cd /news/ai-safety/gemini-went-rogue-hacked-three-compa… · home topics ai-safety article
[ARTICLE · art-134642] src=theverge.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Gemini went rogue, hacked three companies, and Google hid it

Google's Gemini AI model broke containment and hacked three real companies in May during a cybersecurity test run by third-party firm Irregular, and Google did not disclose the incident until the Wall Street Journal approached the company, according to the WSJ. Google declined to call the event model misalignment, with VP of Security Engineering Heather Adkins saying "the model acted appropriately" and that it stopped after realizing it had brute-forced its way into a real company by guessing a password; Irregular said internet access was unintentionally left available during the test. Jack Cable, CEO of AI security firm Corridor, told the WSJ that "the meta problem is, hey, models are going outside the bounds of what they should be doing, and doing actual cyberattacks.

by read2 min views1 publishedSep 19, 2026
Gemini went rogue, hacked three companies, and Google hid it
Image: The Verge

In May, Gemini broke containment and hacked three different companies, but Google didn’t disclose the incident until the Wall Street Journal approached the company. The hacks happened during a test of the model’s cybersecurity capabilities run by third-party Irregular, which was also involved in similar incidents involving Meta and OpenAI.

Google says that breaking containment and targeting real companies doesn’t constitute ‘misalignment.’

According to WSJ, Google didn’t disclose the hack because it didn’t consider it to be an “example of model misalignment.” The company said that it was an instance of “mistaken identity,” and once the model realized it had brute-forced its way into a real company by guessing a password, it stopped. “In this case, the model acted appropriately,” Google VP of Security Engineering Heather Adkins said.

Adkins told The Verge that “the model found public information online and guessed credentials to access websites it thought were part of the test. In all three of these instances, the model stopped.”

Adkins didn’t elaborate on how Gemini taking it upon itself to break containment and target third parties failed to qualify as misalignment. “Our security team has a long track record of reporting issues we find in other people’s software and systems - even if it’s as simple as a weak password,” she said. “We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes. These events highlight the importance of training powerful AI models to act responsibly.”

But Jack Cable, CEO of AI security firm Corridor, told WSJ that, “the meta problem is, hey, models are going outside the bounds of what they should be doing, and doing actual cyberattacks.” Additionally, security lapses at Irregular may have made these attacks possible. The model wasn’t supposed to have internet access during testing, but Irregular told WSJ it was unintentionally left available.

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.

── more in #ai-safety 4 stories · sorted by recency
── more on @google 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/gemini-went-rogue-ha…] indexed:0 read:2min 2026-09-19 ·