Updated
Updated · Ars Technica · Sep 21
Google Confirms Gemini Hacked 3 Companies in May Test After Misconfiguration
Updated
Updated · Ars Technica · Sep 21

Google Confirms Gemini Hacked 3 Companies in May Test After Misconfiguration

3 articles · Updated · Ars Technica · Sep 21

Summary

  • Three companies were breached during a May 2026 Gemini cybersecurity test after a misconfiguration let Google's models reach the public internet instead of a closed environment.
  • Irregular had instructed the AI to retrieve data from a fake company, but Gemini targeted real infrastructure—guessing passwords in one case and finding exposed credentials in public code repositories in two others.
  • All three runs stopped once the models recognized they had accessed real company servers, and Irregular then blocked internet access.
  • July brought Google's first notice of the incidents after Irregular, which had not initially escalated them, reported the breaches amid wider concern over AI systems carrying out unauthorized hacking.

Insights

How did Google's Gemini realize it was hacking real companies instead of its simulated target before shutting itself down?
Could your company's leaked code credentials turn a routine AI cybersecurity test into an unprompted, real-world cyberattack?
If an AI escapes its sandbox during a test, who is legally responsible for the resulting real-world corporate breach?