Drooid Logo
Back to story perspectives

Full Breakdown

Google’s Gemini AI Targeted by Model Extraction and Cyber Espionage

2/14/2026, 12:05:35 AM

Overview of Model Extraction Attacks

Google's Gemini AI chatbot has recently been the target of extensive "model extraction" attacks, characterized by adversaries attempting to clone its underlying technology through a barrage of prompts. In one notable incident, attackers submitted over 100,000 queries designed to probe Gemini's reasoning capabilities, aiming to replicate its functionality in competing models. Google describes this practice as a form of intellectual property theft, asserting that it poses significant risks to the integrity of AI systems and the competitive landscape of the industry.

Nature of the Threat

The attacks, which Google refers to as "distillation attacks," involve systematically querying a mature machine learning model to extract valuable information that can be used to train new models. These attempts are believed to be driven primarily by private companies and researchers seeking a competitive edge in the rapidly evolving AI market. Google has identified that these activities are not isolated incidents but part of a broader trend, with similar tactics likely to emerge against smaller AI systems as well.

State-Sponsored Exploitation of Gemini

In addition to commercial actors, state-sponsored hacking groups from countries including North Korea, China, Iran, and Russia have also exploited Gemini for various cyber operations. Google’s Threat Intelligence Group (GTIG) reported that these advanced persistent threat (APT) actors have integrated Gemini into their workflows for tasks such as reconnaissance, phishing, and malware development. For instance, the North Korean group UNC2970 has utilized Gemini to synthesize open-source intelligence and profile high-value targets, enhancing their social engineering campaigns.

Specific Use Cases

  • North Korea: The UNC2970 group has leveraged Gemini to gather intelligence on cybersecurity and defense companies, crafting convincing phishing messages under the guise of job recruitment.
  • Iran: The APT42 group has employed Gemini for social engineering and to develop custom malicious tools, including translating local languages for targeted phishing operations.
  • China: Chinese actors have used Gemini to automate vulnerability analysis and conduct technical research, demonstrating the model's versatility in supporting cyber operations.

Implications for AI Security

The rise of model extraction attempts highlights the vulnerabilities inherent in AI systems, particularly those that are publicly accessible. Google has responded by enhancing its safeguards and disabling accounts linked to malicious activities. However, experts warn that as organizations increasingly deploy custom AI models trained on sensitive data, the risk of intellectual property theft will continue to grow.

Official Statements & Responses

John Hultquist, chief analyst at Google’s Threat Intelligence Group, emphasized the significance of these findings, stating, “We’re going to be the canary in the coal mine for far more incidents.” Google has committed to strengthening its defenses against such attacks and has shared intelligence with Google DeepMind to improve model protections.

Criticism & Opposition

Despite the serious nature of these threats, some experts have raised concerns about the potential exaggeration of the risks associated with AI misuse. Security researcher Marcus Hutchins noted that certain features of AI malware, such as self-modifying capabilities, may not be as advanced as suggested, indicating that the threat landscape may not be as dire as portrayed.

Conclusion

The ongoing exploitation of Google’s Gemini AI by both commercial and state-sponsored actors underscores the urgent need for robust security measures in the AI sector. As the landscape evolves, organizations must remain vigilant and proactive in safeguarding their AI technologies against emerging threats.