Google confirms Gemini models hacked three companies in May 2026

Google confirms Gemini models hacked three companies in May 2026

谷歌确认 Gemini 模型在 2026 年 5 月入侵了三家公司

It has become increasingly common for AI firms to announce that their latest and most capable models engaged in unauthorized real-world hacking. Google, which has been slow to release frontier Gemini models in recent months, has been absent from the “rogue AI” conversation until now. 人工智能公司宣布其最新、最强大的模型参与了未经授权的现实世界黑客攻击,这种情况已变得越来越普遍。谷歌近几个月在发布前沿 Gemini 模型方面进展缓慢,此前一直未参与关于“流氓 AI”的讨论。

Following a Wall Street Journal report, Google has confirmed that Gemini models hacked three companies during a May 2026 test, but the nature of the intrusion isn’t as troubling (or impressive) as previous AI hacks. The hack took place during a test conducted by cybersecurity firm Irregular. 继《华尔街日报》报道后,谷歌确认 Gemini 模型在 2026 年 5 月的一次测试中入侵了三家公司,但此次入侵的性质并不像之前的 AI 黑客事件那样令人担忧(或令人印象深刻)。此次黑客攻击发生在网络安全公司 Irregular 进行的一项测试期间。

A collection of Gemini models were taking part in a “capture the flag” exercise intended to test the AI’s cybersecurity capabilities in a closed environment. The AI was instructed to retrieve information from a fake company (which shared a name with a real company) within this environment. 一组 Gemini 模型参与了一项旨在测试 AI 在封闭环境中网络安全能力的“夺旗”演习。AI 被指示从该环境内的一家虚构公司(与一家真实公司同名)中检索信息。

Irregular was not supposed to allow the model to operate outside its servers, but due to a misconfiguration, Gemini was able to access the Internet. When Gemini started snooping around the web, it targeted real infrastructure instead of the fakes. Irregular 本不应允许该模型在其服务器之外运行,但由于配置错误,Gemini 得以访问互联网。当 Gemini 开始在网络上搜寻时,它瞄准的是真实的基础设施,而非虚构的目标。

For one of the three hacks, Gemini simply guessed passwords until it accessed a company’s online services. In the other two instances, Gemini searched public software repositories until it found login credentials for companies that had been accidentally included. 在三次入侵中的其中一次,Gemini 只是通过猜测密码,直到成功访问了一家公司的在线服务。在另外两次案例中,Gemini 搜索了公共软件存储库,直到找到被意外包含在内的公司登录凭据。

In all three test runs, Google’s models reportedly stopped after realizing they had accessed a real company’s servers. At that point, Irregular changed its configuration to prevent the AI from accessing the Internet. 据报道,在所有三次测试中,谷歌的模型在意识到自己访问了真实公司的服务器后都停止了操作。随后,Irregular 修改了配置,以防止 AI 再次访问互联网。

Apparently, Irregular didn’t initially consider this event worthy of further investigation—it didn’t even tell Google about the hacks until July, following the news of other AI hacking incidents. After becoming aware of the event, Google notified the companies so they could (we hope) improve their password security. 显然,Irregular 最初并未认为此事件值得进一步调查——直到 7 月份其他 AI 黑客事件的消息传出后,他们才将此事告知谷歌。在获悉该事件后,谷歌通知了相关公司,以便他们(我们希望)能提高其密码安全性。

Google’s decision not to publicly disclose the hacks comes down to the model’s behavior after using its ill-gotten passwords. Since the models realized the systems were real and stopped, the company didn’t consider this a true example of model misalignment. 谷歌决定不公开披露这些黑客攻击,归结于模型在使用非法获取的密码后的行为。由于模型意识到系统是真实的并停止了操作,该公司并不认为这是一个真正的模型失准(model misalignment)案例。

In a statement, Google’s vice president of security engineering, Heather Adkins, downplayed the severity of the incident. “This event highlights the importance of training powerful AI models to act responsibly. In this case, the model acted appropriately,” she said. 谷歌安全工程副总裁 Heather Adkins 在一份声明中淡化了该事件的严重性。她说:“这一事件凸显了训练强大的 AI 模型以负责任地行事的重要性。在这种情况下,模型的表现是恰当的。”

This is very different from hacks like the OpenAI-Hugging Face incident, which was clear-cut model misalignment. When OpenAI’s models escaped containment, they did so by using software exploits with the express purpose of accessing information that was not available in their testing environment, all in service of acing a benchmark and earning higher “rewards.” 这与 OpenAI-Hugging Face 事件等黑客攻击截然不同,后者是明确的模型失准。当 OpenAI 的模型逃脱控制时,它们是通过利用软件漏洞,明确目的是访问测试环境中无法获取的信息,这一切都是为了在基准测试中取得高分并获得更高的“奖励”。

You could, however, argue that OpenAI’s setup essentially encouraged this behavior. Google’s AI didn’t do anything so malicious—someone just left the door open and the AI got out. Gemini was allowed access to a wealth of information on the Internet, and it used it to log in to systems it wasn’t authorized to access. 然而,你也可以认为 OpenAI 的设置本质上鼓励了这种行为。谷歌的 AI 并没有做任何恶意的事情——只是有人没关好门,AI 就跑出去了。Gemini 被允许访问互联网上的大量信息,并利用这些信息登录了它未被授权访问的系统。

Guessing passwords isn’t exactly world-ending AI apocalypse behavior, but it’s probably still something Google should have disclosed when it became aware it had happened. 猜测密码并不完全是那种会导致世界末日的 AI 灾难性行为,但这可能仍然是谷歌在意识到事件发生时就应该披露的事情。