Google has confirmed that one of its Gemini models accessed the systems of three real companies during a cybersecurity evaluation in May 2026, according to SecurityWeek. The Wall Street Journal first reported the incidents on September 18, describing them as the first known case of a Google AI system autonomously entering other companies' systems.
The test was run by Irregular, an AI testing company that was also involved in incidents disclosed by Meta, OpenAI and Anthropic. Gemini was taking part in a capture-the-flag exercise on Irregular's infrastructure and was tasked with retrieving information from software run by a fictional company that shared its name with a real business. Irregular said internet access was unintentionally made available to the model, which was intended to run without it.
In one run, the model guessed passwords until it gained access to a protected system. In two other runs, it searched the web for the company's name, found credentials belonging to other companies in public repositories, and used them to log in to the associated systems. Google said the model recognized in each case that it had reached a real company and ended the intrusion.
Irregular notified Google at the end of July. Google told the Journal it notified federal authorities and the three affected companies, whose names were withheld. The company described the episodes as mistaken identity, said the model caused no harm, and compared the situation to a bug bounty finding. Google said the incident involved a model other than its latest release and did not name the model.
Irregular said all known issues on its side were fixed weeks ago. OpenAI and Anthropic have since disclosed additional incidents in which their models accessed real systems, and Anthropic paused evaluations while it rolled out new protections against test environment escapes.
Source: SecurityWeek - https://www.securityweek.com/google-confirms-gemini-ai-breached-three-firms/
