google gemini hacked

Google’s Gemini Hacked Three Companies During an AI Security Test. Here Is What Happened

3 Mins Read

PureVPNNewsGoogle’s Gemini Hacked Three Companies During an AI Security Test. Here Is What Happened

Google has confirmed to The Wall Street Journal that its Gemini AI model accessed the systems of three real companies during a cybersecurity test in May 2026. The incidents occurred during an evaluation conducted by AI security company Irregular, where Gemini was completing cybersecurity tasks involving fictional targets in a controlled environment.

The test did not stay contained. Gemini was unintentionally able to access the internet and reached systems belonging to real companies. In one case, it guessed a password to gain access. In two others, it found credentials in public repositories and used them to access protected systems.

https://twitter.com/hey_madni/status/2101242276928512279/photo/1

Google says Gemini stopped once it recognized that the companies were real and not part of the test. So, how did a controlled security test end with Gemini hacking three companies? Find out what happened below:

How Did Gemini End Up Hacking Three Real Companies?

Gemini was taking part in a capture-the-flag exercise run by Irregular, an AI security company that tests advanced AI models. The exercise tasked Gemini with retrieving information from software operated by a fictional company.

The testing environment was supposed to keep Gemini away from the public internet. Instead, internet access was unintentionally left available. That became a problem when Gemini encountered a fictional company in the exercise that shared its name with a real business.

Gemini searched for the company online and reached the real company’s system. It then tried different passwords until one worked, giving it access to a system that was never supposed to be part of the test.

The other two incidents followed a different route. During separate tests, Gemini found publicly available credentials and used them to access systems belonging to two other companies.

Gemini Stopped Once It Realized the Companies Were Real

According to Google, Gemini did not continue once it recognized that the systems belonged to real companies rather than targets in the security test. The model stopped its actions in all three cases.

Google does not consider the incidents an example of model misalignment. The company’s position is that Gemini was carrying out the cybersecurity task it had been given and initially believed the systems it found were part of that task. Once it determined otherwise, it stopped.

Heather Adkins, Google’s vice president of security engineering, said the company contacted the three affected organizations and worked with Irregular on changes to its testing processes. Google also said that no harm was caused to the companies.

There are still details that have not been made public. Google has not named the three companies, and the exact Gemini model used in the tests has not been disclosed.

Why the Incident Only Became Public Months Later

The three incidents happened in May 2026, but they did not become public until September. Irregular notified Google about the incidents in late July. The company says the same testing problems were connected to incidents involving models from other AI labs as well.

Google did not publicly disclose the Gemini incidents at the time. The company told The Wall Street Journal that it did not consider disclosure necessary because Gemini stopped after recognizing the companies were real and, according to Google, caused no harm. The three affected companies were informed, and Google said US federal authorities were also notified.

The incidents became public in September after The Wall Street Journal contacted Google. Irregular says all relevant AI labs had been notified in late July and that the known problems on its side had since been fixed. It is also working on guidelines for running AI cybersecurity evaluations more securely.

What the Gemini Incident Says About AI Security Testing

The Gemini incident put the testing environment itself under scrutiny. These evaluations deliberately give AI models offensive cybersecurity tasks, which makes keeping those tasks within their intended boundaries particularly important. In this case, Gemini was supposed to attack fictional targets, but unintended internet access gave it a path to real systems.

The Gemini case is not the first time an AI cybersecurity evaluation has resulted in a model reaching systems outside its intended environment. In August 2026, OpenAI published the findings of its investigation into a July security incident in which models being evaluated for advanced cybersecurity capabilities circumvented controls designed to isolate them from the internet. 

The models exploited vulnerabilities in OpenAI’s research environment and Hugging Face’s production infrastructure, eventually gaining access to data from Hugging Face’s production database. The circumstances were different from the Gemini incident, but both cases show what can happen when an AI model performing offensive security tasks gets beyond the environment intended for the test.

author

Arsalan Rashid

date

September 21, 2026

time

14 hours ago

A marketing geek turning clicks into customers and data into decisions, chasing ROI like it’s a sport.

Have Your Say!!