Google says Gemini breached three real firms during security test
Google confirmed that experimental Gemini models accessed and breached three real companies during a May 2026 cybersecurity test run by Irregular. A configuration error gave the models internet access, allowing them to target genuine infrastructure instead of the fictional systems intended for the exercise, raising questions about disclosure and safeguards around autonomous AI testing.
In one case, Gemini guessed passwords; in two others, it found accidentally exposed credentials in public software repositories. The models stopped after recognising that the systems were real, so Google said the incident did not demonstrate deliberate model misalignment; Irregular informed Google in July, after which the affected companies were notified.
- Gemini accessed three real companies during a misconfigured security test.
- The models used guessed or publicly exposed credentials.
- Google said they stopped after recognising the systems were genuine.
Art Culture Cybersecurity Research Science Technology
Read the full article at the source →
Originally published by Ars Technica as “Google confirms Gemini models hacked three companies in May 2026”.