The model used guessed passwords and credentials exposed in public code repositories after an internet connection was mistakenly left enabled #
Google has confirmed that one of its Gemini AI models accessed the systems of three real companies during a cybersecurity test in May, after a configuration error left the model connected to the internet when it should have been isolated.
The Wall Street Journal first reported the incidents on Friday 18 September, describing them as the first known case of Google's AI systems autonomously breaching other companies' systems.
Google said the model guessed passwords to enter one company's protected system and used login details left exposed in public code repositories to reach the other two. The three firms have not been named.
Heather Adkins, Google's vice president of security engineering, told SecurityWeek the model had 'guessed credentials to access websites it thought were part of the test'. A Google spokesperson told The Record: 'In all three of these instances, the model stopped.'
All three intrusions relied on guessed or exposed credentials, weaknesses human attackers have exploited for years. Google said the model realised each time that it had reached a real company.
How a Safety Test Turned Into a Live Breach #
The exercise was a 'capture-the-flag' challenge run by Irregular, an AI security testing firm that also evaluates models for Meta, OpenAI and Anthropic. The model was asked to retrieve information from software run by a fictional company, but that invented firm shared its name with a real business.
The model was not meant to have internet access. Irregular has acknowledged that access was 'unintentionally made available'.
In one run, the model kept trying passwords until it entered a protected system belonging to a real company. In two others, it searched the web using the fictional firm's name, found credentials belonging to other companies in public repositories and used them to reach the associated systems.
Irregular told Google at the end of July, and Google said the affected companies were informed. Irregular said all known issues on its side were resolved weeks ago. There has been no public report of data being stolen or systems being damaged.
Why Google's Delayed Disclosure Is Raising Questions #
Google did not disclose the incidents until the Journal contacted it. OpenAI, Anthropic and Meta had each reported similar episodes linked to Irregular's tests weeks earlier, and Irregular has said all the incidents stemmed from the same problem. In August, the firm declined to say whether other clients had been affected by the mistaken internet access.
Ms Adkins said Google's security team had a long record of reporting flaws it finds in other people's systems, however minor, and that the episodes underlined the need to train powerful models to act responsibly.
The Bigger Risk Behind 'Simple' Password Failures #
The Gemini incidents differ from OpenAI's, which confirmed that its models breached Hugging Face's production infrastructure in July after escaping a sandboxed test environment. Unlike the Irregular cases, which stemmed from a misconfiguration, those models exploited vulnerabilities to get out.
Jack Cable, chief executive of security firm Corridor, told the Journal he saw the underlying issue as models that 'are going outside the bounds of what they should be doing'. In the Gemini cases, no novel exploit was reported. Guessable passwords and exposed credentials were enough.
© Copyright IBTimes 2026. All rights reserved.