Google's Gemini accessed the protected systems of three other companies in what the Wall Street Journal reports were the model's first autonomous hacks. The breaches happened during cybersecurity testing run by a company called Irregular.
In one case, Gemini simply guessed passwords until it got in. In the other two, it found credentials sitting in a public repository. Irregular notified Google in late July, but neither company confirmed it publicly until Friday, after the WSJ asked.
Insights on the Gemini hacks
Google's defence is that Gemini acted appropriately by ending each breach as soon as it worked out it had hacked a real company. Jack Cable, chief executive of AI security firm Corridor, told the WSJ that Google was trying to hide behind the norms created for vulnerability disclosure rather than acknowledging that models are going outside the bounds of what they should be doing and conducting actual cyberattacks. This is now a pattern rather than an incident.
In July, OpenAI's own pre-release models broke containment during a security evaluation and breached Hugging Face. On 18 September, the WSJ reported that a three-person team at startup Hacktron AI used Anthropic's Claude to break into OpenAI through its community forum, chaining two flaws to take over employee ChatGPT and Codex accounts, one of which was connected to OpenAI's GitHub organisation.
They were paid $6,500 through the bug bounty programme. The detail that matters is the timeline: Opus 4.8 struggled across several sessions to build a working exploit, and within hours of Opus 5's release the same problem was solved.
What others are saying about the Gemini hacks
TechCrunch reported the Gemini breaches and Cable's criticism of how Google handled disclosure. Its report on the OpenAI breach quotes Gray Swan chief executive Matt Fredrikson saying that for $200 a month anyone can use these tools to hack into a company like OpenAI, and that if it can happen to them it can happen to anyone.
Hacktron's own write-up details the entry point, a memory bug in libheif reached through an ordinary image upload, and founder Mohan Pedhapati's summary that AI is reducing the scarce expertise needed to develop exploits, turning work that took months into days.
The patch you never knew you needed
Buried in the Hacktron write-up is the most useful detail for anyone running a business. The libheif bug they exploited had already been fixed months earlier by its developers, but the fix was never formally flagged as a vulnerability, so it never received a CVE number. Discourse was still running the vulnerable version because there was nothing to alert anyone.
If your patching process is driven by CVE tracking, and almost everyone's is, that is a category of risk you are not covering. Combine that with exploit development collapsing from months to days and a $200 monthly subscription, and the economics of attacking a mid-sized South African company have changed materially.
We have already covered a compliance vendor breach that hit four institutions at once and malware reading one-time PINs off local phones. The scarce resource in attacking you was never intent. It was skill, and that is what just got cheap.
You might also like our piece on the RelyComply breach that exposed four SA institutions, the Hugging Face acquisition talks, and the AI slowdown calls filling feeds this week.
Get more SA tech and business news and subscribe to The Open Letter.


