Reported by Simon Daniel Yusuph l Journalist at Weng Global
Google has confirmed that its Gemini artificial intelligence model accessed the systems of three real companies during a cybersecurity evaluation in May 2026, after the model unexpectedly gained access to the live internet and used credentials to enter systems it believed were part of a controlled test.
The incidents occurred during cybersecurity testing conducted by Irregular, an independent company that evaluates the security capabilities of artificial intelligence systems. Google said the model was operating within a testing exercise designed around fictional companies, but unintended internet access allowed Gemini to interact with real-world systems.
The disclosure has drawn attention to the growing ability of AI systems to carry out multi-step cybersecurity operations with limited human intervention. It also highlights the challenges involved in ensuring that increasingly autonomous AI agents remain within the boundaries of controlled testing environments.
Gemini Accessed Real Companies During a Controlled Test
According to Google, Gemini was asked to perform cybersecurity tasks as part of a standard evaluation. The model searched for information online and used credentials it discovered or generated during the exercise.
In one of the three incidents, Gemini reportedly guessed passwords repeatedly until it obtained access to a protected system.
In the other two cases, the model located credentials in publicly accessible repositories and used them to enter systems belonging to real companies. The companies themselves were not identified publicly by Google.
The model was not originally intended to target those real-world systems. Reporting from Reuters and other outlets indicates that the testing environment involved fictional scenarios, while unintended internet connectivity created a pathway to actual systems.
Google Says Gemini Stopped After Recognising the Mistake
Google Vice President of Security Engineering Heather Adkins said the company informed the three affected entities after the incidents were identified.
Google also said Gemini stopped its activity in each case after recognising that it had accessed real companies rather than the fictional targets associated with the test.
Adkins described the incidents as an indication of why powerful AI systems need to be trained to behave responsibly, while Google said it worked with Irregular to make changes to the testing process.
Irregular also said the relevant issues on its side had been addressed and that affected AI laboratories were notified.
The company had reportedly informed Google about the incidents in July, while Google confirmed them publicly only after being approached by journalists.
Why Internet Access Became a Critical Issue
The incident illustrates the risks associated with giving AI systems access to external networks while evaluating their ability to perform cybersecurity tasks.
An AI model capable of searching the internet, identifying useful information, testing credentials and interacting with computer systems can potentially move through several stages of a cyber operation much faster than a traditional human-only workflow.
In this case, however, the problem was not that Gemini deliberately decided to attack unrelated companies. The model was operating within a testing scenario and apparently treated the real systems as legitimate targets because of the way the evaluation environment was configured.
That distinction is important when assessing what happened.
The incidents demonstrate the potential consequences of allowing an AI agent to operate with internet connectivity, even when the intended exercise is confined to simulated targets.
The Test Was Designed to Assess Cybersecurity Capabilities
Irregular’s evaluation was intended to measure how effectively AI models could perform cybersecurity tasks.
According to reporting on the incidents, Gemini was presented with a fictional company and asked to retrieve information from its software environment as part of a cybersecurity exercise.
One of the fictional companies shared a name with an actual company. Because Gemini had unintended access to the internet, the model was able to encounter the real organisation and interact with its systems.
The other incidents involved publicly available credentials that Gemini discovered during the evaluation.
The episode therefore involved a combination of an improperly isolated testing environment, publicly accessible information and an AI system capable of taking actions based on the information it found.
No Damage Was Reported by Google
Google said it did not initially disclose the incidents because the model stopped its activity after recognising that it had reached real companies and did not cause harm to the affected organisations.
The three companies were nevertheless informed of what had occurred.
Google’s position, as reported by several outlets, was that the model’s ability to recognise the situation and stop demonstrated the effectiveness of some of its safeguards. At the same time, the fact that the safeguards did not prevent the initial access has raised questions about how AI cybersecurity tests should be isolated from real-world infrastructure.
The incident therefore does not amount to evidence that Gemini intentionally launched a conventional cyberattack against businesses. Rather, it shows how an AI system performing an authorised cybersecurity task can cross into unintended real-world systems when testing controls fail.
A Wider Concern for AI Security
The Gemini incidents are part of a broader series of cases involving advanced AI systems and cybersecurity testing.
Recent reports have described similar incidents involving models associated with other major AI companies, including OpenAI, Anthropic and Meta.
The repeated appearance of such incidents has intensified discussions about how AI developers should test increasingly autonomous systems, particularly models capable of browsing the internet, writing code, interacting with software and carrying out multi-step tasks.
The central concern is not simply whether an AI model can identify a vulnerability.
The greater issue is what happens when the model has the ability to act on what it discovers.
Traditional software tools generally execute predefined commands. More advanced AI agents can interpret information, make decisions about subsequent actions and continue working through a task with considerably less human intervention.
That shift increases the importance of carefully controlled permissions and isolated testing environments.
AI Is Also Being Used to Strengthen Cybersecurity
The risks highlighted by the Gemini incident exist alongside significant efforts to use AI for defensive cybersecurity.
Google’s own Threat Intelligence Group has reported that cybercriminals are increasingly using AI to gather information, develop malware and automate parts of their operations.
In May 2026, Google reported identifying what it believed was the first known case of a threat actor using an AI-developed zero-day exploit in an attempted cyber operation. Google said the planned exploitation was disrupted before a wider attack could occur.
Google has also promoted AI systems as defensive tools capable of identifying and fixing software vulnerabilities.
The company launched its Fairwind programme in September 2026 to provide selected governments, enterprises and cybersecurity partners with advanced Gemini-based capabilities for identifying and addressing vulnerabilities.
This creates a dual-use challenge.
The same advances that can help defenders identify weaknesses more quickly can also make AI systems capable of carrying out offensive cybersecurity tasks.
The Importance of Stronger Testing Controls
The Gemini incident underscores the need for AI developers and independent evaluators to ensure that simulated cybersecurity environments are genuinely isolated from real-world systems.
Testing environments can contain fictional companies, simulated credentials and artificial networks, but those safeguards become less effective if an AI agent can unexpectedly reach the public internet.
Credentials stored in public repositories also present an additional security concern. The fact that an AI model was able to discover publicly exposed credentials reinforces the importance of organisations removing sensitive information from publicly accessible systems and rotating credentials when exposure occurs.
For AI developers, the incident highlights another requirement: models must understand not only how to perform a cybersecurity task but also when they are no longer operating within an authorised environment.
What Happens Next
Google said it has worked with Irregular on changes to the testing process following the incidents.
The affected companies were also informed, while Irregular said the relevant issues had been resolved.
The broader AI industry is now facing increasing pressure to establish clearer safeguards around autonomous systems, particularly when those systems are given access to external networks and the ability to execute actions without constant human approval.
The Gemini episode provides a practical example of why those safeguards matter.
As AI systems become more capable of searching, coding, reasoning and acting across digital environments, cybersecurity testing will increasingly need to account for the possibility that an agent may interpret a simulated task differently from what its human operators intended.
For users and organisations, the incident also reinforces a basic cybersecurity lesson: information placed publicly online, including credentials, can become an immediate security risk when increasingly capable automated systems are able to discover and act on it.
Google’s confirmation of the incidents does not establish that Gemini independently launched a deliberate cyber campaign against the three companies. It does, however, demonstrate that an AI model performing a controlled cybersecurity exercise was able to cross into real systems, obtain access and carry out actions before recognising that the targets were outside the intended scope.
That distinction will remain central to the debate over how far autonomous AI systems should be allowed to operate and what safeguards should be required before they are connected to the wider internet.
Weng Global — Stories beyond borders
- Google — Statements from Heather Adkins, Vice President of Security Engineering, and Google cybersecurity reports.
- Reuters — Report on Gemini accessing and hacking three companies during a cybersecurity test.
- The Wall Street Journal — Initial report on the Gemini cybersecurity testing incidents.
- RTÉ — Report on Google’s confirmation of the Gemini incidents.
- Axios — Report on the three cybersecurity incidents and details of the testing environment.
- The Guardian — Report on Google’s Gemini model breaching three companies during testing.
- Google Threat Intelligence Group — Reports on AI-enabled cyber threats and defensive cybersecurity measures.