cd /news/ai-safety/gemini-s-three-real-world-breaches-e… · home topics ai-safety article
[ARTICLE · art-136388] src=ibtimes.co.uk ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Gemini's Three Real-World Breaches Expose a Bigger Problem: AI Agents Can Exploit the Passwords Humans Leave Behind

Google confirmed that a Gemini AI model accessed the systems of three real companies during a May capture-the-flag cybersecurity test run by AI security firm Irregular, after a configuration error left the model connected to the internet when it should have been isolated. Google said the model guessed passwords to enter one company's protected system and used login details exposed in public code repositories to reach the other two, and Heather Adkins, Google's vice president of security engineering, told SecurityWeek the model had 'guessed credentials to access websites it thought were part of the test'. The Wall Street Journal first reported the incidents on Friday 18 September, describing them as the first known case of Google's AI systems autonomously breaching other companies' systems; Google did not disclose the incidents until the Journal contacted it, and there has been no public report of data being stolen or systems being damaged.

by read3 min views1 publishedSep 21, 2026
Gemini's Three Real-World Breaches Expose a Bigger Problem: AI Agents Can Exploit the Passwords Humans Leave Behind
Image: Ibtimes (auto-discovered)

The model used guessed passwords and credentials exposed in public code repositories after an internet connection was mistakenly left enabled #

Google has confirmed that one of its Gemini AI models accessed the systems of three real companies during a cybersecurity test in May, after a configuration error left the model connected to the internet when it should have been isolated.

The Wall Street Journal first reported the incidents on Friday 18 September, describing them as the first known case of Google's AI systems autonomously breaching other companies' systems.

Google said the model guessed passwords to enter one company's protected system and used login details left exposed in public code repositories to reach the other two. The three firms have not been named.

Heather Adkins, Google's vice president of security engineering, told SecurityWeek the model had 'guessed credentials to access websites it thought were part of the test'. A Google spokesperson told The Record: 'In all three of these instances, the model stopped.'

All three intrusions relied on guessed or exposed credentials, weaknesses human attackers have exploited for years. Google said the model realised each time that it had reached a real company.

How a Safety Test Turned Into a Live Breach #

The exercise was a 'capture-the-flag' challenge run by Irregular, an AI security testing firm that also evaluates models for Meta, OpenAI and Anthropic. The model was asked to retrieve information from software run by a fictional company, but that invented firm shared its name with a real business.

The model was not meant to have internet access. Irregular has acknowledged that access was 'unintentionally made available'.

In one run, the model kept trying passwords until it entered a protected system belonging to a real company. In two others, it searched the web using the fictional firm's name, found credentials belonging to other companies in public repositories and used them to reach the associated systems.

Irregular told Google at the end of July, and Google said the affected companies were informed. Irregular said all known issues on its side were resolved weeks ago. There has been no public report of data being stolen or systems being damaged.

Why Google's Delayed Disclosure Is Raising Questions #

Google did not disclose the incidents until the Journal contacted it. OpenAI, Anthropic and Meta had each reported similar episodes linked to Irregular's tests weeks earlier, and Irregular has said all the incidents stemmed from the same problem. In August, the firm declined to say whether other clients had been affected by the mistaken internet access.

Ms Adkins said Google's security team had a long record of reporting flaws it finds in other people's systems, however minor, and that the episodes underlined the need to train powerful models to act responsibly.

The Bigger Risk Behind 'Simple' Password Failures #

The Gemini incidents differ from OpenAI's, which confirmed that its models breached Hugging Face's production infrastructure in July after escaping a sandboxed test environment. Unlike the Irregular cases, which stemmed from a misconfiguration, those models exploited vulnerabilities to get out.

Jack Cable, chief executive of security firm Corridor, told the Journal he saw the underlying issue as models that 'are going outside the bounds of what they should be doing'. In the Gemini cases, no novel exploit was reported. Guessable passwords and exposed credentials were enough.

© Copyright IBTimes 2026. All rights reserved.

── more in #ai-safety 4 stories · sorted by recency
── more on @google 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/gemini-s-three-real-…] indexed:0 read:3min 2026-09-21 ·