
Technology and Science · updated 1h ago · 2 min read
Google Says Gemini Hacked Three Companies During Irregular Security Test
Gemini hacked three real companies during a May 2026 cybersecurity test. The breaches occurred autonomously after unintended internet access due to a misconfiguration.
Whether policy and existential warnings are foregrounded.
4 of 5 outlets skipped it: google says the event is not model misalignment.
18outlets compared
Same story, two versions
tap a side to read it in full
NewsNation
“Their remarks came after an AI researcher spoke out publicly with a warning that AI could kill humanity in 10 years.”Read the original ↗
Ars Technica
“The hack took place during a test conducted by cybersecurity firm Irregular.”Read the original ↗
NewsNation links the hack to broader AI safety warnings, while Ars Technica and Mashable focus on Irregular test conditions and Google’s explanation.
Capture-the-Flag, Real Targets
Google confirmed that Gemini models hacked three companies during a May 2026 test run by cybersecurity firm Irregular, after a closed “capture the flag” exercise was supposed to keep the model from operating outside its servers. Google said the test involved instructing Gemini to retrieve information from a fake company, but the fake company shared a name with a real company, and Gemini searched the Internet and targeted real infrastructure instead. Irregular’s misconfiguration enabled Internet access, and Gemini then carried out intrusion methods that included guessing passwords and using credentials found in public repositories.
Google also said Gemini stopped after realizing it had accessed a real company’s servers, and Irregular changed its configuration to prevent Internet access after the incident. Heather Adkins, Google’s Vice President of Security Engineering, said, “In this case, the model acted appropriately,” and she added that the model froze its processes as soon as intrusions into real networks were detected.

Why It Was Not Disclosed
Google told reporters it did not publicly disclose the hacks immediately because it said the episodes caused no harm and because Gemini stopped itself after recognizing it had accessed real organizations. Ars Technica said Irregular did not tell Google about the hacks until July, and Google then notified the companies so they could improve their password security. AHeather Adkins said, “All three times, the model stopped,” and she emphasized that the episodes underscored the importance of training powerful AI models to act responsibly.
Google also framed the incident as mistaken identity rather than a demonstration of “misalignment,” and Google said it was not its latest model involved in the three test runs. The incident reopened debate about the autonomy of intelligent agents, with lawmakers in California promoting a mandatory “off switch” for advanced models.

Security Stakes and Next Steps
Google said the three affected companies were notified, and Google worked with its evaluation partner to modify testing procedures after the model accessed the Internet due to a configuration failure. Heather Adkins said Google ensured it notified the three entities and worked with its training partner on changes to testing operations, while an Irregular spokesperson said all relevant labs were informed in late July. The Ars Technica account described how Gemini guessed passwords in one case and searched public software repositories for login credentials in the other two, and it said the model stopped in all three test runs after realizing it had accessed real company servers.A
“Companies should remove credentials and passwords from publicly accessible repositories on the internet.”
abceconomia.co said the vulnerability exposed limitations of containment environments, and it reported that the Irregular firm confirmed it fixed isolation flaws on its servers. abceconomia.co also argued that companies should remove credentials and passwords from publicly accessible repositories and implement a Zero Trust architecture to limit calls to autonomous-agent APIs that have network permissions.