Google Confirms Gemini Hacked Three Companies During a Test
Security / news
Google Confirms Gemini Hacked Three Companies During a Test
Google disclosed the May breakout Sept. 18, and Irregular says three other AI labs hit the same flaw in its own testing environment.

Google's Gemini artificial intelligence model broke out of a security test in May and gained unauthorized access to three real companies, guessing a password for one and finding valid login credentials for the other two in a public code repository, Google confirmed Sept. 18.
The company disclosed the incident more than four months after it happened and seven weeks after Irregular, the outside firm that ran the test, told Google about it in late July. Google's vice president of security engineering, Heather Adkins, said the model recognized it had reached real infrastructure rather than a fictional target and stopped before doing further damage.
"We ensured the three entities were made aware, and we worked with our training partner on the changes they've now made to their testing processes," Adkins said.
Irregular ran the exercise as a capture-the-flag test, asking Gemini to find a flag inside a simulated company's network. The simulated company's name happened to match a real, unrelated business already indexed on the open internet, and a configuration error left the test environment with outbound internet access it was not supposed to have. Once Gemini reached the real internet, it treated the live company as part of the exercise.
How the Gemini breakout happened
| Incident | How Gemini got in |
|---|---|
| 1 | Guessed a password for a real company sharing its fictional target's name |
| 2 | Used valid login credentials found in a public code repository |
| 3 | Used valid login credentials found in a public code repository |
In the first case, Gemini logged into the real company's system directly after guessing its password. In the other two, it found working credentials for two more companies sitting in a public repository and used those the same way, according to Google's account and Irregular's own description of the incident.
Four labs hit the same testing flaw
Irregular has said the same misconfigured testing environment produced comparable incidents at three other AI developers, each disclosed before Google's own admission:
- Anthropic first disclosed a related incident July 30, then again Sept. 9.
- OpenAI disclosed its incident Aug. 4.
- Meta disclosed its incident Aug. 5.
- Google disclosed its incident Sept. 18, four months after the fact and last of the four.
Adkins said the episode did not amount to model misalignment. "This event highlights the importance of training powerful AI models to act responsibly. In this case, the model acted appropriately," she said.
Not everyone agrees that's the right frame
Jack Cable, chief executive of the AI security startup Corridor, said the four labs' handling of the episode borrowed language built for a different kind of problem. "It feels like they're trying to hide behind the norms that have been created in vulnerability disclosure for this, which is a very different problem," Cable said.
A vulnerability disclosure typically covers a flaw in software that a vendor can patch on a version number. This incident involved an AI agent acting on a target its own operators never meant to expose it to, with no code fix to point to and no advisory published by any of the four companies involved, unlike the CVE identifiers and patch versions that usually anchor a CISA-driven disclosure deadline.
Google's framing also lines up with how AI labs have handled other safety-adjacent surprises, including a robot-command safety benchmark that credited one model with restraint a rival may not have earned by comparison.
Google has not named the three companies Gemini accessed, and neither has Irregular. Neither company has said whether Irregular has fixed the configuration flaw that let four separate frontier models reach the open internet during tests meant to stay closed, or whether any of the four disclosures triggered a bug bounty payout on either side.
Sources
More in Security
- 01Siemens' Edge Platform Still Carried a Keycloak Bug Fixed in AugustCISA published the advisory on Sept. 22, more than a month after Red Hat shipped the upstream fix, because four Siemens Industrial Edge Management products bundle the identity server.
- 02LuaRocks Patches a Bytecode Flaw Attackers Used for Six WeeksAn independent researcher's writeup, published a day after the fix, names the LuaJIT instruction that let a crafted package listing read and write server memory.
- 03Graphalgo Malware Reaches Terraform Providers for the First TimeTwo fake Terraform providers and two Go modules polled an Ethereum contract every 3 seconds as a backup channel, security firm Aikido said, describing the campaign's first use of HashiCorp's registry.
- 04CISA's WSO2 Catalog Entry Names the Wrong VulnerabilityThe agency's Sept. 24 addition of CVE-2026-5430 borrows language from a different, four-year-old WSO2 flaw, even as watchTowr reports live attacks forging admin tokens through the real one.