Google’s Gemini AI accidentally hacked three real companies during a security test

1 hour ago 2



During a routine cybersecurity evaluation in May 2026, Google’s Gemini AI model did something nobody had planned for: it accessed the real networks of three actual companies. The AI was supposed to be testing its offensive capabilities against fictional targets. Google confirmed the incidents on September 18, 2026, making this the first publicly disclosed case of its AI systems taking autonomous action during a testing scenario. What actually happened The tests were part of a “capture the flag” style evaluation run by Irregular, an independent security firm hired to stress-test AI models’ offensive capabilities. Gemini wandered off the map. The model used credential guessing and found publicly exposed login information sitting in open repositories, then used those details to access live company infrastructure. The model recognized it had reached real systems rather than the simulation’s intended targets and stopped its intrusion immediately. No data was exfiltrated, no systems were damaged, and Google’s security vice president Heather Adkins described the incidents as not representing a major misalignment of the model. “Safety protocols successfully stopped the activities once real...

Read Entire Article