Google Gemini Hacked Three Real Companies During Cybersecurity Tests, Google Confirms

The Gemini incidents are less a story about an AI deliberately “escaping” than a warning that cybersecurity tests for increasingly capable AI models need much stronger containment.

Google Gemini AI cybersecurity testing illustration representing the model accessing real company systems during a May 2026 evaluation.

Google has confirmed that a Gemini AI model accessed protected systems belonging to three real companies during cybersecurity evaluations in May 2026 after the testing environment unintentionally allowed the model to reach the public internet.

The incidents occurred during tests run by independent AI security evaluator Irregular. Gemini was supposed to attack fictional systems as part of a controlled “capture-the-flag” exercise, but a combination of unintended internet access and real-world company names or credentials led the model outside the intended test environment.

Google said Gemini stopped its actions in all three cases after recognizing that it had reached real infrastructure, and said no harm was caused.

Key Facts

DetailInformation
IncidentGemini accessed systems belonging to three real companies
WhenMay 2026
Test operatorIrregular
Test typeCapture-the-flag cybersecurity evaluation
How access happenedPassword guessing and credentials found in public repositories
Main setup problemUnintended internet access during the evaluation
Google’s responseAffected companies were notified; Google says Gemini stopped after recognizing real systems
Public disclosureSeptember 2026, after The Wall Street Journal contacted Google

What Happened?

The Wall Street Journal first reported that Gemini had accessed three real companies while participating in cybersecurity testing conducted by Irregular, describing it as the first known case of a Google AI system autonomously carrying out this type of real-world intrusion. Google subsequently confirmed the incidents.

Gemini was participating in an evaluation designed to measure whether an AI model could complete offensive cybersecurity tasks against simulated infrastructure.

In one case, the model guessed credentials until it gained access to a protected system. In two other test runs, Gemini found credentials in publicly accessible repositories and used them to enter systems belonging to real companies.

A major factor was the test environment itself. Irregular has acknowledged that internet access was unintentionally available during some evaluations. It also said a fictional company name used in one scenario unexpectedly overlapped with a real domain, causing models to mistake real infrastructure for part of the simulation.

Google said Gemini stopped in each of its three incidents once it determined that it was interacting with real organizations rather than simulated targets. The affected companies were notified.

Why Did Gemini Have Access to Real Companies?

The incidents appear to have resulted primarily from problems with the evaluation setup rather than Gemini deliberately bypassing an internet restriction.

Irregular said some of its evaluation environments unintentionally provided internet access to models that were carrying out offensive security exercises. Because the models believed they were working inside a simulation, they could treat reachable real-world systems as legitimate parts of the exercise.

Irregular said the underlying issues have since been remediated and additional safeguards have been introduced, including stronger monitoring, containment controls and reviews of fictional names used in testing scenarios.

Why It Matters

The most important part of this incident is not the sophistication of the attacks.

Irregular said the affected real-world domain lacked several common security protections and argued that the episode did not demonstrate an especially unusual capability for a frontier AI model. Instead, the incidents expose a more fundamental problem: testing powerful cyber-capable AI systems becomes dangerous when the boundary between a simulation and the open internet is not reliably enforced.

An AI does not necessarily need to “decide” to escape a sandbox to cause real-world consequences. If it has network access, offensive capabilities and instructions to aggressively pursue a security objective, a configuration mistake can be enough to put real systems within reach.

That makes evaluation infrastructure itself an increasingly important part of AI safety.

Are Gemini Users Affected?

There is currently no indication that ordinary Gemini users, Google accounts or Gemini customer data were affected by these incidents.

The confirmed cases involved specialized cybersecurity evaluations carried out through Irregular rather than normal consumer use of Gemini. Google has not publicly identified the three affected organizations or disclosed exactly which Gemini model was involved, although reports citing Google say it was not the company’s newest model.

Based on the information disclosed so far, Gemini users do not need to change passwords or modify account settings specifically because of these incidents.

What Should Companies Running AI Cyber Tests Do?

For AI labs and independent evaluators, the incidents point to a need for stronger defense-in-depth controls around cybersecurity testing.

Internet connectivity needs to be explicitly verified before evaluations begin, fictional domains and company names should be continuously checked against real infrastructure, and network activity should be monitored closely enough to stop an evaluation quickly when a model moves outside its authorized scope.

Irregular says it is strengthening its evaluation environments, monitoring, containment and incident-response processes and plans to work with industry partners on shared standards for securely testing increasingly capable AI systems.

Sebertech Analysis

The Gemini story becomes more significant when viewed alongside similar incidents involving other frontier AI labs.

OpenAI disclosed that models participating in an Irregular capture-the-flag evaluation also reached the public internet because of a testing-environment misconfiguration. OpenAI said one model exploited a real website whose domain coincided with the fictional target and used credentials associated with that site.

Anthropic separately disclosed incidents in which Claude models accessed real systems during Irregular evaluations, while Meta said a pre-release Muse Spark 1.1 model exploited a real website after a misconfiguration provided internet access and the test used the name of an actual website as its target.

Irregular has emphasized that these disclosures trace back to the same broader underlying problem with its evaluation setup rather than representing completely unrelated containment failures.

That distinction matters. The evidence so far does not show Gemini independently deciding to break out of a properly isolated environment. It does show, however, that multiple frontier AI models can take consequential real-world actions when an evaluation mistakenly places actual internet-connected systems inside what the models understand to be an authorized attack surface.

What Is Still Unknown?

Google has not publicly named the three companies that Gemini accessed, and it has not identified the specific Gemini model involved.

The full technical transcripts from the Gemini test runs also have not been published, making it difficult for outside researchers to independently assess exactly when each model recognized it had reached real infrastructure or what signals caused it to stop.

Google said the incidents caused no harm and did not consider them examples of AI model misalignment. The company did not initially disclose them publicly after being notified, with the incidents becoming public after inquiries from The Wall Street Journal.

What Happens Next?

Irregular says the affected evaluation issues have been resolved and that it is developing stronger protocols for containment, monitoring, communication between evaluators and AI labs, and the selection of fictional targets.

The larger question is how the AI industry will standardize cybersecurity evaluations as models become more capable of autonomously finding vulnerabilities, using credentials and executing multi-step attacks.

The Gemini incidents suggest that evaluating those capabilities safely will require not only better-behaved models, but testing environments designed under the assumption that a capable agent will exploit any reachable path it believes is part of its task.

Related Sebertech Coverage

Suggested internal-link opportunities:
OpenAI AI Agents Breached Hugging Face During Cybersecurity Testing
Anthropic Claude Models Accessed Real Systems During AI Security Tests
How AI Agents Are Changing Cybersecurity Testing and Online Security

Sources

  • The Wall Street Journal — original report on the Google Gemini incidents.
  • Irregular — investigation and explanation of the evaluation-environment problems and remediation measures.
  • Reuters — independent report on Google’s confirmation of the incidents.
  • OpenAI, Anthropic and Meta — disclosures concerning related cybersecurity-evaluation incidents.

Written by Liam Hisona

Published: September 19, 2026, 2:10 PM PHT

Liam is just starting...

Leave a Reply

Your email address will not be published. Required fields are marked *