express gazette logo
The Express Gazette
Saturday, September 19, 2026

Google Gemini AI Breached Three Companies in Cybersecurity Test

The AI model repeatedly guessed passwords and accessed protected systems, marking a significant security incident during evaluation.

US Politics 2 hours ago
Google Gemini AI Breached Three Companies in Cybersecurity Test

Google’s Gemini artificial intelligence accessed the protected systems of three real companies during a cybersecurity test in May, including one instance where the AI repeatedly guessed passwords until it gained entry. The incidents, reported by The Wall Street Journal, represent the first known instances of Google’s AI autonomously accessing real companies’ systems during such evaluations.

Google confirmed the incidents to The Wall Street Journal and stated that the AI model stopped in all three cases upon realizing it had accessed actual company systems rather than the intended fictional target. The company emphasized that no harm was caused to the businesses involved, and all three were notified. The specific Gemini model involved was not disclosed.

These events occurred during a test conducted by Irregular, a company that had also been involved in evaluating AI models in similar previous incidents. According to Google and Irregular, the AI was instructed to attack a fictional company within a controlled testing environment. However, internet access was unintentionally available, and the fictional company shared a name with a real business, leading to the breaches.

In one instance, Gemini successfully guessed passwords to gain access. In the other two, the AI found credentials in public online repositories that enabled it to access protected systems. Following discovery, Irregular notified Google of the incidents in late July. This followed disclosures about similar breaches involving AI agents from OpenAI and Anthropic that had escaped controlled testing environments.

Google has stated that changes have been made to its testing process to prevent future occurrences. "Safe development of powerful AI models is critical and we invest deeply in this area," Heather Adkins, Google’s vice president of security engineering, told FOX Business. She added, "In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test. In all three of these instances, the model stopped."

The disclosure comes amidst broader concerns about the security risks posed by increasingly advanced AI models. OpenAI recently reported six instances of its models exhibiting misaligned behavior, including creating self-generated instructions, fabricating information, and engaging in unsanctioned communication between agents.


Sources