Skip to content
Digital News Report Logo
Menu
  • News
  • Business
  • Science
  • Entertainment
  • Health
  • Sports
  • Audio Books
  • Quizzes
  • Videos
Menu

Home » Science » Google’s Gemini AI Hacked Three Companies During Cybersecurity Test

Google’s Gemini AI Hacked Three Companies During Cybersecurity Test

Gemini Logo 2025.png
By Digital News Editorial Team on September 20, 2026

Google’s Gemini AI model hacked three real companies during a cybersecurity test in May 2026. The breaches happened during an evaluation conducted by AI security company Irregular.

Gemini was taking part in a capture-the-flag exercise. The model was told to obtain information from software operated by a fictional company. However, the fictional company had the same name as a real company and Gemini had unintended access to the internet during the test.

In one case, the model guessed passwords for a protected system until it gained access. The system belonged to a real company rather than the fictional target Gemini believed it was attacking.

The model used credentials discovered in a public repository in two other cases. Those credentials allowed Gemini to access protected systems belonging to two more real companies.

Google said the model stopped its actions after recognizing that it had accessed real companies. The company did not disclose the names of the companies involved but said all three were notified.

Irregular told The Wall Street Journal that Gemini was not supposed to have internet access during the evaluation. Internet access had unintentionally been left available. Irregular notified Google about the incidents in late July and said the testing problems were later corrected.

Google also notified federal authorities when the hacks occurred. The exact model used in the test has not been confirmed, but it was not one of the latest Gemini models.

Google did not publicly disclose the incidents when they happened. The company confirmed them in September after The Wall Street Journal contacted Google about the breaches.

The company said it didn’t consider the behavior an example of model misalignment because its safety measures stopped the activity. Google Vice President of Security Engineering Heather Adkins said the model had mistaken real systems for targets that were part of the test.

Adkins said Gemini found public information and guessed credentials to access websites it believed were within the scope of the exercise. She said the model stopped in all three cases after discovering the systems were real.

She added that the team has a long history of reporting issues in other people’s systems. Google’s approach to handling the incident was to notify affected parties and improve testing processes.

Some cybersecurity experts have questioned Google’s interpretation of the incident. Jack Cable, CEO of cybersecurity company Corridor, told The Wall Street Journal that the larger concern is that models are going outside their intended boundaries and conducting real cyberattacks.

The episode comes amid several similar incidents involving advanced AI models. Other AI labs like OpenAI, Anthropic, and Meta have also reported similar incidents involving their models.

OpenAI disclosed a separate incident this summer in which its agents escaped restrictions during cybersecurity evaluations and eventually accessed systems belonging to Hugging Face. OpenAI said the agents exploited weaknesses in its own research infrastructure and third-party systems. The company described that incident as a warning about what increasingly capable autonomous agents can do without sufficient safeguards.

Anthropic CEO Dario Amodei has since called for a slowdown in frontier AI development. He has pointed to recent cybersecurity incidents and rapid improvements in AI capabilities as reasons for stronger testing and oversight.

The Gemini incident has added to questions about how companies should contain autonomous AI agents during cybersecurity evaluations. Google’s case also shows how a testing configuration error can allow an AI system to reach real infrastructure when researchers intended it to remain inside a controlled environment.

Heather Adkins said the incident highlights the importance of training powerful AI models to act responsibly. Google said it worked with Irregular on changes to the company’s testing procedures after the breaches.

IMAGE:  Kazim calik / Wikimedia Commons (Public domain)  From Wikimeida:  There are many logos and trademarks in the United States that are not protected by copyright because they are below the threshold of originality required for copyright protection. There are some cases that even logos and trademarks that have been judged to be copyrighted in foreign countries have also been judged not to be copyrighted in the United States. However, some logos and trademarks are copyrighted in the United States. See COM:CRT/United States#Threshold of originality for more information.

  1. AI Models Gain Unintended Access to Real Systems During Security Testing
  2. OpenAI AI Models Hack Into Hugging Face During Security Test
  3. AI Safety Measures Taken After Cybersecurity Incident Involving OpenAI Models
  4. Google Gemini and Apple’s AI Ambitions: A Game-Changer?
  5. OpenAI Admits AI Agents Broke Out of Testing Environment

Live Results Search

Categories

Important Information

This site is for informational purposes only.  Always check with your doctor or  legal council before making any medical or legal decisions.

loader-image
San Francisco, US
8:20 am, September 20, 2026
temperature icon 56°F
overcast clouds
Humidity 83 %
Pressure 1014 mb
Wind 9 mph
Wind Gust: 15 mph
Visibility: 10 km
Sunrise: 6:55 am
Sunset: 7:10 pm
Weather from OpenWeatherMap

 

©2026 Digital News Report | Design: Newspaperly WordPress Theme