Low-confidence report
This report is hidden because you're viewing high- and medium-confidence reports only. It isn't counted in the scores you're seeing.
Leaderboard / Case No. FB-2026-09-08-google-sandworm-relic-password-spraying
Russia's Sandworm used Gemini to write and refine automated password-spraying scripts and host-fingerprinting tools for its continued hacking operations against Ukraine.
Score breakdown
| Component | Value | Reasoning |
|---|---|---|
| Sentence-Years | 1 | 18 USC 1030(a)(2)(C) |
| × Contribution | 0.5 | Wrote the content: Google says the group used Gemini "to write and refine asynchronous Python scripts designed to perform automated password spraying against target services" and "to develop scripts for endpoint fingerprinting and host profiling"; humans ran the operations, so this is written content. |
| × Blast Radius | 1 | Third party: Google places the activity in "continued operations targeting Ukraine" but names no victim organisation or government body, so blast radius is the conservative third party. |
| × Legal status | 1 | Crime. |
| + Tradecraft | 0 | The scripts guess passwords rather than use stolen ones, and the proxy-routing obfuscation Google lists isn't attributed to Gemini, so no rubric technique is credited to the AI. |
| + Guardrails | 0 | Guardrails intact: Google's report describes no jailbreak; it says the activity triggered Gemini's safety responses and Google disabled the associated assets, so guardrails are scored intact. |
| + Dwell Time | 0 | The report gives no dates for the activity, so date_precision is before with the report's publication date (2026-09-08); dwell is counted from that latest possible date (0 days) and never inflated. Google found the misuse itself. |
| Total | 0.5 |
Charges the human could face
18 USC 1030(a)(2)(C)Up to 1 year