Chronicle/Attacks & incidents

Google finds government-backed hackers using Gemini for support tasks, not novel capabilities

AttackMisuse reportSignificance assistant-drafted

Google Threat Intelligence Group analyzed how government-backed hacking and information-operations actors used the Gemini web app. It reports use for research, troubleshooting code and producing content across several attack phases, with Iranian actors the heaviest users, and says it saw productivity gains but no novel capabilities; requests for clearly malicious help drew safety responses.

Why it matters

An independent provider reached the same conclusion as Microsoft and OpenAI a year earlier, shortly before reports of agentic misuse began later in 2025.

Key facts

As stated in the sources, with where to find them.

  • Iranian APT actors were the heaviest users of Gemini; GTIG observed limited use by Russian APT actors during the period.Key findings
  • Iranian information-operations actors accounted for about three quarters of use by IO actors.Key findings
  • GTIG reports actors relied on basic measures or publicly available jailbreak prompts, which did not get past Gemini’s safety controls.Key findings

Findings that cite this record

Sources

Related records