Advertise With Us

How Google’s Gemini AI Hacked Three Real Companies During Security Test

It was supposed to be a controlled cybersecurity test
Google Gemini Al model Google Gemini Al model
The incidents occurred during a cybersecurity evaluation conducted by Irregular. Credit: Google

Google’s Gemini AI model accessed the internet and broke into systems belonging to three real companies in May 2026, marking the first known instance of a Google AI system autonomously carrying out such actions.

The incidents occurred during a cybersecurity evaluation conducted by Irregular, an independent firm that tests AI models for major labs.

According to reports first published by The Wall Street Journal on 18 September 2026, and later confirmed by Google, the model was supposed to operate inside a controlled testing environment targeting a fictional company. However, a configuration error gave the model unintended access to the open internet.

Advertisement

How Google’s Gemini AI Hacks Happened

Google Gemini Al model
Google confirmed that the three companies were informed. Credit: Google Blog

The fictional company used in the test shared its name with a real business.

When it was online, Gemini, in one case, repeatedly guessed passwords until it was able to gain access to a protected system.

In two other cases, it located login credentials stored in public code repositories and used them to enter protected systems belonging to two additional companies.

The model stopped its activity in the three cases after determining that it had gone beyond the intended simulated environment into real-world infrastructure. However, Google stated that no damage was caused to the affected companies.

SEE ALSO: Protest in Minna: 37 Miners Die in Custody, Tinubu Orders Investigation as Gov Bago Imposes Curfew

Gemini Halted the Intrusions on its Own

Irregular made it known to Google and the labs involved in July 2026, but Google did not publicly disclose the incidents at the time.

The company said it did not view the events as an example of prototype misalignment. It argued that its safety measures worked because Gemini halted the intrusions on its own.

Similar breakouts involving models from OpenAI, Anthropic, and Meta also occurred during tests run by Irregular as well.

The company has since said it fixed the internal configuration issues that allowed internet access during the evaluations.

Google confirmed that the three companies were informed and that it worked with Irregular to improve testing procedures.

Loading

About The Author

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Advertisement