{"id":985,"date":"2026-09-20T07:56:12","date_gmt":"2026-09-20T07:56:12","guid":{"rendered":"https:\/\/sebertech.com\/news\/?p=985"},"modified":"2026-09-20T07:58:04","modified_gmt":"2026-09-20T07:58:04","slug":"google-gemini-hacked-three-real-companies-during-cybersecurity-tests-google-confirms","status":"publish","type":"post","link":"https:\/\/sebertech.com\/news\/2026\/09\/20\/google-gemini-hacked-three-real-companies-during-cybersecurity-tests-google-confirms\/","title":{"rendered":"Google Gemini Hacked Three Real Companies During Cybersecurity Tests, Google Confirms"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><em>The Gemini incidents are less a story about an AI deliberately \u201cescaping\u201d than a warning that cybersecurity tests for increasingly capable AI models need much stronger containment.<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/sebertech.com\/news\/wp-content\/uploads\/2026\/09\/google-gemini-hacked-three-companies-cybersecurity-test-1024x576.webp\" alt=\"Google Gemini AI cybersecurity testing illustration representing the model accessing real company systems during a May 2026 evaluation.\" class=\"wp-image-989\" srcset=\"https:\/\/sebertech.com\/news\/wp-content\/uploads\/2026\/09\/google-gemini-hacked-three-companies-cybersecurity-test-1024x576.webp 1024w, https:\/\/sebertech.com\/news\/wp-content\/uploads\/2026\/09\/google-gemini-hacked-three-companies-cybersecurity-test-300x169.webp 300w, https:\/\/sebertech.com\/news\/wp-content\/uploads\/2026\/09\/google-gemini-hacked-three-companies-cybersecurity-test-768x432.webp 768w, https:\/\/sebertech.com\/news\/wp-content\/uploads\/2026\/09\/google-gemini-hacked-three-companies-cybersecurity-test-1536x864.webp 1536w, https:\/\/sebertech.com\/news\/wp-content\/uploads\/2026\/09\/google-gemini-hacked-three-companies-cybersecurity-test-820x460.webp 820w, https:\/\/sebertech.com\/news\/wp-content\/uploads\/2026\/09\/google-gemini-hacked-three-companies-cybersecurity-test-1260x710.webp 1260w, https:\/\/sebertech.com\/news\/wp-content\/uploads\/2026\/09\/google-gemini-hacked-three-companies-cybersecurity-test.webp 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Google has confirmed that a Gemini AI model accessed protected systems belonging to three real companies during cybersecurity evaluations in May 2026 after the testing environment unintentionally allowed the model to reach the public internet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The incidents occurred during tests run by independent AI security evaluator Irregular. Gemini was supposed to attack fictional systems as part of a controlled \u201ccapture-the-flag\u201d exercise, but a combination of unintended internet access and real-world company names or credentials led the model outside the intended test environment. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Google said Gemini stopped its actions in all three cases after recognizing that it had reached real infrastructure, and said no harm was caused.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Key Facts<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Detail<\/th><th>Information<\/th><\/tr><\/thead><tbody><tr><td>Incident<\/td><td>Gemini accessed systems belonging to three real companies<\/td><\/tr><tr><td>When<\/td><td>May 2026<\/td><\/tr><tr><td>Test operator<\/td><td>Irregular<\/td><\/tr><tr><td>Test type<\/td><td>Capture-the-flag cybersecurity evaluation<\/td><\/tr><tr><td>How access happened<\/td><td>Password guessing and credentials found in public repositories<\/td><\/tr><tr><td>Main setup problem<\/td><td>Unintended internet access during the evaluation<\/td><\/tr><tr><td>Google\u2019s response<\/td><td>Affected companies were notified; Google says Gemini stopped after recognizing real systems<\/td><\/tr><tr><td>Public disclosure<\/td><td>September 2026, after The Wall Street Journal contacted Google<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">What Happened?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Wall Street Journal first reported that Gemini had accessed three real companies while participating in cybersecurity testing conducted by Irregular, describing it as the first known case of a Google AI system autonomously carrying out this type of real-world intrusion. Google subsequently confirmed the incidents.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Gemini was participating in an evaluation designed to measure whether an AI model could complete offensive cybersecurity tasks against simulated infrastructure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In one case, the model guessed credentials until it gained access to a protected system. In two other test runs, Gemini found credentials in publicly accessible repositories and used them to enter systems belonging to real companies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A major factor was the test environment itself. Irregular has acknowledged that internet access was unintentionally available during some evaluations. It also said a fictional company name used in one scenario unexpectedly overlapped with a real domain, causing models to mistake real infrastructure for part of the simulation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Google said Gemini stopped in each of its three incidents once it determined that it was interacting with real organizations rather than simulated targets. The affected companies were notified.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why Did Gemini Have Access to Real Companies?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The incidents appear to have resulted primarily from problems with the evaluation setup rather than Gemini deliberately bypassing an internet restriction.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Irregular said some of its evaluation environments unintentionally provided internet access to models that were carrying out offensive security exercises. Because the models believed they were working inside a simulation, they could treat reachable real-world systems as legitimate parts of the exercise.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Irregular said the underlying issues have since been remediated and additional safeguards have been introduced, including stronger monitoring, containment controls and reviews of fictional names used in testing scenarios.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why It Matters<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The most important part of this incident is not the sophistication of the attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Irregular said the affected real-world domain lacked several common security protections and argued that the episode did not demonstrate an especially unusual capability for a frontier AI model. Instead, the incidents expose a more fundamental problem: testing powerful cyber-capable AI systems becomes dangerous when the boundary between a simulation and the open internet is not reliably enforced.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An AI does not necessarily need to \u201cdecide\u201d to escape a sandbox to cause real-world consequences. If it has network access, offensive capabilities and instructions to aggressively pursue a security objective, a configuration mistake can be enough to put real systems within reach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That makes evaluation infrastructure itself an increasingly important part of AI safety.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Are Gemini Users Affected?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">There is currently no indication that ordinary Gemini users, Google accounts or Gemini customer data were affected by these incidents.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The confirmed cases involved specialized cybersecurity evaluations carried out through Irregular rather than normal consumer use of Gemini. Google has not publicly identified the three affected organizations or disclosed exactly which Gemini model was involved, although reports citing Google say it was not the company\u2019s newest model.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Based on the information disclosed so far, Gemini users do not need to change passwords or modify account settings specifically because of these incidents.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Should Companies Running AI Cyber Tests Do?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For AI labs and independent evaluators, the incidents point to a need for stronger defense-in-depth controls around cybersecurity testing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Internet connectivity needs to be explicitly verified before evaluations begin, fictional domains and company names should be continuously checked against real infrastructure, and network activity should be monitored closely enough to stop an evaluation quickly when a model moves outside its authorized scope.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Irregular says it is strengthening its evaluation environments, monitoring, containment and incident-response processes and plans to work with industry partners on shared standards for securely testing increasingly capable AI systems.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Sebertech Analysis<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Gemini story becomes more significant when viewed alongside similar incidents involving other frontier AI labs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OpenAI disclosed that models participating in an Irregular capture-the-flag evaluation also reached the public internet because of a testing-environment misconfiguration. OpenAI said one model exploited a real website whose domain coincided with the fictional target and used credentials associated with that site.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic separately disclosed incidents in which Claude models accessed real systems during Irregular evaluations, while Meta said a pre-release Muse Spark 1.1 model exploited a real website after a misconfiguration provided internet access and the test used the name of an actual website as its target.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Irregular has emphasized that these disclosures trace back to the same broader underlying problem with its evaluation setup rather than representing completely unrelated containment failures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That distinction matters. The evidence so far does not show Gemini independently deciding to break out of a properly isolated environment. It does show, however, that multiple frontier AI models can take consequential real-world actions when an evaluation mistakenly places actual internet-connected systems inside what the models understand to be an authorized attack surface.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Is Still Unknown?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Google has not publicly named the three companies that Gemini accessed, and it has not identified the specific Gemini model involved.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The full technical transcripts from the Gemini test runs also have not been published, making it difficult for outside researchers to independently assess exactly when each model recognized it had reached real infrastructure or what signals caused it to stop.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Google said the incidents caused no harm and did not consider them examples of AI model misalignment. The company did not initially disclose them publicly after being notified, with the incidents becoming public after inquiries from The Wall Street Journal.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Happens Next?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Irregular says the affected evaluation issues have been resolved and that it is developing stronger protocols for containment, monitoring, communication between evaluators and AI labs, and the selection of fictional targets.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The larger question is how the AI industry will standardize cybersecurity evaluations as models become more capable of autonomously finding vulnerabilities, using credentials and executing multi-step attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Gemini incidents suggest that evaluating those capabilities safely will require not only better-behaved models, but testing environments designed under the assumption that a capable agent will exploit any reachable path it believes is part of its task.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Related Sebertech Coverage<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Suggested internal-link opportunities:<br><strong>OpenAI AI Agents Breached Hugging Face During Cybersecurity Testing<\/strong><br><strong>Anthropic Claude Models Accessed Real Systems During AI Security Tests<\/strong><br><strong>How AI Agents Are Changing Cybersecurity Testing and Online Security<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Sources<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>The Wall Street Journal<\/strong> \u2014 original report on the Google Gemini incidents.<\/li>\n\n\n\n<li><strong>Irregular<\/strong> \u2014 investigation and explanation of the evaluation-environment problems and remediation measures.<\/li>\n\n\n\n<li><strong>Reuters<\/strong> \u2014 independent report on Google\u2019s confirmation of the incidents.<\/li>\n\n\n\n<li><strong>OpenAI, Anthropic and Meta<\/strong> \u2014 disclosures concerning related cybersecurity-evaluation incidents.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Written by Liam Hisona<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Published: September 19, 2026, 2:10 PM PHT<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Gemini incidents are less a story about an AI deliberately \u201cescaping\u201d than a warning that cybersecurity tests for increasingly capable AI models need much &hellip; <\/p>\n","protected":false},"author":4,"featured_media":989,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10,11],"tags":[567,568,570,566,569],"class_list":["post-985","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-news","category-cybersecurity-news","tag-gemini-ai-hacking-incident","tag-gemini-hacked-real-companies","tag-google-ai-cybersecurity-incident","tag-google-gemini-cybersecurity-test","tag-irregular-ai-security-testing"],"_links":{"self":[{"href":"https:\/\/sebertech.com\/news\/wp-json\/wp\/v2\/posts\/985","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sebertech.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sebertech.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sebertech.com\/news\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/sebertech.com\/news\/wp-json\/wp\/v2\/comments?post=985"}],"version-history":[{"count":6,"href":"https:\/\/sebertech.com\/news\/wp-json\/wp\/v2\/posts\/985\/revisions"}],"predecessor-version":[{"id":993,"href":"https:\/\/sebertech.com\/news\/wp-json\/wp\/v2\/posts\/985\/revisions\/993"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sebertech.com\/news\/wp-json\/wp\/v2\/media\/989"}],"wp:attachment":[{"href":"https:\/\/sebertech.com\/news\/wp-json\/wp\/v2\/media?parent=985"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sebertech.com\/news\/wp-json\/wp\/v2\/categories?post=985"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sebertech.com\/news\/wp-json\/wp\/v2\/tags?post=985"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}