TechDogs-"Google Gemini Hacked 3 Companies During A Cybersecurity Test"

Cyber Security

Google Gemini Hacked 3 Companies During A Cybersecurity Test

By Amrit Mehra

Updated on Mon, Sep 21, 2026

Overall Rating

Google's Gemini AI was supposed to prove its cybersecurity skills in a controlled evaluation.

Instead, it crossed into three real company systems, using guessed or publicly exposed credentials before stopping its activity once it recognized the targets were outside the test.
 

TL;DR

 
  • Gemini accessed three real company systems during a May cybersecurity evaluation conducted by Irregular.
  • One system was accessed after Gemini guessed a password, while two were reached using credentials found in a public repository.
  • Irregular said the testing issue has been fixed, while Google said Gemini stopped in each case and highlighted the need to train powerful AI systems to act responsibly.
 

Google Gemini Accessed Three Real Company Systems During An AI Security Test


During a May cybersecurity evaluation conducted by Irregular, Gemini was given internet access and expected to operate against test targets. Instead, the model identified public information online and gained access to three websites it believed were part of the exercise, making this the first known instance of Google's AI autonomously hacking real companies, according to reports.

In one case, the model repeatedly guessed passwords until it entered a protected system. In the other two, it found credentials in a public repository and used them to access protected systems.

Crucially, this was not reported as Gemini deliberately seeking real-world victims. Google said the model stopped in all three instances after recognizing it had reached systems outside the intended test, while the identities of the affected companies have not been disclosed.
 

TechDogs-"An Image Of The Logos Of Google And Gemini"  

Irregular's Security Test Error Opened A Path From Simulation To Real Systems


The unusual incident appears to have started with the evaluation environment rather than a planned attack. The reporting indicates that a fictional company name used during capture-the-flag exercises unintentionally matched a real domain, giving the AI systems a path to targets beyond the intended simulation.

That detail puts the spotlight on the testing process itself. Irregular describes itself as a frontier security lab that builds research platforms designed to simulate and monitor real-world AI security scenarios, meaning the incident occurred inside an exercise intended to probe exactly these kinds of risks.

In a statement, Irregular said it informed Google and all affected entities in July. "Irregular took immediate action, and all known issues on our end were remedied and resolved weeks ago," the company said.
 

 

Google Says Gemini Stopped After The Unauthorized Access


Google has framed Gemini's behavior after the breaches as an important distinction. Heather Adkins, Google's vice president of Security Engineering, said the three affected entities were informed and that Google worked with its training partner on changes to the testing process.

"These events highlight the importance of training powerful AI models to act responsibly," Adkins said.

Further reporting noted that Google does not view the incident as model misalignment because Gemini halted its activity after safety mechanisms were triggered. Similar evaluation incidents involving Irregular have also previously been disclosed by Meta, Anthropic, and OpenAI.

That makes Gemini's case part of a broader issue emerging as AI agents gain more autonomy, internet access, and the ability to interact with protected systems. The irony is difficult to miss: a test designed to evaluate cyber capabilities ended up demonstrating how quickly an AI security exercise can spill beyond its intended boundaries.

First published on Mon, Sep 21, 2026

Enjoyed what you read? Great news – there’s a lot more to explore!

Dive into our content repository of the latest tech news, a diverse range of articles spanning introductory guides, product reviews, trends and more, along with engaging interviews, up-to-date AI blogs and hilarious tech memes!

Also explore our collection of branded insights via informative white papers, enlightening case studies, in-depth reports, educational videos and exciting events and webinars from leading global brands.

Head to the TechDogs homepage to Know Your World of technology today!

Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.

Loading comments...

  • Dark
  • Light