Google Gemini AI Hacked 3 Companies During Security Test: What Happened?

Google's Gemini AI model accessed three real companies during a cybersecurity evaluation conducted in May 2026.
Spread the love

Google Gemini Accessed Three Real Companies During Cybersecurity Test

AI model reportedly guessed passwords and used publicly exposed credentials before stopping after identifying the systems as belonging to real companies.

Business / Technology | September 21, 2026: Google’s Gemini AI model accessed the computer systems of three real companies during a cybersecurity evaluation conducted in May, marking a reported first known instance of a Google AI system autonomously carrying out such activity during testing.

The evaluation was conducted by Irregular, an independent company that tests the cybersecurity capabilities of artificial intelligence systems. The exercise was designed as a controlled “capture the flag” test in which Gemini was expected to interact with systems belonging to a fictional company.

However, the testing environment unintentionally allowed the AI model to access the internet. The fictional company used in the exercise also shared its name with a real company, creating the possibility of confusion between the simulated and real-world systems.

Gemini Used Public Information and Credentials

According to reports, Gemini searched publicly available information and attempted to obtain credentials to access websites it believed were part of the authorised test.

In one instance, the model reportedly guessed passwords until it gained access to a protected system. In two other cases, it discovered credentials in a publicly accessible repository and used them to access protected systems.

Google Vice President of Security Engineering Heather Adkins said the model stopped its activity in all three cases after determining that it had accessed systems belonging to real companies. The affected organisations were subsequently informed.

Testing Environment Was the Key Issue

The incident was linked to an unintended internet-access issue within the testing environment. Irregular said the same underlying issue had also been connected to other AI-security incidents involving evaluations of models from companies including OpenAI, Anthropic and Meta.

Irregular said relevant AI companies were notified in late July and that the known issues on its side had been resolved. The company also said it was working on improved practices for conducting cybersecurity evaluations involving increasingly autonomous AI systems.

Google Says No Harm Was Caused

Google said the model stopped once it recognised that the systems were associated with real companies. The identities of the three companies have not been publicly disclosed.

Google also said the incident highlighted the importance of training advanced AI systems to operate responsibly and strengthening safeguards around AI agents that can browse the internet and interact with computer systems.

The incident comes amid increasing attention on the cybersecurity risks associated with autonomous AI agents. As AI systems gain the ability to independently search for information, use credentials and interact with computer systems, security researchers are examining how testing environments can prevent unintended access to real-world infrastructure.

Leave a Reply