Hackers Try to Clone Google’s Gemini With 100,000+ AI Probes

Hackers Try to Clone Google’s Gemini With 100,000+ AI Probes

two people working on a code in a computer

Image: DC_Studio/Envato

Écrit par
Esther Shein
Esther Shein
Feb 13, 2026
2 minute read
eWeek Le contenu et les recommandations de produits sont indépendants de la rédaction. Nous pouvons gagner de l'argent lorsque vous cliquez sur des liens vers nos partenaires. En savoir plus

Google built Gemini to answer questions. Now attackers are using questions as lockpicks.

In a surge of more than 100,000 carefully engineered prompts, threat actors have been hammering Google’s Gemini chatbot in what the company calls “model extraction” or “distillation” attacks. By systematically probing the system, adversaries attempt to reverse engineer the model’s underlying logic, reasoning patterns, and chain of thought to build rival AI systems without paying the steep cost of training one from scratch.

Google says the activity appears to be tied to actors in countries including North Korea, Russia, and China. The company classifies the effort as intellectual property theft and a clear violation of its terms of service.

Other companies may see similar attacks

But Gemini may just be the opening act.

John Hultquist, the chief analyst of Google’s Threat Intelligence Group, told NBC News that while Gemini may be one of the first targets, other companies’ custom AI tools are likely to see these types of attacks as well.

“We’re going to be the canary in the coal mine for far more incidents,” Hultquist said. 

Experts warn this trend will accelerate. “Given the cost of training new models, it’s not surprising to see model extraction attacks as an illegal way of trying to gain ground on developing a new model,” Melissa Ruzzi, director of AI at AppOmni, told TechRepublic in a statement. “We can expect more and more AI to be used in attacks.”

The proprietary logic and specialized training found in major LLMs have made them high-value targets, Google said. Whereas adversaries once relied on conventional intrusion operations to steal trade secrets, actors can now use legitimate API access to attempt to “clone” select AI model capabilities.

Agentic AI introduces internal data risks

Law firm Shumaker, Loop & Kendrick adds that agentic AI systems introduce additional risk. When organizations grant AI agents broad access to sensitive systems, data leakage can quietly erode trade secrets, patents, trademarks, and copyrights.

“By leaking data, agentic AI can quietly erode IP rights unless you change the defaults,” the firm wrote in a recent blog. “These leaks can negatively impact trade secrets, patents, trademarks, and copyrights.”

The firm advises organizations to grant agents credentials only for the tasks they perform.

Related reading: Google is also testing AI defenses in Chrome, offering up to $20,000 to researchers who can expose security flaws in its AI features.

Esther Shein

Esther Shein is a longtime content writer specializing in tech and business. Her work has appeared in several local and national publications. She writes news, features, case studies, custom content and marketing materials.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Propriété de TechnologyAdvice. © 2026 TechnologyAdvice. Tous droits réservés

Divulgation publicitaire : Certains des produits qui apparaissent sur ce site proviennent d'entreprises dont TechnologyAdvice reçoit une compensation. Cette compensation peut influencer la façon dont les produits apparaissent sur ce site, notamment l'ordre dans lequel ils apparaissent. TechnologyAdvice n'inclut pas toutes les entreprises ou tous les types de produits disponibles sur le marché.