cd /news/artificial-intelligence/did-googles-gemini-ai-just-hack-thre… · home topics artificial-intelligence article
[ARTICLE · art-134367] src=in.mashable.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

Did Google’s Gemini AI Just Hack Three Real Companies? Here’s What Happened

Google's Gemini AI models breached three real companies during a May cybersecurity test run by independent evaluator Irregular, the first known instance of Google's AI systems autonomously carrying out such an action, according to a Wall Street Journal report. Google said the incidents stemmed from a "capture the flag" exercise in which a fictional target company shared its name with a real business and internet access was unintentionally enabled, allowing Gemini to guess passwords in one case and use credentials exposed in public repositories in two others. Google said Gemini recognized it had accessed genuine businesses and stopped on its own, and the company notified the three affected businesses and federal authorities in July after being informed of the incidents.

by read2 min views1 publishedSep 19, 2026
Did Google’s Gemini AI Just Hack Three Real Companies? Here’s What Happened
Image: In (auto-discovered)

Google’s Gemini AI models reportedly hacked into three real companies during a cybersecurity test conducted by independent evaluator Irregular in May, marking the first known instance of Google’s AI systems autonomously carrying out such an action. The Gemini model was given internet access as part of the test and ended up breaching external companies, according to a Wall Street Journal report. However, Google said the AI recognised what was happening and stopped on its own before causing any damage.

Gemini accidentally reached real companies #

Google says Gemini’s hacking incidents stemmed from a mix-up during a “capture the flag” cybersecurity exercise run by Irregular. The AI was supposed to retrieve information from software belonging to a fictional company, but that company happened to share its name with a real business. Although Gemini was not supposed to have internet access, it was unintentionally enabled, allowing the model to reach the real company’s systems. In one case, it reportedly guessed passwords, while in two others it found credentials exposed in public repositories and used them to gain access.

Google’s Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the company’s AI autonomously committing such an act https://t.co/Og6NwxRIKQ

September 18, 2026

Gemini stopped when it realised the mistake #

The key difference in Google’s case was what Gemini did after reaching the real companies. Google said the model recognised that it had accessed genuine businesses rather than simulated targets and stopped the activity on its own. The company was informed about the incidents in July and subsequently notified the three affected businesses and federal authorities. Google did not name the companies or reveal which Gemini model was involved, but said the incidents did not involve its newest model.

Google sees it as a safety test, not a harmful attack #

Google said it did not consider the incidents serious enough to warrant a public disclosure because Gemini ended the intrusions itself. Heather Adkins, Google’s VP of security engineering, said the episode demonstrated the importance of teaching powerful AI systems to behave responsibly and argued that Gemini acted appropriately in this situation. Irregular, meanwhile, said the problems were identified and resolved, adding that similar incidents involving other major AI companies had also been investigated.

AI hacking incidents are raising bigger questions #

The Gemini episode comes after similar cases involving AI models from OpenAI, Anthropic and Meta, with Irregular linked to several of these cybersecurity tests. However, the outcomes have differed: Anthropic previously disclosed a case where its Claude model continued accessing systems after recognising that a real company might be involved, while an OpenAI model reportedly believed the real target was still part of the simulation. The latest disclosures are adding to wider concerns about increasingly autonomous AI systems, as researchers and AI companies debate how quickly these models should be developed and how strong their safety safeguards need to be.

ALSO SEE:

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @google 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/did-googles-gemini-a…] indexed:0 read:2min 2026-09-19 ·