnLabs.

Sources