# Did Google’s Gemini AI Just Hack Three Real Companies? Here’s What Happened

> Source: <https://in.mashable.com/tech/114086/did-googles-gemini-ai-just-hack-three-real-companies-heres-what-happened>
> Published: 2026-09-19 05:40:17+00:00

Google’s Gemini AI models reportedly hacked into three real companies during a cybersecurity test conducted by independent evaluator Irregular in May, marking the first known instance of [Google](https://in.mashable.com/pixel-11/113734/google-pixel-11-pro-xl-review-a-great-phone-that-doesnt-need-to-show-off)’s [AI](https://in.mashable.com/tech/113781/what-is-meta-muse-ai-agent-know-features-india-roll-out-of-the-new-personal-ai-assistant) systems autonomously carrying out such an action. The [Gemini](https://in.mashable.com/tech/113838/matcha-craze-takes-over-india-as-google-searches-for-how-to-make-matcha-soar-1300) model was given internet access as part of the test and ended up breaching external companies, according to a *Wall Street Journal* report. However, Google said the AI recognised what was happening and stopped on its own before causing any damage.

## Gemini accidentally reached real companies

Google says Gemini’s hacking incidents stemmed from a mix-up during a “capture the flag” [cybersecurity](https://in.mashable.com/tech/113579/openai-launches-gpt-6-astra-with-critical-level-cybersecurity-capabilities-heres-what-it-offers) exercise run by Irregular. The AI was supposed to retrieve information from software belonging to a fictional company, but that company happened to share its name with a real business. Although Gemini was not supposed to have internet access, it was unintentionally enabled, allowing the model to reach the real company’s systems. In one case, it reportedly guessed passwords, while in two others it found credentials exposed in public repositories and used them to gain access.

Google’s Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the company’s AI autonomously committing such an act [https://t.co/Og6NwxRIKQ](https://t.co/Og6NwxRIKQ)

[September 18, 2026](https://x.com/WSJTech/status/2101072258022388109?ref_src=twsrc%5Etfw)

## Gemini stopped when it realised the mistake

The key difference in Google’s case was what Gemini did after reaching the real companies. Google said the model recognised that it had accessed genuine businesses rather than simulated targets and stopped the activity on its own. The company was informed about the incidents in July and subsequently notified the three affected businesses and federal authorities. Google did not name the companies or reveal which Gemini model was involved, but said the incidents did not involve its newest model.

## Google sees it as a safety test, not a harmful attack

Google said it did not consider the incidents serious enough to warrant a public disclosure because Gemini ended the intrusions itself. Heather Adkins, Google’s VP of security engineering, said the episode demonstrated the importance of teaching powerful AI systems to behave responsibly and argued that Gemini acted appropriately in this situation. Irregular, meanwhile, said the problems were identified and resolved, adding that similar incidents involving other major AI companies had also been investigated.

## AI hacking incidents are raising bigger questions

The Gemini episode comes after similar cases involving AI models from [OpenAI](https://in.mashable.com/tech/113482/apple-claims-ex-employee-stole-trade-secrets-openai-says-apple-has-no-proof), [Anthropic](https://in.mashable.com/tech/113906/why-are-sam-altman-elon-musk-anthropic-ceo-calling-for-a-slower-ai-race-the-safety-warning-explained) and [Meta](https://in.mashable.com/tech/113061/oakley-meta-hstn-smart-glasses-review-specs-on-steroids), with Irregular linked to several of these cybersecurity tests. However, the outcomes have differed: Anthropic previously disclosed a case where its [Claude](https://in.mashable.com/tech/111902/claude-ai-subscription-just-got-easier-in-india-as-anthropic-rolls-out-local-pricing) model continued accessing systems after recognising that a real company might be involved, while an OpenAI model reportedly believed the real target was still part of the simulation. The latest disclosures are adding to wider concerns about increasingly autonomous AI systems, as researchers and AI companies debate how quickly these models should be developed and how strong their safety safeguards need to be.

**ALSO SEE:**
