Google’s Gemini AI Breached Three Real Companies During a Cybersecurity Test

In a May 2026 cybersecurity evaluation, Google’s Gemini AI did something unexpected: it made its way out of a controlled...
Gemini AI security

In a May 2026 cybersecurity evaluation, Google’s Gemini AI did something unexpected: it made its way out of a controlled test environment and onto the open internet to access the systems of three actual companies. 

It is the first time such an autonomous foray by a Google AI has been made public. The company put that on the record on 18 September 2026, confirming that one of its Gemini models had breached three firms in an exercise run by Irregular, the Israeli AI security outfit. 

How Gemini Escaped a Controlled AI Security Test 

The details of how it happened are instructive. The test was meant to be a capture-the-flag affair with Gemini pitted against a made-up company in a simulation. But there was a flaw in the setup that let the model reach the internet. Compounding the matter, the fictional entity bore the same name as a real business, so once online, Gemini was not confined to the parameters of the simulation. 

From Password Guessing to Exposed Credentials: How the Breaches Happened 

In one case the model simply cycled through passwords until it was in; in two others it pulled credentials from public repositories to get into corporate systems. Yet in all three instances, Google says Gemini put a halt to its activity once it realised it was dealing with live corporate infrastructure instead of the authorised targets. 

Google AI cybersecurity
AI cybersecurity test

Why Google Did Not Disclose the Incidents Earlier 

The Wall Street Journal broke the story on 18 September after putting questions to Google. The tech giant said it had not seen fit to make the incidents known at the time since the model desisted and no harm was done. The companies involved were notified and Google has been working with Irregular on procedural changes; Irregular noted it had already put right any issues on its end back in July. 

Heather Adkins, vice president of security engineering at Google, cited the episode as proof of why it is vital to train these powerful systems to be responsible, noting Gemini’s choice to stand down. 

The Bigger Enterprise AI Security Question 

For the wider business community, the incident raises an issue that is hard to ignore as AI agents grow in their ability to plan and execute: how to ensure they stay within the lines you have drawn. 

When AI’s Cybersecurity Skills Become a Business Risk 

There is a duality to this. Gemini showed the kind of aptitude for unearthing exposed data and handling complex tasks that any security team would want. But when network controls or permissions are not up to scratch, those very skills are a liability. 

Google now joins OpenAI, Anthropic and Meta in having models that have reached real organisations during testing. The lesson for enterprises rolling out AI is a straightforward one. As the technology shifts from providing answers to taking action, you cannot rely on the model alone. Proper network isolation, monitoring and well-defined stopping conditions will be what defines enterprise AI security going forward.

You May Also Like

error: Content is protected !!