AI Safety

Gemini AI Cyberattack: 7 Real Threats Exposed

Gemini AI cyberattack
Gemini AI cyberattack

By Stuart Kerr, Technology Correspondent, LiveAIWire

A single Google Calendar invite was enough for security researchers to hijack a victim’s Gemini AI assistant, open their smart windows, start an unauthorised Zoom recording, and quietly leak their emails, all without the person clicking anything or realising it happened. That is not a hypothetical. It is what SafeBreach Labs demonstrated in research disclosed to Google in February 2025 and published in August 2025, and it sits alongside a separate stream of confirmed nation-state misuse of Gemini that Google itself has documented and disrupted. The real story of Gemini’s security problems in 2025 and 2026 is not a single catastrophic breach. It is a steady accumulation of verified, mostly patched vulnerabilities and confirmed misuse, which is a different and more useful thing to understand than a single dramatic headline.

The word cyberattack gets thrown around loosely, so it is worth being precise about what has and has not actually happened. No evidence supports a single mass breach of Gemini user data. What the record does support is a series of distinct, disclosed, largely patched vulnerabilities, plus documented use of Gemini as a tool by state-linked hacking groups, both of which carry real lessons for anyone using AI assistants connected to their email, calendar, or smart home.

The Calendar Invite That Could Hijack Your Assistant

SafeBreach Labs researchers Or Yair, Ben Nassi, and Stav Cohen developed what they call Targeted Promptware Attacks, a technique that hides malicious instructions inside an ordinary Google Calendar invite title. When a victim later asks Gemini to summarise their day, Gemini reads the poisoned invite as part of its context and follows the hidden instruction, without the user seeing anything unusual. In their demonstrations, the technique was used to delete calendar events, control smart home devices such as connected windows, boilers, and lights, track a victim’s location, trigger an unauthorised Zoom call, and exfiltrate email content. The researchers classified 73 percent of the threats they identified as high or critical risk. Google was notified in February 2025 and rolled out layered defences, including expanded user confirmations for sensitive actions, before the research was made public at Black Hat USA.

State-Backed Hackers Are Already Using Gemini, Just Not the Way Headlines Suggest

Separately, Google’s own Threat Intelligence Group has confirmed that government-backed hacking groups from Iran, North Korea, and China have used Gemini in real operations. Iran’s APT42 used Gemini to research targets, draft phishing personas, and translate content for social engineering campaigns. North Korea’s UNC2970 used it to profile high-value targets in the defence and cybersecurity sectors. Chinese groups including APT31 and APT41 used Gemini to analyse vulnerabilities, generate testing plans, and troubleshoot code. In every documented case, Google says it detected the activity and disabled the associated accounts and projects. This is meaningfully different from an assistant being broken into. It is threat actors using a publicly available tool the way they might use any other software, and Google actively working to shut that misuse down.

What This Actually Means for Anyone Using Gemini

For everyday users, the practical risk is narrower than a headline like AI cyberattack implies. The single most useful precaution from the SafeBreach research is caution about accepting calendar invites or opening documents from unfamiliar senders, since the attack chain in every demonstrated case began there, not with a flaw in Gemini’s core intelligence. Google’s confirmation that disclosed techniques were patched before wide exploitation is context often missing from more alarmist coverage. The bigger structural lesson is that any AI assistant with access to your calendar, inbox, or smart home devices inherits the security posture of every one of those connected systems, which is exactly why researchers keep testing this specific attack surface.

New Malware Is Learning to Ask Gemini for Help

Google’s threat researchers have also tracked malware that uses Gemini’s own API mid-attack rather than targeting Gemini directly. A downloader family Google calls HONESTCUE sends prompts to Gemini’s API to generate fresh, functional code for its second stage on demand, rather than shipping that code inside the malware itself, making it harder for traditional antivirus tools to detect. A separate phishing kit called COINBAIT, built to impersonate a major cryptocurrency exchange, shows clear signs of having been constructed with AI coding tools. Google disabled the accounts and projects associated with both, but the pattern, malware calling a legitimate AI service as a component rather than attacking it, is one security teams are watching closely as it becomes more common.

The Honest Wake-Up Call

The real wake-up call here is not a single Gemini breach, because the evidence does not support one having happened. It is that Gemini, like every AI assistant now wired into email, calendars, and smart devices, sits at the intersection of two things attackers actively target: the trust users place in a familiar assistant, and the growing list of tools that assistant is permitted to use on their behalf. Our earlier reporting on why the inbox has become AI’s new front line covered the same dynamic from the email side, and the pattern holds here too. Getting the basics right, understanding what your AI assistant is testing when it flags a hallucination or refuses a request, and pushing for AI systems that surface their own limitations rather than hide them, all matter more day to day than any single dramatic incident. The fixes that count are not dramatic. They are patched vulnerabilities, tighter default permissions, and users treating an AI assistant’s access to their calendar and smart home with the same caution they would give a new app requesting the same permissions.

About the Author

Stuart Kerr is Technology Correspondent at LiveAIWire, covering artificial intelligence, emerging technology, and their impact on business, society, and everyday life. LiveAIWire publishes original AI journalism every weekday at liveaiwire.com.