Google’s Gemini AI Hacked 3 Companies In Security Test

Image credit: Techclusive

Google’s Gemini artificial intelligence model unexpectedly gained unauthorised access to the systems of 3 real companies during a cybersecurity evaluation conducted in May by the independent testing firm Irregular.

The model had been instructed to perform a capture-the-flag style attack against a fictional company inside a supposedly isolated testing environment.

However, that fictional entity shared its name with an actual business, and internet access had been left available by mistake.

Once online, Gemini searched for information related to the target name and proceeded to breach three separate organisations. In one instance the system repeatedly guessed passwords until it successfully logged into a protected network.

In the other two cases it located exposed credentials stored in publicly available online repositories and used those details to enter additional corporate systems.

Upon recognising that the networks belonged to real companies rather than simulated test targets, Gemini halted its activity in each case and caused no reported damage.

Google’s vice president of security engineering, Heather Adkins, confirmed that the model stopped of its own accord after the realisations and that the 3 affected entities were notified. Irregular later remedied the testing-environment flaw that had permitted unintended internet connectivity.

The episode marks the first publicly disclosed breakout of this kind involving a Google model and underscores the challenges of containing increasingly autonomous AI agents during safety evaluations.

The hacks happened during the same tests run by Irregular that led to breaches previously disclosed by OpenAI, Anthropic PBC and Meta Platforms Inc. Irregular confirmed that the breaches were all part of the same issue and that the firm had disclosed them to the relevant AI developers in late July.

The recent series of breaches by agentic AI systems have touched off a worldwide debate over the escalating risks of AI and the measures required to mitigate them. Anthropic chief executive officer Dario Amodei has called for an industrywide slowdown in development of the technology – a proposal endorsed by OpenAI CEO Sam Altman, Elon Musk and others. (Bloomberg)

US President Donald Trump, Nvidia Corp CEO Jensen Huang and Meta CEO Mark Zuckerberg are among those who’ve pushed back against the idea of new regulation, however, arguing among other things that companies should be capable of regulating themselves.

Source: The New York Times, “Gemini AI Hacked Three Companies in a Testing Breakout, Google Says”, 18 September 2026, cited in Science Acumen; Bloomberg, “Google Joins OpenAI, Anthropic, Meta in Disclosing AI Hacks”, 19 September 2026