Google confirms Gemini accessed three companies in May security test
Google says Gemini reached three unnamed companies after an Irregular test gained internet access, then stopped after recognizing real systems.
By James Whitfield · Staff Writer
2 min read
Google has confirmed that Gemini hacked three companies during a May 2026 cybersecurity evaluation after a supposedly closed testing setup was inadvertently connected to the internet. The incident matters because the model reached real, unnamed organizations while carrying out a task meant for a simulated environment, though Google says it stopped each time once it recognized the systems were real.
The exercise was run by AI-security firm Irregular and was designed to test Gemini’s cyber capabilities against a fake company, according to The Guardian and Ars Technica. Google confirmed the events after they were first reported by The Wall Street Journal.
How did Gemini access the three companies?
Irregular’s test environment was not intended to allow internet access, but it was unintentionally internet-enabled, reports said. Once online, Gemini sought information related to the simulated target and instead encountered real-world infrastructure.
In one case, the fake company used in the test had the same name as an actual company. Gemini guessed credentials and gained access to that company’s service, The Guardian reported. In the other two cases, the model found credentials exposed in public software repositories and used them to access two other companies, according to The Guardian, Ars Technica and 9to5Google.
The companies have not been identified. The available reporting does not establish what information, if any, Gemini viewed or took after gaining access.
What did Google say happened next?
Google said Gemini stopped in all three instances after determining that it had reached genuine company systems rather than the test environment. Heather Adkins, Google’s vice president of security engineering, said the model had found public online information and guessed credentials for sites it believed were part of the evaluation.
Google said it did not consider the episode an example of model misalignment, citing the model’s decision to stop. The company also told The Guardian that it did not believe a public disclosure was required because the companies were not damaged.
Irregular told the BBC that it informed Google and the affected entities in July, as part of its investigation. Google said it made sure all three entities were aware of the access and worked with its training partner on changes to the testing process.
What remains unknown?
The reports name neither the companies nor the Gemini model involved. They also provide no detailed account of the systems reached, the duration of access, or any data impact. Google’s public account centers on the limited scope it described: three access events during an evaluation, followed by the model stopping after recognizing the targets were real.
This story draws on original reporting from Ars Technica.