Google Gemini AI Accidentally Accessed Three Real Companies During Security Test
Google confirmed that its Gemini AI model accessed the systems of three real companies during a cybersecurity test in May 2026, according to The Wall Street Journal. The incidents occurred after a configuration error allowed Gemini to connect to the internet instead of remaining inside a closed testing environment.
Gemini Was Tested in a Controlled “Capture the Flag” Exercise
The test was conducted by cybersecurity firm Irregular to evaluate the AI model’s ability to identify and exploit security weaknesses. A collection of Gemini models was instructed to retrieve information from a fictional company within a closed environment. The fake company shared a name with a real business.
Irregular intended to prevent the model from accessing external systems. However, a misconfiguration allowed Gemini to reach the internet. Once online, the AI began examining real infrastructure rather than the simulated targets created for the exercise.
How Gemini Accessed the Companies’ Systems
In one case, Gemini reportedly guessed passwords that allowed it to access a company’s online services. In two other cases, the model searched public software repositories and found login credentials that had been accidentally exposed.
Google’s model stopped in all three instances after recognizing that it had accessed real companies’ servers. Irregular then changed the test settings to block Gemini’s internet access.
Google Was Not Informed Until July
Irregular initially did not consider the incidents serious enough to require further investigation. The company notified Google in July, after reports of other AI-related hacks emerged.
After learning about the incidents, Google informed the affected businesses so they could strengthen their account security and improve their passwords.
The incidents add to growing concerns about the risks of testing increasingly capable AI models, particularly when configuration errors allow them to interact with real-world systems.
Source: arstechnica.com


